Identity authentication method, device and equipment
By employing a stimulus-response mechanism with physically unclonable functions and two-way authentication in IoT devices, the problem of limited resources in IoT devices is solved, and higher data transmission security and identity authentication security are achieved.
Patent Information
- Application Number
- CN202411358460.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-27
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2044-09-27
AI Technical Summary
Traditional user-driven, complex security authentication protocols are difficult to implement in resource-constrained IoT devices, making it difficult to guarantee the security of data transmission in IoT devices.
An incentive-response mechanism based on physically unclonable functions is used for identity authentication. Through two-way authentication between the server and IoT devices, unauthorized data operations are detected to prevent communication data from being tampered with.
It improves the data transmission security of IoT devices, solves the problem of complex security authentication protocols being difficult to implement in resource-constrained devices, and enhances the security of identity authentication and the reliability of data transmission.
Smart Images

Figure CN119299102B_ABST
Abstract
Description
Technical Field
[0001] This document relates to the field of computer technology, and in particular to methods, devices and equipment for identity authentication. Background Technology
[0002] With the rapid development of Internet technology, various smart devices can be connected through the Internet to realize multiple functions such as automatic data reporting, remote access, and remote control management by taking advantage of the convenience of Internet information dissemination, thereby building a network.
[0003] Traditional IoT security mechanisms require complex cryptographic mathematical operations, which necessitate sufficient storage space and high computing memory. However, IoT devices are small in size and have limited hardware processing power and resources. Therefore, traditional user-driven complex security authentication protocols are difficult to implement effectively in the IoT. To address this, this specification provides a technical solution to improve the data transmission security of IoT devices. Summary of the Invention
[0004] The purpose of the embodiments in this specification is to provide a technical solution to improve the data transmission security of Internet of Things (IoT) devices.
[0005] To achieve the above technical solution, the embodiments in this specification are implemented as follows:
[0006] This specification provides an authentication method applied to a server. The method includes: generating a first random authentication code corresponding to the current authentication period when authentication of an IoT device is successful in the current authentication period, and obtaining a first incentive corresponding to the current authentication period from pre-stored incentives; determining a second incentive based on the first random authentication code and the first incentive, and inputting the second incentive into a physically unclonable function to generate a first response value; sending the first random authentication code and the first response value to the IoT device; receiving the authentication result of the IoT device against the server in the current authentication period, wherein the authentication result is determined by the IoT device based on the matching detection result of the first response value and the second response value, the second response value is a response value corresponding to a third incentive generated by the IoT device based on the physically unclonable function, and the third incentive is determined by the IoT device based on the first random authentication code and a fourth incentive corresponding to the current authentication period from pre-stored incentives; and determining whether to establish a communication connection with the IoT device based on the first authentication result.
[0007] This specification provides an identity authentication device, comprising: a first generation module, configured to generate a first random authentication code corresponding to the current identity authentication period and acquire a first incentive corresponding to the current identity authentication period from pre-stored incentives when successful identity authentication of an IoT device in the current identity authentication period; a second generation module, configured to determine a second incentive based on the first random authentication code and the first incentive, and input the second incentive into a physically unclonable function to generate a first response value; a first sending module, configured to send the first random authentication code and the first response value to the IoT device; a first receiving module, configured to receive the identity authentication result of the IoT device for the identity authentication device in the current identity authentication period, wherein the identity authentication result is determined by the IoT device based on the matching detection result of the first response value and the second response value, the second response value is a response value corresponding to a third incentive generated by the IoT device based on the physically unclonable function, and the third incentive is determined by the IoT device based on the first random authentication code and a fourth incentive corresponding to the current identity authentication period from pre-stored incentives; and a result determination module, configured to determine whether to establish a communication connection with the IoT device based on the first identity authentication result.
