A Multi-Factor Authentication Method for Internet of Things Device Groups to Ensure Firmware Security
Through the multi-factor authentication method combined with PUF and device firmware integrity verification, the problem of vulnerability to attacks by IoT devices and insufficient traditional authentication efficiency is solved, efficient and secure device authentication and key negotiation are achieved, and the security and authentication efficiency of IoT systems are improved.
Patent Information
- Application Number
- CN202310311735.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-28
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2043-03-28
AI Technical Summary
IoT devices are vulnerable to counterfeit attacks and tampering. Traditional single device access authentication solutions are insufficient in large-scale equipment access, and cannot meet the security and efficiency requirements of complex application scenarios.
The multi-factor authentication method is adopted, and the physical non-cloneable function (PUF) and device firmware integrity verification are used. Through the gateway as an aggregator, multi-factor mutual authentication and key negotiation between devices and servers are realized, including initialization, group device authentication and inter-device communication negotiation stages.
It improves the physical and software security of IoT devices, ensures that the devices are not threatened by counterfeiting and tampering, improves the authentication efficiency and privacy protection of large-scale device access, and provides front-end and back-end security guarantees.
Smart Images

Figure CN116405219B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of the Internet of Things and relates to a multi-factor authentication method for Internet of Things device groups to ensure firmware security. Background Art
[0002] The Internet of Things can connect any objects and individuals that need to be connected and share information through sensors, mobile communication technologies, etc. At the same time, with the help of technologies such as artificial intelligence and cloud computing, intelligent cognition and decision-making can be realized. The Internet of Things system can be divided into a perception layer, a transmission layer, and an application layer according to functions and characteristics. With the continuous development of the Internet of Things and mobile communication technologies, the number of Internet of Things devices is increasing day by day. The network model of the Internet of Things system is constantly updated and iterated, mainly manifested in the following two aspects: with the continuous expansion of the network scale, the number of Internet of Things device accesses is increasing, and devices and data show a massive trend; facing more comprehensive and complex application scenarios, such as intelligent transportation and smart cities, the types and functions of Internet of Things devices are increasing, and the network structure shows a complex heterogeneous trend.
[0003] Internet of Things devices usually have characteristics such as low computing power, small volume, and low power consumption, and are often arranged in public places without personnel maintenance for a long time, making them vulnerable to spoofing attacks and device tampering attacks. For example, attackers can use means such as side-channel attacks to obtain the privacy of devices; they can use cloning means to spoof legitimate devices and then obtain sensitive information of the Internet of Things system; they can even tamper with the firmware of Internet of Things devices or implant malicious code through physical or network means, thereby destroying the security of the devices.
[0004] At the same time, with the continuous development of comprehensive and complex application scenarios and the continuous changes in network scale and device form, the traditional single-device access authentication scheme cannot meet the efficiency requirements for large-scale device access. Therefore, when designing an Internet of Things authentication protocol for comprehensive application scenarios, not only the security requirements of the protocol need to be considered, but also the efficiency requirements for multi-device simultaneous access authentication need to be met. Summary of the Invention
[0005] In view of this, the purpose of the present invention is to provide a multi-factor authentication method for Internet of Things device groups to ensure firmware security. The physical and software security is guaranteed by verifying the device PUF and firmware integrity. To make the authentication method more efficient, the gateway acts as an aggregator (AG) in the authentication to assist the device and the server to complete the authentication. At the same time, considering the communication requirements between Internet of Things devices in the application scenario, a method for mutual authentication and key negotiation between devices is provided.
[0006] To achieve the above object, the present invention provides the following technical solutions:
[0007] A multi-factor authentication method for Internet of Things device groups to ensure firmware security, the method includes the following three stages:
[0008] (1) Initialization phase: When the device is initialized, it generates a corresponding initialization request and combines it with its own identity ID, which is sent to the server through the gateway. The server registers the identities of the device and the gateway into its own database based on the message, and generates a PUF stimulus and sends it to the device. The device uses the PUF to calculate a response based on the stimulus and sends it back to the server. The server uses the generated random number and master key to calculate the corresponding key and pseudo-identity based on the response information and sends it to the gateway. The gateway stores the corresponding pseudo-identity and key and forwards them to the device for storage. At this point, the device gateway and the server both store the corresponding authentication information.
