A certificateless cross-domain secure authentication method and system based on SRAM PUF

By adopting a certificateless cross-domain security authentication method based on SRAM PUF, the problems of identity authentication efficiency and security in cross-domain collaborative scenarios of power smart terminals are solved. It realizes efficient and adaptive cross-domain authentication and trust assessment, and improves the interaction efficiency and security of power grid terminals.

CN118827059BActive Publication Date: 2025-11-21STATE GRID CORPORATION OF CHINA +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410843756.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-27
Publication Date
2025-11-21
Estimated Expiration
2044-06-27

AI Technical Summary

Technical Problem

The existing single identity authentication mode cannot meet the requirements of efficiency, dynamism and adaptability in cross-domain collaborative scenarios of power smart terminals. Especially when the ownership and operation rights of power grid assets are separated, the terminal interaction becomes more complicated, and there is an urgent need to build an identity trust transmission mechanism across heterogeneous domains.

Method used

A certificateless cross-domain security authentication method based on SRAM PUF is adopted. By randomly selecting registered terminals in each management domain, a unique device identifier and authentication public key are generated using SRAM PUF. Combined with token generation and verification in the registration and authentication stages, cross-domain identity authentication is achieved. Trust assessment and clustering are performed through convolutional autoencoder and density space clustering algorithms to reduce authentication overhead.

Benefits of technology

It improves the authentication efficiency of cross-domain interaction of smart power terminals, reduces authentication overhead, realizes high efficiency and adaptability of cross-domain communication, and enhances the credibility and security of terminal identity authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118827059B_ABST
    Figure CN118827059B_ABST
Patent Text Reader

Abstract

The application relates to a kind of methods and systems for establishing certificateless cross-domain authentication based on SRAM-PUF, randomly selecting domain-registered terminals in the domain, randomly selecting historical interaction terminals as cross-domain authentication terminals, using CRPs to construct a two-stage identity authentication mechanism for registration-authentication, and forming a cross-domain terminal interaction group after authentication. An indirect evaluation mechanism based on feature extraction-trust evaluation of convolutional autoencoder and trust clustering based on DBSCAN is constructed, and a terminal in the cross-domain interaction group is randomly selected as a trust anchor. After indirect trust evaluation between trust anchors, direct communication can be performed by skipping the trust anchor terminal, thereby effectively improving the authentication efficiency of power intelligent terminals and cross-domain interaction terminals in the same area, and reducing authentication overhead.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to the collaborative field of power intelligent terminals, in particular to a certificateless cross-domain security authentication method and system based on SRAM PUF. BACKGROUND

[0002] With the increasing demand for orderly opening and collaborative operation of power grids, the "terminal-terminal" collaborative capability of power intelligent terminals is continuously built, and higher requirements are put forward for the efficiency, dynamics and adaptability of terminal identity authentication. At the same time, social capital participates in the investment and operation of incremental distribution and distributed energy in large quantities, the ownership and operation right of power grid assets are separated, and the massive and complex terminal interaction breaks the original status of the partitioning of power terminals, and the single identity authentication mode cannot meet the actual demand, and a hierarchical terminal identity authentication mechanism needs to be established for terminals.

[0003] The cross-domain collaborative scenarios of different business terminals of power, such as the collaboration of terminals belonging to distribution automation systems and power utilization information collection systems, have different security levels and some security mechanisms are heterogeneous, and it is necessary to build an identity trust transmission mechanism across heterogeneous domains according to the level difference of both parties, and continuously evaluate the credibility of the other party in the interaction process. SUMMARY

[0004] In order to solve the above problems, the purpose of the present application is to provide a certificateless cross-domain security authentication method and system based on SRAM PUF, which can effectively improve the authentication efficiency of power intelligent terminals and reduce the authentication overhead.