[0008] This specification provides an identity authentication device, comprising: a processor; and a memory configured to store computer-executable instructions, wherein, when executed, the processor: if successful authentication of an IoT device in the current identity authentication cycle, generates a first random authentication code corresponding to the current identity authentication cycle and obtains a first incentive corresponding to the current identity authentication cycle from pre-stored incentives; determines a second incentive based on the first random authentication code and the first incentive, and inputs the second incentive into a physically unclonable function to generate a first response value; sends the first random authentication code and the first response value to the IoT device; receives the identity authentication result from the IoT device in the current identity authentication cycle, wherein the identity authentication result is determined by the IoT device based on a matching detection result of the first response value and the second response value, the second response value being a response value corresponding to a third incentive generated by the IoT device based on the physically unclonable function, the third incentive being determined by the IoT device based on the first random authentication code and a fourth incentive corresponding to the current identity authentication cycle from pre-stored incentives; and determines whether to establish a communication connection with the IoT device based on the first identity authentication result.
[0009] This specification also provides a storage medium for storing computer-executable instructions. When executed by a processor, these instructions implement the following process: If authentication of an IoT device is successful during the current authentication period, a first random authentication code corresponding to the current authentication period is generated, and a first incentive corresponding to the current authentication period is obtained from pre-stored incentives; a second incentive is determined based on the first random authentication code and the first incentive, and the second incentive is input into a physically unclonable function to generate a first response value; the first random authentication code and the first response value are sent to the IoT device; the authentication result of the IoT device against the server during the current authentication period is received, where the authentication result is determined by the IoT device based on a matching detection result of the first and second response values, the second response value is a response value corresponding to a third incentive generated by the IoT device based on the physically unclonable function, and the third incentive is determined by the IoT device based on the first random authentication code and a fourth incentive corresponding to the current authentication period from pre-stored incentives; and a communication connection is established with the IoT device based on the first authentication result.
[0010] This specification also provides a computer program product, including a computer program that, when executed by a processor, implements the following process: If the authentication of an IoT device is successful during the current authentication period, a first random authentication code corresponding to the current authentication period is generated, and a first incentive corresponding to the current authentication period is obtained from pre-stored incentives; a second incentive is determined based on the first random authentication code and the first incentive, and the second incentive is input into a physically unclonable function to generate a first response value; the first random authentication code and the first response value are sent to the IoT device; the authentication result of the IoT device against the server during the current authentication period is received, wherein the authentication result is determined by the IoT device based on the matching detection result of the first response value and the second response value, the second response value is a response value corresponding to a third incentive generated by the IoT device based on the physically unclonable function, and the third incentive is determined by the IoT device based on the first random authentication code and a fourth incentive corresponding to the current authentication period from pre-stored incentives; and a communication connection is established with the IoT device based on the first authentication result.
[0011] This specification provides an authentication method applied to an Internet of Things (IoT) device. The method includes: receiving a first random authentication code and a first response value sent by a server when the IoT device is successfully authenticated during the current authentication period; the first response value being a response value generated by the server by inputting a second incentive into a physically unclonable function (IoTF); the second incentive being determined based on the first random authentication code and the first incentive, and the first incentive being an incentive pre-stored by the server corresponding to the current authentication period; obtaining a fourth incentive corresponding to the current authentication period, and determining a third incentive based on the fourth incentive and the first random authentication code; determining a second response value corresponding to the third incentive based on the IoTF; determining a first authentication result for the server based on a matching detection result of the first and second response values, and returning the first authentication result to the server; the first authentication result triggering the server to determine whether to establish a communication connection with the IoT device.
[0012] This specification provides an identity authentication device, comprising: a data receiving module, configured to receive a first random authentication code and a first response value sent by a server when the authentication device is successfully authenticated in the current identity authentication period; the first response value being a response value generated by the server by inputting a second incentive into a physical non-cloning function; the second incentive being determined based on the first random authentication code and the first incentive; and the first incentive being an incentive pre-stored by the server corresponding to the current identity authentication period; a data acquisition module, configured to acquire a fourth incentive corresponding to the current identity authentication period and determine a third incentive based on the fourth incentive and the first random authentication code; a response value determination module, configured to determine a second response value corresponding to the third incentive based on the IoT non-cloning function; and a result sending module, configured to determine a first identity authentication result for the server based on a matching detection result of the first and second response values, and return the first identity authentication result to the server; the first identity authentication result being used to trigger the server to determine whether to establish a communication connection with the identity authentication device.