[0009] (2) Group device authentication phase: complete multi-factor mutual authentication and key negotiation between multiple devices and the server based on PUF and firmware integrity with the help of the gateway; after receiving a certain number of device authentication requests, the gateway aggregates the request messages and sends them to the server, and the authentication messages returned by the server are also distributed by the gateway to different devices; in the group device authentication phase, the device first selects a pair of pseudo-identity and key pairs from the registered ones and calculates the verification information and sends it to the gateway; after receiving a certain number of messages or reaching the waiting time, the gateway forwards the verified device message to the server; after receiving the message, the server verifies the identity of the device through the verification information. If the verification is successful, it selects an incentive message from the stored incentive-response pairs CRPs, and then generates a random number and sends it to the gateway; after receiving the message, the gateway generates a random number and sends it together with the received message Forward to the device; After receiving the message, the device verifies the authenticity of the gateway and the server. If it fails, the authentication is rejected and the corresponding information is deleted. Then a random number is generated, and the corresponding PUF response is calculated according to the stimulus sent by the gateway. Then, the PUF response and the partition hash value are used to calculate its own firmware integrity value, and the above information is encrypted by XOR hashing and other methods and sent to the gateway; After receiving the message, the gateway verifies the identity of the device, and if it passes, it sends it to the server with the random number generated by itself; The server queries the response and calculates the device firmware integrity value, and then verifies the identity of the device. If it passes, the session key is calculated based on the random number and PUF generated by the device, gateway and server, and the authentication result is sent to the device; The device obtains the authentication result, and calculates the session key with the server accordingly, completing mutual authentication and key negotiation with the server;
[0010] (3) Device - to - device communication negotiation phase: With the help of the gateway aggregator, the two devices complete authentication with the gateway and key negotiation between the devices. At the same time, when the gateway intermediate routing is transparent to the devices, this solution is also applicable to the scenario of device - to - device communication between different local area networks. When Device 1 needs to communicate with Device 2, Device 1 first sends its own and Device 2's pseudo - identities to the gateway. After receiving the message, the gateway authenticates the identity of Device 1. After successful authentication, it selects new pseudo - identities and keys for Device 1 and Device 2 from the pseudo - identity key pairs stored in Device 1 and Device 2 respectively, and calculates the exclusive - OR value K of the two new keys. Then it sends the corresponding new pseudo - identities, K, and the generated random number N to Device 1 and Device 2 respectively. After receiving the message, both Device 1 and Device 2 first verify the identity of the gateway. After passing the verification, they calculate their own keys, the other party's keys, and the random number N based on the pseudo - identities and K, calculate the session key with the other party through the two new keys and the random number N, and send a confirmation message to the other party, thus completing the negotiation of the session key between the two devices.
[0011] Optionally, both the device and the server complete multi - factor authentication based on keys, PUF, and device firmware integrity during the group authentication phase. Among them, the device calculates the response through Ri = PUF(Ci) according to the excitation information Ci sent by the server, and uses the fuzzy extractor to reduce the problem that the PUF is vulnerable to environmental noise in actual use, and calculates (hd,k) = FE.Gen(Ri), thus obtaining the key k of the PUF. The server uses this key to complete the authentication of the device's PUF.
[0012] Optionally, the server completes the verification of the device's firmware integrity during the group device authentication phase. The device first calculates the hash values of each partition according to its own firmware and partition information, and then uses the PUF key k used in this authentication and the hash values of each partition as the input of HMAC to calculate the firmware integrity value F. The server calculates the firmware integrity value according to the device partition information sent by the gateway, combined with its own stored global partition table and the PUF key k used in this authentication, and verifies the firmware integrity of the device by comparing the two values. At the same time, the firmware integrity value is reflected by the verification message V generated as the input of the hash function. The server calculates the same V and compares it with the received value.
[0013] Optionally, the verification of the device firmware integrity specifically includes the following two stages:
[0014] (1) Device deployment phase: The network owner partitions the device firmware according to the size and functions of the device firmware, calculates the hash values of each partition respectively, and then the server constructs a global partition table based on the hash values of each partition of all devices in the network. The content includes the partition number and the corresponding hash value of the partition. The gateway, in the initialization stage of the authentication protocol, constructs a device partition table within the local area network according to the firmware information sent by the device. The content includes the identity ID of the device and the set of device partition numbers;
[0015] (2) Firmware integrity verification phase: The server, based on the device partition table sent by the gateway and combined with the global partition table stored by itself, calculates the firmware integrity value of a specific device with the help of the response of the PUF, and compares it with the integrity value sent by the device to verify the firmware integrity of the device. The device partition table and the global partition table containing the device firmware integrity information are respectively stored in the gateway and the server, which can ensure that when the gateway or the server is hijacked, neither party alone can obtain the correct device firmware integrity value and cannot complete the authentication process.