[0005] In order to achieve the above purpose, the following technical solutions are adopted:

[0006] A certificateless cross-domain security authentication method based on SRAM PUF, in a terminal set composed of multiple management domains, a terminal node is randomly selected in each domain as an intra-domain registration terminal, responsible for managing the identity registration of terminals in the domain, and each domain randomly votes to elect a cross-domain authentication terminal to support cross-domain identity authentication collaboration, including a registration phase and an authentication phase, as follows:

[0007] Registration phase:

[0008] Let each terminal D i SRAM PUF function generation device unique identifier ID i and authentication CRPs i , public key PK i , after each terminal joins the management domain, the identity identifier ID i and part of the authentication CRPs′ i of the intra-domain registration terminal InCer j are registered, and the intra-domain registration terminal InCerj Command terminal D i Calculate CRPs using the SRAMPUF function. i Verify terminal D i After verifying the physical authenticity, the ID will be... i PK with public key i Bind your account and generate a registration token:

[0009] RToken i =SM3(ID) i PK i ,t i CRPs' i SK j );

[0010] Among them SK j InCer is a domain-registered terminal j private key, t i For registration timestamp;

[0011] Certification phase:

[0012] When terminal D i Need to access another domain k When accessing resources in the cross-domain authentication terminal OutCer, i Initiate cross-domain authentication request Apply_DO(ID) i PK i CRPs' i RToken i Domain k Cross-domain authentication terminal OutCer verifies RToken i Confirm terminal D i A legitimate identity within its domain;

[0013] Then, the cross-domain authentication terminal OutCer i To the target domain k Cross-domain authentication terminal OutCer k Send cross-origin authentication request Apply_DO(ID) i PK i CRPs' i Domain k Cross-domain authentication terminal OutCer k After receiving the request, for terminal D i Initiate CRP authentication, terminal D i Calculate CRPs using the SRAMPUF function. i Cross-domain authentication terminal OutCer kThe received result is compared with the domain-internal registration terminal InCer j The generated registration token is the same, and the identity authentication is completed.

[0014] Further, when the unincorporated terminal has cross-domain interaction needs, the unauthenticated terminal selects a group of intermediate terminals with direct interaction history with the cross-domain authentication terminal, i.e., the domain-internal authentication terminal, as the bridge of trust propagation.

[0015] Further, when the unauthenticated terminal and the intermediate terminal with direct interaction history are larger than the threshold, the unauthenticated terminal processes the edge distributed heterogeneous trust data, fuses multi-source heterogeneous data, automatically learns feature representation, performs feature extraction and trust evaluation based on a convolutional autoencoder, realizes knowledge sharing and collaborative computing between different trust evaluation models, applies a noise algorithm for trust clustering based on density-based spatial clustering, and distinguishes between low-density and high-density areas to identify trusted and untrusted terminal groups.

[0016] Further, the feature extraction based on the convolutional autoencoder is as follows:

[0017] First, the input layer of the autoencoder is constructed, and the terminal evaluation data is encoded into a high-dimensional feature vector. The output layer is responsible for decoding the feature vector to reconstruct the data.

[0018] Then, the hidden layer for feature extraction is constructed. By calculating the reconstruction error, the autoencoder compares the feature vectors before and after the hidden layer encoding to measure the effect of feature extraction.

[0019] In node clustering, KL divergence is used to calculate the reconstruction error:

[0020]

[0021] where g i′ and h i′ represent the feature vectors of the i'th input and output, respectively, and n' is the total number of feature vectors.

[0022] Further, when constructing the convolutional autoencoder, a convolutional neural network is introduced, and sparse constraints are introduced into the hidden layer of the autoencoder for regularization. By keeping most neurons in an inactive state, the complexity of the edge network is reduced and overfitting is prevented. The average activation avg j of each hidden neuron is calculated to determine the active neurons. The sparse penalty term in the loss function measures the difference through KL divergence, and the network is learned based on a small number of active neurons.

[0023] Let be the activation value of neuron j, and N be the number of nodes. Then the average activation avg j of neuron j is:

[0024]

[0025] The loss function is represented as

[0026]

[0027] wherein, is a sparse penalty coefficient, KL i is a similarity measure based on KL divergence, L is a base loss.

[0028] Further, the trust evaluation based on the convolutional autoencoder is specifically as follows:

[0029] Suppose there are m evaluation terminals in the middle layer, and the terminal set is E={e1,e2,…,e m};

[0030] For the evaluation terminal e i , interact with all terminals, and the evaluation node sets the weight as:

[0031]

[0032] wherein represents the number of communications between node i and node j within a period of time t, and the indirect trust value is represented as:

[0033]

[0034] wherein, is a direct trust value.