[0013] This specification provides an identity authentication device, comprising: a processor; and a memory arranged to store computer-executable instructions, wherein, when executed, the processor: receives a first random authentication code and a first response value sent by a server in the current identity authentication cycle, provided that the authentication device has successfully authenticated the device; the first response value is a response value generated by the server by inputting a second incentive into a physical non-cloning function; the second incentive is determined based on the first random authentication code and the first incentive, and the first incentive is an incentive pre-stored by the server corresponding to the current identity authentication cycle; acquires a fourth incentive corresponding to the current identity authentication cycle, and determines a third incentive based on the fourth incentive and the first random authentication code; determines a second response value corresponding to the third incentive based on the IoT non-cloning function; determines a first identity authentication result for the server based on a matching detection result of the first response value and the second response value, and returns the first identity authentication result to the server; the first identity authentication result is used to trigger the server to determine whether to establish a communication connection with the identity authentication device.
[0014] This specification also provides a storage medium for storing computer-executable instructions. When executed by a processor, the executable instructions implement the following process: receiving a first random authentication code and a first response value sent by a server when the authentication of an IoT device is successful in the current authentication period. The first response value is a response value generated by the server by inputting a second incentive into a physical non-cloning function. The second incentive is determined based on the first random authentication code and the first incentive, and the first incentive is an incentive pre-stored by the server corresponding to the current authentication period; obtaining a fourth incentive corresponding to the current authentication period, and determining a third incentive based on the fourth incentive and the first random authentication code; determining a second response value corresponding to the third incentive based on the IoT non-cloning function; determining a first authentication result for the server based on a matching detection result of the first and second response values, and returning the first authentication result to the server. The first authentication result is used to trigger the server to determine whether to establish a communication connection with the IoT device.
[0015] This specification also provides a computer program product, including a computer program that, when executed by a processor, implements the following process: receiving a first random authentication code and a first response value sent by a server when the authentication of an IoT device is successful in the current authentication period; the first response value being a response value generated by the server by inputting a second incentive into a physically unclonable function; the second incentive being determined based on the first random authentication code and the first incentive; the first incentive being an incentive pre-stored by the server corresponding to the current authentication period; obtaining a fourth incentive corresponding to the current authentication period; and determining a third incentive based on the fourth incentive and the first random authentication code; determining a second response value corresponding to the third incentive based on the IoT unclonable function; determining a first authentication result for the server based on a matching detection result of the first and second response values; and returning the first authentication result to the server; the first authentication result being used to trigger the server to determine whether to establish a communication connection with the IoT device. Attached Figure Description
[0016] To more clearly illustrate the technical solutions in the embodiments or prior art of this specification, the drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0017] Figure 1 This is an embodiment of an identity authentication method described in this specification;
[0018] Figure 2 This is another embodiment of the identity authentication method described in this specification;
[0019] Figure 3 This is another embodiment of the identity authentication method described in this specification;
[0020] Figure 4 This is a schematic diagram of an Internet of Things (IoT) system architecture as described in this specification;
[0021] Figure 5 This is a schematic diagram of an initialization phase in this specification;
[0022] Figure 6 This is a schematic diagram of one of the device registration stages in this specification;
[0023] Figure 7 This is a schematic diagram illustrating one stage of the device certification process described in this manual.
[0024] Figure 8This is another embodiment of the identity authentication method described in this specification;
[0025] Figure 9 This is another embodiment of the identity authentication method described in this specification;
[0026] Figure 10 This is an embodiment of an identity authentication device described in this specification;
[0027] Figure 11 This is another embodiment of an identity authentication device described in this specification;
[0028] Figure 12 This is an example of an identity authentication device described in this specification. Detailed Implementation
[0029] This specification provides methods, apparatus, and devices for identity authentication through its embodiments.