[0016] The beneficial effects of the present invention are as follows:
[0017] (1) This method can provide mutual authentication and key negotiation between the device and the server, and provide privacy protection for the device. The device and the server complete the multi-factor mutual authentication based on the PUF and firmware integrity between the two parties through the authentication method. At the same time, the two parties calculate the session key according to the random numbers generated by themselves and the PUF key, and complete the key negotiation. There is no association and rule between the keys, providing forward and backward security guarantees. At the same time, the device uses different pseudo-identities each time it authenticates with the server, and when there is a problem with the verification, it deletes the currently used pseudo-identity, ensuring the privacy security of the device.
[0018] (2) This method uses the PUF and firmware integrity to authenticate the device, ensuring the physical and software security of the device. The PUF has the characteristic of being non-clonable, and any modification to the PUF will affect its function, and thus the correct response cannot be obtained. Therefore, this method can protect the physical security of the device; at the same time, by verifying the firmware integrity of the device during the authentication process, it ensures that the device is not threatened by firmware tampering, thereby improving its software security.
[0019] Other advantages, objectives and features of the present invention will be described to some extent in the subsequent description, and to some extent, will be obvious to those skilled in the art based on the study of the following text, or can be learned from the practice of the present invention. The objectives and other advantages of the present invention can be realized and obtained through the following description. Brief Description of the Drawings
[0020] To make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be described in detail and preferably below in conjunction with the accompanying drawings, where:
[0021] Figure 1 is the system model diagram applicable to the method;
[0022] Figure 2 is the initialization stage of the method;
[0023] Figure 3 is the group device authentication stage of the method;
[0024] Figure 4 is the communication negotiation stage between devices of the method. Specific embodiments
[0025] The following uses specific specific examples to illustrate the implementation manners of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that the drawings provided in the following embodiments only illustrate the basic concept of the present invention in a schematic manner. Without conflict, the following embodiments and the features in the embodiments can be combined with each other.
[0026] Among them, the drawings are only for illustrative purposes, showing only schematic diagrams, not physical diagrams, and cannot be construed as limitations on the present invention; in order to better illustrate the embodiments of the present invention, some components in the drawings will be omitted, enlarged or reduced, which does not represent the dimensions of actual products; for those skilled in the art, it is understandable that some well-known structures and their descriptions in the drawings may be omitted.
[0027] In the drawings of the embodiments of the present invention, the same or similar reference numerals correspond to the same or similar components; in the description of the present invention, it should be understood that if there are terms such as "upper", "lower", "left", "right", "front", "rear", etc. indicating the orientation or positional relationship, it is based on the orientation or positional relationship shown in the drawings. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation. Therefore, the terms describing the positional relationship in the drawings are only for illustrative purposes and cannot be construed as limitations on the present invention. For those of ordinary skill in the art, the specific meanings of the above terms can be understood according to specific circumstances.
[0028] The present invention is a device-oriented multi-factor group authentication method applicable to complex Internet of Things application scenarios. The authentication entities include devices, gateways and servers. Refer to Figure 1, Different types of Internet of Things devices are connected to the server through a gateway. The gateway acts as an aggregator during the authentication process, responsible for message aggregation and distribution of the messages sent by the devices and the server, and at the same time assisting the devices to complete mutual authentication with the server.
[0029] In the device-oriented multi-factor group authentication method, it is necessary to verify the firmware integrity of the device. The specific steps of the verification include two stages: device deployment and integrity verification.