[0035] Further, the trust clustering is performed by the density-based spatial clustering application noise algorithm, and is specifically as follows:

[0036] The concept of neighborhood is defined, and the neighborhood of each data point is defined by a neighborhood radius, that is, the distance between points is less than θ and is regarded as a neighborhood; a point containing at least MinPts sample points in the neighborhood is defined as a core point, and the specific clustering process is as follows:

[0037] (1) a node is randomly selected as a starting point, and the number of neighbor nodes thereof is calculated;

[0038] (2) if the number of neighbor nodes is greater than MinPts, then the neighbor nodes of the node will be added to the cluster of the node;

[0039] (3) then, the neighborhood expansion is continued on the newly added points to ensure that all reachable core points are added to the cluster;

[0040] (3) if the neighborhood of a core point contains other core points, they will be connected to the same cluster.

[0041] (4) All data points that are not assigned to a cluster are marked as noise points, which do not belong to any cluster;

[0042] (5) Repeat the above process until all data points are visited and classified.

[0043] Further, in the clustering process, the edge nodes have various trust attribute characteristics, different attribute weights are assigned according to the relative importance of each attribute in the clustering process, assuming that the edge nodes have a total of M' attributes, the neighborhood distance ND of any node r and node s is calculated as follows:

[0044]

[0045] A certificateless cross-domain secure authentication system based on SRAM PUF includes a processor, a memory and a computer program stored on the memory, when the processor executes the computer program, specifically executes the steps of a certificateless cross-domain secure authentication method based on SRAM PUF as described above.

[0046] The present application has the following beneficial effects:

[0047] The present application randomly selects a registration terminal in the domain and completes the two-stage identity authentication of registration and authentication with the CRPs of SRAM PUF; the authentication terminal is included in the cross-domain interaction group. The system extracts features from multi-source heterogeneous trust data based on convolutional autoencoder and outputs unified representation, and then calculates direct and indirect trust, and uses DBSCAN to trust cluster the terminal and label the group as trusted with double thresholds of density and average trust. On this basis, the system randomly selects a trust anchor point in the cross-domain interaction group, and evaluates the indirect trust between the non-anchor terminal and the anchor point; when the evaluation is passed and the terminal belongs to the trusted cluster, it is allowed to skip the complete identity authentication process in subsequent communication with other terminals passing through the same anchor point, thereby reducing the authentication overhead and improving the cross-domain communication efficiency. BRIEF DESCRIPTION OF DRAWINGS

[0048] Figure 1 The present application is a cross-domain authentication framework for the same region cross-domain interaction terminal. DETAILED DESCRIPTION

[0049] The present application will be further described in detail below in combination with the drawings and specific embodiments:

[0050] REFERENCE Figure 1In the embodiment, a certificateless cross-domain security authentication method based on SRAM PUF is provided. In a terminal set composed of multiple management domains, a terminal node is randomly selected in each domain as an intra-domain registration terminal, which is responsible for managing the identity registration of terminals in the domain. Each domain randomly votes to elect a cross-domain authentication terminal, which supports cross-domain identity authentication collaboration. The method includes a registration phase and an authentication phase, and the details are as follows.

[0051] Registration phase:

[0052] Suppose that each terminal D i has an SRAM PUF function to generate a unique device identifier ID i and authentication CRPs i , a public key PK i . After each terminal joins the management domain, the intra-domain registration terminal InCer j registers the identity identifier ID i and part of the authentication CRPs′ i . The intra-domain registration terminal InCer j asks the terminal D i to call the SRAM PUF function to calculate CRPs′ i , verifies the physical authenticity of the terminal D i , and then binds the ID i and the public key PK i to generate a registration token:

[0053] RToken i = SM3(ID i , PK i , t i , CRPs′ i , SK j );

[0054] where SK j is the private key of the intra-domain registration terminal InCer j , and t i is the registration timestamp;

[0055] Authentication phase:

[0056] When the terminal D i needs to access resources in another domain Domain k , it initiates a cross-domain authentication application Apply_DO(ID i , PK i , CRPs′ i , RToken i , Domain k ) to the cross-domain authentication terminal OutCer i . The cross-domain authentication terminal OutCer verifies RTokeni Confirm terminal D i A legitimate identity within its domain;

[0057] Then, the cross-domain authentication terminal OutCer i To the target domain k Cross-domain authentication terminal OutCer k Send cross-origin authentication request Apply_DO(ID) i PK i CRPs' i Domain k Cross-domain authentication terminal OutCer k After receiving the request, for terminal D i Initiate CRP authentication, terminal D i Calculate CRPs using the SRAMPUF function. i Cross-domain authentication terminal OutCer k The received results will be compared with the domain-registered terminal InCer. j If the generated registration tokens are identical, then identity authentication is complete.