[0030] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this specification.
[0031] This specification provides methods, apparatus, and devices for identity authentication. With the rapid development of internet technology, various smart devices can be connected via the internet, leveraging its convenience to automatically report data, access remotely, and manage remotely, thus building a network. Traditional IoT security mechanisms require complex cryptographic mathematical operations, which necessitate sufficient storage space and high computing memory. However, IoT devices are small, have limited hardware processing power and resources, making traditional user-driven complex security authentication protocols ineffective in the IoT. Therefore, this specification provides a technical solution to improve the data transmission security of IoT devices. This solution, on the one hand, uses an incentive-response mechanism to ensure the security of identity authentication for IoT devices, solving the problem that complex security authentication collaboration is difficult to implement in resource-constrained IoT devices. On the other hand, through two-way authentication between the server and the IoT device, unauthorized data operations can be detected, preventing unauthorized parties from tampering with the communication data between the IoT device and the server, thereby improving the data transmission security of IoT devices. Specific processing details can be found in the following embodiments.
[0032] like Figure 1As shown in the embodiments of this specification, an identity authentication method is provided. The executing entity of this method can be a server, which can be a single independent server or a server cluster composed of multiple servers. The server can be a backend server for financial services or online shopping services, or a backend server for an application. Specifically, the method may include the following steps:
[0033] In step S102, if the IoT device is successfully authenticated in the current authentication cycle, a first random authentication code corresponding to the current authentication cycle is generated, and the first incentive corresponding to the current authentication cycle is obtained from the pre-stored incentives.
[0034] The identity authentication period can be a preset authentication period, such as 1 hour, 3 hours or any other authentication period. The IoT device can be a smart device containing sensors, such as a smart device containing a SIM card.
[0035] In implementation, the server can generate a corresponding random authentication code for each authentication cycle. For example, the server can generate a random authentication code of a preset length for each authentication cycle based on a preset random algorithm. Furthermore, the server can also generate a corresponding incentive for each authentication cycle and send the generated incentive to the IoT device. The IoT device can receive and store the incentive corresponding to each authentication cycle.
[0036] The server can receive authentication requests from IoT devices and perform authentication processing on them. There are several methods the server can use to perform authentication. For example, an IoT device can send its device identifier to the server. The server can then perform a matching check between the received device identifier and pre-stored device identifiers. If a matching device identifier exists in the pre-stored identifiers, the server determines that authentication of the IoT device was successful in the current authentication period.
[0037] Furthermore, there are various other methods for performing identity authentication on IoT devices, and different identity authentication methods can be selected according to different actual application scenarios. This specification does not specifically limit these methods in the embodiments.
[0038] In step S104, a second stimulus is determined based on the first random authentication code and the first stimulus, and the second stimulus is input into the physical non-cloning function to generate a first response value.
[0039] Physically non-cloning functions can be uniquely identified by their inherent physical structure; that is, given any input stimulus, a physically non-cloning function will output a unique and unpredictable response value.
[0040] In practice, the server can perform an XOR operation on the first random authentication code and the first incentive, and determine the result as the second incentive.
[0041] The server can input the second stimulus into a physically non-clonable function to obtain the first response value corresponding to the second stimulus.
[0042] In step S106, the first random authentication code and the first response value are sent to the Internet of Things device.
[0043] In implementation, IoT devices can determine the third incentive based on the received first random authentication code and the fourth incentive from pre-stored incentives corresponding to the current identity authentication cycle. Then, a second response value corresponding to the third incentive is generated based on the physically unclonable function. Finally, authentication processing can be performed on the server based on the second response value and the received first response value.
[0044] In step S108, the authentication result of the IoT device against the server is received during the current authentication period.