[0030] In the device deployment stage, the server first calculates the hash value of each partition according to the device firmware according to the partitions. Note that the hash function used in this stage is not HMAC, but a plain hash without a key parameter, because the parameter R of HMAC can only be determined during the authentication process. The server first constructs a global partition table during the calculation process. This table consists of two items: 1) partition number, increasing sequentially according to the number of partitions; 2) the hash value of the corresponding partition. Secondly, after a device finishes the calculation, it constructs a device partition table according to the device ID. This table consists of the following data items: 1) the unique ID of the device; 2) the set of partition compositions of the device's complete firmware, which consists of partition numbers. When adding a new device, the global partition table only needs to add the partition numbers and hash values of different partitions according to the hash values of the partitions, while the device partition table adds the corresponding data according to the rules. Similarly, after the device firmware is updated, the global partition table and the device partition table can also be updated with reference to the above method.
[0031] In the firmware integrity verification stage, we assume that the device firmware X is divided into blocks as {x1, x2.. xi}. First, the device calculates Y = {y1, y2.. yi} through a plain hash algorithm, and then uses the PUF response R used in the authentication process and the firmware hash value Y as the input of HMAC to calculate the final hash value Z. After receiving Z sent by the device, the server obtains the corresponding Y' by consulting the device partition table and the global partition table, and calculates the corresponding Z' in combination with R used in the authentication. Finally, the server can verify the integrity of the device firmware by comparing the values of Z and Z'.
[0032] The device-oriented multi-factor group authentication method mainly includes three stages: initialization, group device authentication, and communication negotiation between devices.
[0033] The initialization stage mainly completes the negotiation and storage of authentication factors among devices, gateways, and servers, including CRPs, pseudo-identities, and device firmware information, etc., which is usually carried out under a secure channel. In the present invention, two tables, the device partition table (DTB) and the global partition table (GTB), containing device firmware integrity information, are respectively stored in the gateway and the server. This can ensure that when the gateway or the server is hijacked, neither party alone can obtain the correct device firmware integrity value and complete the authentication process, thereby enhancing the system security. At the same time, separate storage can also reduce the storage burden of the server to some extent. It should be noted that it is assumed that the gateway has established a connection with the server in advance before the initialization of the Internet of Things device. The specific steps are as follows.
[0034] (1) As shown in Figure 2 , when the Internet of Things device is initialized, it selects its own ID i , generates an initialization request message Req, and sends it to the gateway.
[0035] (2) After receiving the message, the gateway registers the device ID i into the database, selects its own ID Ag , and sends the message {ID i , ID Ag , Req} to the server.
[0036] (3) After receiving the message, the server registers the IDs of the device and the gateway into its own database, randomly generates m excitations C1~C m of the PUF, and sends them to the gateway.
[0037] (4) After receiving the excitation information sent by the server, the gateway does not process it and directly forwards it to the corresponding device.
[0038] (5) After receiving the excitation of the PUF, the device calculates m responses Ri = PUF(C i ), obtains its own firmware partition information Fir, and sends the message {R1~R m , Fir} to the gateway.
[0039] (6) After receiving the message, the gateway forwards the response R of the PUF to the server, and at the same time generates a device partition table DTB according to the firmware partition information Fir sent by the device, which records the device ID and the corresponding set of partition numbers.
[0040] (7) After receiving the response sent by the gateway, the server generates a random number N, calculates the pseudo-identity PID i = h(R i || N), calculates the key K i = h(R i||mk), where mk is the master key of the server, and then store the data in the form of {PID i ,(C i ,R i ),K i}.
[0041] (8) After receiving the message, the gateway matches {PID i ,K i} with the device ID for storage and forwards the message {PID i ,K i}.
[0042] (9) The device receives the message and stores the data in the form of {PID i ,K i}.
[0043] The group device authentication phase mainly completes the multi-factor mutual authentication and key negotiation based on PUF and firmware integrity between multiple devices and the server with the help of the gateway. After receiving a certain number of device authentication requests, the gateway aggregates the request messages and sends them to the server. The authentication messages returned by the server are also distributed by the gateway to different devices. Refer to Figure 3 as shown, and the specific steps are as follows.
[0044] (1) When a device needs to be authenticated, it first selects a pair of {PID i ,K i} from its stored pseudo-identities and keys, and calculates the verification information V0 = h(PID i ||K i ), and sends the message {PID i ,V0} to the gateway.
[0045] (2) After receiving the authentication request sent by the device, the gateway first looks up the corresponding K i in its own stored database according to PID i , and then calculates and verifies the correctness of V0. If it is incorrect, it terminates the authentication with this device and deletes the corresponding {PID i ,K i} from the database. If it is correct, the authentication continues. Then, when the gateway collects and verifies a certain number of device authentication requests within a limited time (to avoid blocking caused by the gateway waiting for device requests), it aggregates the {PID i ,V0} of multiple devices and sends them to the server.