[0058] In this embodiment, after terminals within the same region complete authentication, the authenticated terminals establish a cross-domain terminal interaction group. However, some terminals are not included in this group. When the unincluded terminals have cross-domain interaction needs, the terminals that have not directly established authentication select a group of intermediate terminals with a direct interaction history with the cross-domain authenticated terminals, i.e., the domain-internal authenticated terminals, as a bridge for trust propagation.

[0059] When the number of unauthenticated terminals and intermediate terminals with direct interaction history exceeds a threshold, the unauthenticated terminals process edge-distributed heterogeneous trust data, integrate multi-source heterogeneous data, automatically learn feature representations, perform feature extraction and trust evaluation based on convolutional autoencoders, realize knowledge sharing and collaborative computing among different trust evaluation models, and perform trust clustering based on density-based spatial clustering application noise algorithms. By distinguishing between low-density and high-density regions, trustworthy and untrustworthy terminal groups are identified.

[0060] Preferably, in this embodiment, feature extraction is performed based on a convolutional autoencoder, as follows:

[0061] First, an input layer of an autoencoder is constructed to encode the terminal evaluation data into high-dimensional feature vectors, and the output layer is responsible for decoding the feature vectors to reconstruct the data.

[0062] Then, a hidden layer for feature extraction is constructed. By calculating the reconstruction error, the autoencoder compares the feature vectors before and after the hidden layer encoding to measure the effect of feature extraction.

[0063] In the node clustering, the KL divergence is used to calculate the reconstruction error:

[0064]

[0065] where g i′ and h i′ represent the feature vectors of the i'th input and output respectively, and n' is the total number of feature vectors.

[0066] Preferably, in the embodiment, when constructing the convolutional autoencoder, a convolutional neural network is introduced, and a sparse constraint is introduced into the hidden layer of the autoencoder for regularization; by keeping most neurons in an inactive state, the complexity of the edge network is reduced and overfitting is prevented; the average activation avg j of each hidden neuron is calculated to determine the active neurons; the sparse penalty term in the loss function measures the difference through KL divergence, and the network is learned based on a small number of activated neurons;

[0067] Let be the activation value of neuron j, and N be the number of nodes, then the average activation avg j of neuron j is:

[0068]

[0069] The loss function is represented as

[0070]

[0071] where, is the sparse penalty coefficient, and KL i is the similarity measure based on KL divergence, and L is the basic loss.

[0072] Preferably, in the embodiment, the trust evaluation based on the convolutional autoencoder is as follows:

[0073] Let there be m evaluation terminals in the middle layer, and the terminal set be E = {e1, e2, …, em}; m};

[0074] For the evaluation terminal e i , it interacts with all terminals. As the number of interactions increases, it means that the higher the frequency of interaction between the two parties, the greater the possibility of trust. Therefore, the evaluation node sets the weight as:

[0075]

[0076] where represents the number of communications between node i and node j in a period of time t, and the indirect trust value is represented as:

[0077]

[0078] wherein, is a direct trust value.

[0079] Preferably, in the present embodiment, the density-based spatial clustering of applications with noise algorithm is applied to trust clustering, in particular as follows:

[0080] The concept of neighborhood is defined, and the neighborhood of each data point is defined by a neighborhood radius, i.e. the distance between points less than θ is considered as a neighborhood; a point containing at least MinPts sample points in the neighborhood is defined as a core point, and the specific clustering process is as follows:

[0081] (1) A node is randomly selected as the starting point, and the number of its neighbor nodes is calculated;

[0082] (2) If the number of neighbor nodes is greater than MinPts, then the neighbor nodes of the node will be added to the cluster of the node;

[0083] (3) Then, the neighborhood expansion is continued for the newly added points to ensure that all reachable core points are added to the cluster;

[0084] (3) If the neighborhood of a core point contains other core points, they will be connected to the same cluster;

[0085] (4) All data points that are not assigned to a cluster will be marked as noise points, which do not belong to any cluster;

[0086] (5) Repeat the above process until all data points are accessed and classified.