[0045] The identity authentication result can be determined by the IoT device based on the matching detection result of the first response value and the second response value. The second response value can be the response value generated by the IoT device according to the physical non-cloning function and corresponding to the third incentive. The third incentive can be determined by the IoT device based on the first random authentication code and the fourth incentive corresponding to the current identity authentication cycle from the pre-stored incentives.
[0046] In step S110, based on the first identity authentication result, it is determined whether to establish a communication connection with the Internet of Things device.
[0047] In practice, once the IoT device has successfully authenticated the server based on the first identity authentication result, the server can establish a communication connection with the IoT device.
[0048] This specification provides an identity authentication method. Upon successful authentication of an IoT device during the current authentication cycle, a first random authentication code corresponding to the current authentication cycle is generated. A first incentive corresponding to the current authentication cycle is retrieved from pre-stored incentives. A second incentive is determined based on the first random authentication code and the first incentive. The second incentive is input into a physically unclonable function to generate a first response value. The first random authentication code and the first response value are sent to the IoT device. The system receives the authentication result from the IoT device against the server during the current authentication cycle. The authentication result is determined by the IoT device based on the matching detection result of the first and second response values. The second response value is determined by the IoT device based on the physically unclonable function. The LONDON function generates a response value corresponding to the third incentive. The third incentive is determined by the IoT device based on the first random authentication code and the fourth incentive corresponding to the current identity authentication cycle from the pre-stored incentives. Based on the first identity authentication result, it is determined whether to establish a communication connection with the IoT device. In this way, on the one hand, the identity authentication security for IoT devices can be guaranteed through the "incentive-response value" mechanism, which solves the problem that complex security authentication collaboration is difficult to play a role in resource-constrained IoT devices. On the other hand, through two-way authentication between the server and the IoT device, unauthorized data operations can be detected, preventing unauthorized parties from tampering with the communication data between the IoT device and the server, thereby improving the data transmission security of IoT devices.
[0049] In practical applications, before step S102 above, IoT devices can undergo identity authentication. The specific processing methods can vary; one optional method is provided below, such as... Figure 2 and Figure 3 As shown, the specific process may include the following steps S202 to S234.
[0050] In step S202, for each authentication cycle, a first device identifier and incentive corresponding to the IoT device are generated.
[0051] The device identifier corresponding to the current identity authentication period stored by the IoT device may include a first device identifier generated by the server for the IoT device, and the device identifier corresponding to the current identity authentication period stored by the server may include a second device identifier generated by the IoT device based on the first device identifier.
[0052] In step S204, a first message is generated based on the first device identifier and the stimulus.
[0053] In step S206, the first polynomial sent by the IoT device is received.
[0054] In step S208, a second polynomial is generated using a first preset hash function.
[0055] In step S210, a first key is generated based on the first polynomial and the second polynomial, and the first key is sent to the Internet of Things device.
[0056] The first key may include an encryption key and a decryption key. The encryption key may be determined by the inverse polynomial of the first polynomial and the second polynomial, and the decryption key may be determined by the second polynomial and the inverse polynomial of the second polynomial.
[0057] In step S212, the second key sent by the IoT device is received.
[0058] The second key can be generated by the IoT device based on the first polynomial and the third polynomial, and the third polynomial can be generated by the IoT device through the second preset hash function.
[0059] In step S214, the second key is stored.
[0060] In step S216, the first message is encrypted using a pre-constructed first key to obtain the encrypted first message.
[0061] In step S218, the encrypted first message is sent to the IoT device.
[0062] In step S220, an encrypted second message sent by an IoT device is received.
[0063] The encrypted second message can be obtained by encrypting the second message with a pre-built second key by the IoT device. The second message may include a second device identifier generated by the IoT device based on the first device identifier, and a third response value generated by the physical non-cloning function based on the stimulus.
[0064] In step S222, the encrypted second message is decrypted according to the pre-stored second key to obtain the second message.
[0065] In step S224, a fourth response value is generated based on the excitation using a physically non-cloning function, and a matching detection is performed between the third and fourth response values.
[0066] In step S226, if the third response value and the fourth response value match successfully, the second device identifier is stored.