[0046] (3) After receiving the authentication message sent by the gateway, the server queries the corresponding K i one by one from the database according to PID i , C iAnd verify the correctness of V0. Similarly, if the verification fails, terminate the authentication with the device and delete the corresponding {PID from the database i ,(C i ,R i ),K i}. If the authentication is successful, generate a random number N0, and calculate C according to each device i ' = C i ⊕K i and N0' = N0 ⊕ K i , calculate the verification information V1 = h(C i ||N0||K i ), and send the merged message {C i ', N0', V1} to the gateway.
[0047] (4) After the gateway receives the message, calculate the corresponding C according to the K stored in itself i , and get N0 = N0' ⊕ K i = C i ' ⊕ K i , then verify the correctness of V1 one by one. If it is incorrect, terminate the authentication and delete the corresponding information. After successful verification, generate a random number N1, calculate N1' = N1 ⊕ N0, calculate V2 = h(V1||N1) according to each device, and send the message {C i ', N0', N1', V2} to the corresponding device. i ', N0', N1', V2} to the corresponding device.
[0048] (5) After the device receives the message, similar to the gateway, calculate C i and N0 according to K i , then calculate N1 = N'1 ⊕ N0, so as to verify the correctness of V2. If the verification is incorrect, terminate the authentication and delete the corresponding information. If the verification is correct, continue to generate a random number N2, calculate the response R i = PUF(C i ) according to its own PUF, and calculate (hd, k) = FE.Gen(R i ) using the fuzzy extractor. Calculate hd' = hd ⊕ N0 ⊕ N1, N2' = N2 ⊕ N1. Calculate the firmware hash value F using HMAC according to the firmware partition information Fir and the PUF response information R i , and calculate V3 = h(F||k||N0||N1||N2) and V4 = h(F||k), and send the message {hd', N2', V3, V4} to the gateway.
[0049] (6) After the gateway receives the messages sent back by different devices, it first calculates N2 of different devices according to N1, and uses the received V4 to verify the correctness of V3. If it is incorrect, it rejects the authentication and deletes the information. If it is correct, it calculates N1' similar to the previous stage, and queries to obtain the firmware partition number set F of each device. DTB , and calculates V5 = h(V3||F DTB ) respectively, and aggregates and sends the message {hd', N1', N2', V5, F DTB} to the server.
[0050] (7) After the server receives the message, it calculates N1 = N1'⊕N0, N2 = N2'⊕N1, and then calculates hd = hd'⊕N0⊕N1 to obtain the help data hd. Subsequently, the server calculates the key k = FE.Rep(R i and the fuzzy extractor according to the PUF response R obtained by querying the database i , hd), calculates the device firmware integrity information F according to the device partition table sent by the gateway combined with the global partition table using HMAC, and then verifies the correctness of V5. If the verification passes, it means that the current computing device is authenticated. After waiting for the verification of the group devices to end, it obtains the authentication results Res of a group of devices, and calculates Res' = Res⊕N0⊕N1. For the devices that pass the authentication, the server calculates the session key sk = h(N0||N1||N2||k) with each of them one by one, and calculates sk' = sk⊕N2⊕k. Finally, it calculates V6 = h(sk'||Res), and sends {Res', sk', V6} to the gateway.
[0051] (8) The gateway receives the message, calculates Res = Res'⊕N0⊕N1 and verifies the correctness of V6. If it is incorrect, it rejects the authentication and deletes the information. After passing, the gateway sends the authentication result Res and sk' to the corresponding device.
[0052] (9) After the device receives the authentication result, if the authentication passes, it calculates the session key sk = h(N0||N1||N2||k), and compares it with the received sk'⊕N2⊕k. If they are the same, it means that the session key negotiation between the device and the server is successful, and then this session key will be used for communication.
[0053] So far, the group devices have completed mutual authentication and key negotiation with the server with the help of the gateway aggregator. In step (3), the server authenticates the K factor of the device key by verifying V0. Similarly, in step (7), the server completes the authentication of these two authentication factors by verifying V5 containing PUF and device firmware integrity information. Then, the message {Res, sk'} sent to the device by the gateway completes the negotiation of the session key between the two parties.