[0087] In the clustering process, the edge node has various trust attribute characteristics, and different attribute weights are assigned according to the relative importance of each attribute in the clustering process, assuming that the edge node has a total of M' attributes, and the neighborhood distance ND of any node r and node s is calculated as follows:

[0088]

[0089] Finally, one or more clusters are obtained, each cluster containing a group of densely connected data points, and the noise points do not belong to any cluster.

[0090] Those skilled in the art will appreciate that embodiments of the application can be devised for a method, a system, or a computer program product. Accordingly, the present application can be embodied in the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present application can take the form of a computer program product on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage devices, and the like) embodying computer readable program code.

[0091] The present application is described in reference to the flowchart illustrations and / or block diagrams of methods, apparatus (systems) and computer program products according to embodiments of the application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams.

[0092] These computer program instructions can also be stored in a computer- readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams.

[0093] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams.

[0094] The above descriptions are only preferred embodiments of the present application, and are not intended to limit the present application to other forms. Any person skilled in the art can make modifications or alterations to the above-described embodiments based on the technical content disclosed herein, and the modifications or alterations are equivalent embodiments. However, any simple modifications, equivalent alterations, and modifications of the above-described embodiments, which do not deviate from the technical content of the present application, are still within the scope of the present application.

Claims

1. A certificateless cross-domain secure authentication method based on SRAMPUF, characterized in that, In a terminal set composed of multiple management domains, each domain randomly selects a terminal node as the domain's registered terminal, responsible for managing the identity registration of terminals within its domain. Each domain randomly votes to elect a cross-domain authentication terminal, supporting cross-domain identity authentication collaboration, including registration and authentication phases, as detailed below: Registration phase: Let each terminal D i The SRAMPUF function generates a unique device identifier ID. i and Certified CRPs i Public key PK i After each terminal joins its management domain, it registers the terminal InCer within the domain. j Register their identity ID i and some certified CRPs i ', Domain-registered terminal InCer j Command terminal D i Calculate CRPs using the SRAMPUF function i ', Verify terminal D i After verifying the physical authenticity, the ID will be... i PK with public key i Bind your account and generate a registration token: RToken i =SM3(ID i ,PK i ,t i ,CRPs i ',SK j ); Among them SK j InCer is a domain-registered terminal j private key, t i For registration timestamp; Certification phase: When terminal D i Need to access another domain k When accessing resources in the cross-domain authentication terminal OutCer, i Initiate cross-domain authentication request Apply_DO(ID) i PK i CRPs i ',RToken i Domain k Cross-domain authentication terminal OutCer i Verify RToken i Confirm terminal D i A legitimate identity within its domain; Then, the cross-domain authentication terminal OutCer i To the target domain k Cross-domain authentication terminal OutCer k Send cross-origin authentication request Apply_DO(ID) i PK i CRPs i ',Domain k Cross-domain authentication terminal OutCer k After receiving the request, for terminal D i Initiate CRP authentication, terminal D i Calculate CRPs using the SRAMPUF function i Cross-domain authentication terminal OutCer k The received results will be compared with the domain-registered terminal InCer. j If the generated registration tokens are identical, then identity authentication is complete.

2. The certificateless cross-domain security authentication method based on SRAMPUF according to claim 1, characterized in that, When an unincluded terminal has a cross-domain interaction requirement, the terminal that has not directly established authentication selects a group of intermediate terminals that have a direct interaction history with the cross-domain authentication terminal, i.e., intra-domain authentication terminals, as a bridge for trust propagation.