[0067] In implementation, such as Figure 4 As shown, an IoT system can consist of a server, a network, a network management system, and IoT devices with built-in SIM cards. The execution steps of the IoT devices can be performed via their SIM cards, and data interaction between the IoT devices and the server is achieved through the network management system and the network.
[0068] The authentication process between IoT devices and servers can include an initialization phase and a device registration phase.
[0069] The purpose of the initialization phase is to define the second key for IoT devices and the first key for the server, in preparation for the subsequent device registration phase, such as... Figure 5 As shown, the initialization phase may include the following steps:
[0070] Step 1.1: Establish the set of integers and the set of polynomials in the IoT device.
[0071] The set of integers and the set of polynomials can be components of the ciphertext parameters. The set of integers can be a set of numbers containing multiple integers, for example, a set of three integers Z(a,b,c), where a can be a positive prime number, and b and c are coprime (i.e., the greatest common divisor of b and c is 1). The set of polynomials can be a set of multiple polynomials, for example, a set L(LN-1) containing four polynomials of degree N-1 with integer coefficients. j ,L k ,L m ,L n ).
[0072] Step 1.2: The IoT device generates a first polynomial K that satisfies the polynomial set format requirements, for example, K∈L. k .
[0073] Step 1.3: The server generates a set of hash functions H(H) j H k H m H n ).
[0074] Among them, the hash functions in the hash function set can be used to map any input to an N-1 degree polynomial, and the resulting N-1 degree polynomial satisfies the above-mentioned polynomial set format requirements.
[0075] Step 1.4: The server randomly selects a hash function from the generated hash function set H(Hj,Hk,Hm,Hn) as the first preset hash function, and uses the selected first preset hash mapping function to generate the second polynomial. For example, the server can randomly select a hash mapping function Hj from the hash mapping function set H(Hj,Hk,Hm,Hn) as the first preset hash function, and then use the first preset hash function Hj to generate the corresponding second polynomial J, J∈L. j .
[0076] The server can use the first polynomial K and the second polynomial J to generate the first key [h] s,(J,J -1 The server can send this first key to the IoT device, where the encryption key h is part of the first key. s =J -1 *K(mod), J -1 Let J be the inverse polynomial.
[0077] Step 1.5: IoT devices can also use the hash function set H(H) j H k H m H n A hash function is randomly selected from the set of hash functions H(H) as the second preset hash function, and a third polynomial is generated using the selected second preset hash function. For example, an IoT device can generate a third polynomial from the set of hash functions H(H). j H k H m H n The hash function H is randomly selected in the process. m As the second preset hash function, and using the second preset hash function H m Correspondingly, a third polynomial M is generated, M∈L M .
[0078] IoT devices can generate a second key [h] based on the first polynomial K and the third polynomial M. D ,(M,M -1 )], and send the second key to the server side. Among them, h D =M -1 *K(mod), M -1 It is the inverse polynomial of M.
[0079] In this way, through the initialization phase described above, keys for both the IoT device and the server can be defined, and key exchange between the IoT device and the server can be implemented, preparing for subsequent device registration and authentication. Furthermore, during key generation, the IoT device and server can generate keys based on a polynomial generated by a hash function, which can improve the security of key generation.
[0080] The purpose of the device registration phase is to ensure that data can be securely transmitted between IoT devices and servers, such as... Figure 6 As shown, the device registration phase may include the following specific implementation steps:
[0081] Step 2.1: On the server side, a first device identifier and incentive corresponding to the IoT device can be generated for each identity authentication cycle.
[0082] In addition, to prevent IoT devices from being attacked by synchronization attacks or DoS attacks during the authentication process, the server can also generate a temporary identity ID corresponding to the IoT device for each authentication cycle. T and temporary incentives C T .
[0083] The server can package the first device identifier and the incentive into a first message M1, and use the first key [h s ,(J,J -1 The first message M1 is encrypted to obtain the encrypted first message M1. The server can then send the encrypted first message M1 to the IoT device.