[0054] Inter-device communication mainly caters to the application requirements in comprehensive application scenarios where data sharing or synchronization between devices is needed. The inter-device session key negotiation protocol proposed in this section enables the two devices to complete authentication with the gateway and key negotiation between devices with the help of the gateway aggregator. Meanwhile, under the condition that the gateway transparently routes and transmits data between devices, the protocol proposed in this section is also applicable to the communication between devices in different local area networks. Refer to Figure 4 As shown, the specific steps in the inter-device communication negotiation phase are as follows.
[0055] (1) When device i wants to communicate with device j, it needs to know the current pseudo-identity PID used by the other party, which can be obtained in two ways. One is to listen for the pseudo-identity of the device when communicating within the local area network; the other is to query by sending the real ID of the device to the gateway. After learning the pseudo-identity of the other party, device i calculates V0 = h(PID i ||PID j ||K i ) and sends the message {PID i , PID j , V0} to the gateway.
[0056] (2) After receiving the message, the gateway queries to obtain K i and K j through PID i and PID j , and then verifies the correctness of V0. If it is incorrect, the authentication is terminated and the corresponding PIDs and Ks of both devices are deleted. After successful verification, the gateway generates a random number N, calculates N' = N ⊕ K i and N'' = N ⊕ K j . Then, it selects {PID m , K m} of device i and {PID n , K n} of device j from the stored {PID, K} of device i and device j respectively, and calculates K = K m ⊕ K n . Finally, it calculates V1 = h(PID m ||N'||PID j ||K) and V2 = h(PID n ||N''||PID i ||K), and sends the message {PID m , N', PID j , K, V1} to device i and the message {PID n , N'', PID i , K, V2} to device j.
[0057] (3) After receiving the message, device i calculates N = N' ⊕ Ki , obtain K according to PID m and calculate K m = K ⊕ K n Then calculate and verify the correctness of V1. After verification, calculate the session key sk with device j = (K m || K m || N), and send the confirmation message encrypted with sk {sk ⊕ K n} n to device j sk .
[0058] (4) After device j receives the message, similar to device i, calculate the random number N and K m . Through the PID in the message i the identity of the requester can be known. Calculate and verify the correctness of V2. If incorrect, reject the authentication and delete the corresponding information. After passing, calculate the session key sk with device i = (K m || K n || N), and send the message encrypted with sk {sk ⊕ K m} sk to device i as confirmation
[0059] Thus, device i and device j complete mutual authentication and key negotiation through the gateway. Device i first completes mutual authentication with the gateway through V0 and V1, and then device i and device j complete mutual authentication and key negotiation through two messages with the session key
[0060] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the purpose and scope of the present technical solution, and they should all be covered by the scope of the claims of the present invention
Claims
1. A multi-factor Internet of Things device group authentication method for ensuring firmware security, characterized in that: The method includes the following three stages: (1) Initialization stage: When the device is initialized, it generates a corresponding initialization request combined with its own identity ID, and sends it to the server via the gateway. According to the message, the server registers the identities of the device and the gateway in its own database, generates an excitation for the PUF, and sends it to the device; the device calculates a response using the PUF according to the excitation and sends it back to the server; The server calculates the corresponding key and pseudo-identity using the generated random number and the master key according to the response information, and sends them to the gateway; the gateway stores the corresponding pseudo-identity and key, and forwards them to the device for storage; At this point, the device, gateway, and server all store the corresponding authentication information; (2) Group device authentication stage: Complete the multi-factor mutual authentication and key negotiation between multiple devices and the server based on PUF and firmware integrity with the help of the gateway; After the gateway receives a certain number of device authentication requests, it aggregates and sends the request messages to the server, and the authentication messages returned by the server are also distributed by the gateway to different devices; in the group device authentication stage, the device first selects a pair from the registered pseudo-identity and key pair and calculates the verification information to send to the gateway; after the gateway receives a certain number of messages or reaches the waiting time, it forwards the verified device messages to the server; after receiving the message, the server verifies the identity of the device through the verification information. If the verification passes, it selects an excitation information from the stored excitation response pairs CRPs, then generates a random number, and sends it to the gateway; after receiving the message, the gateway generates a random number, forwards it together with the received message to the device; after receiving the message, the device verifies the authenticity of the gateway and the server. If it fails, it rejects the authentication and deletes the corresponding information, then generates a random number, calculates the corresponding PUF response according to the excitation sent by the gateway, then calculates its own firmware integrity