3. The certificateless cross-domain secure authentication method based on SRAM PUF according to claim 2, characterized in that, When the number of unauthenticated terminals and intermediate terminals with direct interaction history exceeds a threshold, the unauthenticated terminals process edge-distributed heterogeneous trust data and automatically learn feature representations by fusing multi-source heterogeneous data. Feature extraction and trust evaluation are performed based on convolutional autoencoders to achieve knowledge sharing and collaborative computation among different trust evaluation models. Trust clustering is performed based on density-based spatial clustering application noise algorithms to obtain low-density regions and high-density regions. High-density regions are identified as trustworthy terminal groups, and low-density regions are identified as untrustworthy terminal groups.

4. The certificateless cross-domain secure authentication method based on SRAM PUF according to claim 3, characterized in that, The feature extraction based on the convolutional autoencoder is as follows: First, an input layer of an autoencoder is constructed to encode the terminal evaluation data into high-dimensional feature vectors, and the output layer is responsible for decoding the feature vectors to reconstruct the data. Then, a hidden layer for feature extraction is constructed. By calculating the reconstruction error, the autoencoder compares the feature vectors before and after the hidden layer encoding to measure the effect of feature extraction. In node clustering, KL divergence is used to calculate the reconstruction error: Among them, g i ′ and h i′ Let i and n represent the feature vectors of the i′th input and output, respectively, and n′ be the total number of feature vectors.

5. The certificateless cross-domain security authentication method based on SRAM PUF according to claim 4, characterized in that, When constructing the convolutional autoencoder, a convolutional neural network is introduced to regularize the hidden layers of the autoencoder by incorporating sparsity constraints. By keeping neurons in an inactive state, the complexity of the edge network is reduced and overfitting is prevented. The average activation level (avg) of each hidden neuron is calculated. j Active neurons are identified; the sparse penalty term in the loss function is obtained by combining the KL divergence measure of difference and learning based on the activated neurons. set up Let be the activation value of neuron j, and N be the number of nodes. Then, the average activation level (avg) of neuron j is... j yes: The loss function is expressed as in, It is the sparsity penalty coefficient, KL i ′ is a similarity measure based on KL divergence, and L is the basic loss.

6. The certificateless cross-domain secure authentication method based on SRAM PUF according to claim 3, characterized in that, Trust evaluation based on convolutional autoencoders is as follows: Suppose there are m evaluation terminals in the intermediate layer, and the terminal set is E = {e1, e2, ..., e...} m }; For evaluating terminal e i It interacts with all terminals, and the evaluation node is set with the following weights: in The indirect trust value represents the number of communications between node i and node j within a time period t. in, This is a direct trust value.

7. The certificateless cross-domain secure authentication method based on SRAM PUF according to claim 3, characterized in that, The density-based spatial clustering application uses a noise algorithm for trust clustering, as detailed below: The concept of neighborhood is defined by the neighborhood radius, where each data point's neighborhood is defined as a point whose distance to another point is less than θ. Points containing at least MinPts sample points within their neighborhoods are defined as core points. The specific clustering process is as follows: (1) Randomly select a node as the starting point and calculate the number of its neighboring nodes; (2) If the number of neighboring nodes is greater than MinPts, then the neighboring nodes of the node will be added to the cluster of the node. (3) Then, continue to expand the neighborhood of the newly added points to ensure that all reachable core points are added to the cluster; (3) If a core point’s neighborhood contains other core points, then they will be connected to the same cluster; (4) All data points that are not assigned to a cluster will be marked as noise points, and they do not belong to any cluster; (5) Repeat the above process until all data points have been accessed and classified.

8. The certificateless cross-domain secure authentication method based on SRAM PUF according to claim 7, characterized in that, During clustering, edge nodes possess various reliable attribute characteristics. Different attribute weights are assigned based on the relative importance of each attribute in the clustering process. Assuming each edge node has a total of M′ attributes, the neighborhood distance ND between any node r and node s is calculated as follows:

9. A certificateless cross-domain security authentication system based on SRAM PUF, characterized in that, It includes a processor, a memory, and a computer program stored on the memory. When the processor executes the computer program, it specifically performs the steps of the certificateless cross-domain security authentication method based on SRAM PUF as described in any one of claims 1-8.

Citation Information

Patent Citations

  • Authentication method and system of power distribution Internet of Things terminal access gateway

    CN117319005A

  • Cross-domain authentication method based on block chain and certificateless signature

    CN117424708A