value using the PUF response and the partition hash value, and encrypts the above information by XOR hashing and sends it to the gateway; after getting the message, the gateway verifies the identity of the device, and after passing, it sends it to the server with the random number it generates; the server queries the response and calculates the device firmware integrity value, then verifies the identity of the device. If it passes, it calculates the session key according to the random numbers generated by the device, gateway, and server and the PUF, and sends the authentication result to the device; the device gets the authentication result and calculates the session key with the server accordingly, completing the mutual authentication and key negotiation with the server; (3) Device - to - device communication negotiation phase: With the help of the gateway aggregator, the two devices complete authentication with the gateway and key negotiation between the devices. At the same time, when the gateway intermediate routing is transparent to the devices, this solution is also applicable to the scenario of device - to - device communication between different local area networks. When Device 1 needs to communicate with Device 2, Device 1 first sends its own and Device 2's pseudo - identities to the gateway. After receiving the message, the gateway authenticates the identity of Device 1. After successful authentication, it selects new pseudo - identities and keys for Device 1 and Device 2 from the pseudo - identity key pairs stored in Device 1 and Device 2 respectively, and calculates the exclusive - OR value K of the two new keys. Then it sends the corresponding new pseudo - identities, K, and the generated random number N to Device 1 and Device 2 respectively. After receiving the message, both Device 1 and Device 2 first verify the identity of the gateway. After successful verification, they calculate their own keys, the keys of the other party, and the random number N based on the pseudo - identity and K, calculate the session key with the other party through the new keys of both parties and the random number N, and send a confirmation message to the other party, thus completing the negotiation of the session key between the two devices.
2. The multi-factor Internet of Things device group authentication method for ensuring firmware security according to claim 1, characterized in that: Both the device and the server complete multi - factor authentication based on keys, PUF, and device firmware integrity during the group authentication phase. Among them, the device calculates the response through Ri = PUF(Ci) according to the excitation information Ci sent by the server, and uses the fuzzy extractor to reduce the problem that PUF is vulnerable to environmental noise during actual use, and calculates (hd,k)=FE.Gen(Ri), thus obtaining the key k of PUF. The server uses this key to complete the authentication of the device's PUF.
3. The multi-factor Internet of Things device group authentication method for ensuring firmware security according to claim 2, wherein: The server completes the verification of the device's firmware integrity during the group device authentication phase. The device first calculates the hash values of each partition according to its own firmware and partition information, and then uses the PUF key k used in this authentication and the hash values of each partition as the input of HMAC to calculate the firmware integrity value F. The server calculates the firmware integrity value according to the device partition information sent by the gateway, combined with the global partition table stored in itself and the PUF key k used in this authentication, and verifies the firmware integrity of the device by comparing the two values. At the same time, the firmware integrity value is reflected by the verification message V generated as the input of the hash function. The server calculates the same V and compares it with the received value.
4. A multi-factor Internet of Things device group authentication method for ensuring firmware security according to claim 3, characterized in that: The verification of the device firmware integrity specifically includes the following two stages: (1) Device deployment stage: The network owner partitions the device firmware according to the device firmware size and function, calculates the hash values of each partition respectively. Then the server constructs a global partition table based on the hash values of each partition of all devices in the network, which includes the partition number and the corresponding hash value of the partition. The gateway constructs a device partition table within the local area network according to the firmware information sent by the device during the initialization stage of the authentication protocol, which includes the set of the device's identity ID and the device partition number. (2) Firmware integrity verification stage: Based on the device partition table sent by the gateway and combined with the global partition table stored on itself, the server calculates the firmware integrity value of the specific device with the help of the response of the PUF and compares it with the integrity value sent by the device to verify the firmware integrity of the device. The device partition table and the global partition table containing the device firmware integrity information are stored in the gateway and the server respectively, which can ensure that when the gateway or the server is hijacked, neither party alone can obtain the correct device firmware integrity value and cannot complete the authentication process.
Citation Information
Patent Citations
Mass Internet of Things equipment authentication method, storage medium and information data processing terminal
CN113079132A
Multi-user authentication method and system for mobile communication scene and information processing terminal
CN114286334A