[0084] Step 2.2: On the IoT device side, the IoT device can use the first key [h] sent by the server. s ,(J,J -1 The first encrypted message M1 received is decrypted.
[0085] The IoT device can generate a second device identifier (which can be a pseudo-random identity PID for the IoT device) based on the decrypted first device identifier. The IoT device can also generate a third response value R based on an incentive C using a physically non-cloning function. Furthermore, the encrypted first message M1 may also include a temporary incentive C. T Therefore, IoT devices can also generate temporary stimuli C through physically non-cloning functions. T The corresponding temporary response value R T IoT devices can use the second key [h] D ,(M,M -1 The second message M2, consisting of the second device identifier and the third response value, is encrypted to obtain the encrypted second message M2, which is then sent to the server. The IoT device can store the first device identifier and the incentive. Additionally, if the first message M1 also includes a temporary identity ID... T Therefore, IoT devices can also store temporary identity IDs. T .
[0086] Step 2.3: On the server side, the server can decrypt the encrypted second message using the pre-stored second key to obtain the second message, and generate a fourth response value based on the stimulus using a physically non-cloning function. The server can perform a matching check on the third and fourth response values, and if the third and fourth response values match successfully, store the second device identifier.
[0087] In step S228, a device authentication request sent by an IoT device during the current identity authentication cycle is received.
[0088] The device authentication request may include the first verifiable data generated by the IoT device in the secure element for the current identity authentication cycle.
[0089] In step S230, the second verifiable data corresponding to the current identity authentication period is obtained.
[0090] In step S234, the IoT device is authenticated based on the first verifiable data and the second verifiable data.
[0091] The first verifiable data may include a second random authentication code and a first device authentication code generated by the IoT device. The first device authentication code may be generated based on the second random authentication code and a device identifier pre-stored that corresponds to the current identity authentication period. The second verifiable data may include a second device authentication code, which may be generated by the server based on the second random authentication code and a device identifier stored in the server that corresponds to the current identity authentication period.
[0092] In practical applications, the specific processing method for authenticating IoT devices based on the first verifiable data and the second verifiable data in step S234 above can be varied. Here is another optional processing method, which may include the processing of step A1.
[0093] In step A1, the IoT device is authenticated based on the first device authentication code and the second device authentication code.
[0094] In step S236, if the IoT device fails to authenticate during the current authentication cycle, an authentication failure message is sent to the IoT device, and third verifiable data is received from the IoT device.
[0095] The third verifiable data can be the verifiable data generated by the IoT device in the secure element for the previous authentication cycle.
[0096] In step S238, the IoT device is authenticated based on the second verifiable data and the third verifiable data.
[0097] In this way, IoT devices can be subjected to secondary identity verification based on the second and third verifiable data. If identity verification based on the first and second verifiable data fails, but identity verification based on the second and third verifiable data succeeds, it can be determined that the first verifiable data may have been tampered with. If identity verification based on the first and second verifiable data fails, and identity verification based on the second and third verifiable data also fails, it can be determined that there may be a risk of identity theft of IoT devices.
[0098] In practical applications, when authentication of an IoT device fails based on the second and third verifiable data, a temporary identity can be generated. The specific processing methods can vary; one optional method is provided below. Figure 2 and Figure 3 As shown, the specific process may include the following steps S240 to S242.
[0099] In step S240, if the authentication of the IoT device fails based on the second verifiable data and the third verifiable data, a first temporary identity identifier corresponding to the server, a second temporary identity identifier corresponding to the IoT device, and a temporary incentive are generated in the current authentication cycle.
[0100] In step S242, the first temporary identity, the second temporary identity, and the temporary incentive are sent to the Internet of Things device.
[0101] In practice, after sending the first temporary identity, the second temporary identity, and the temporary incentive to the IoT device, the server can delete the first temporary identity, the second temporary identity, and the temporary incentive stored locally to resist DoS attacks and desynchronization attacks, thereby ensuring the anonymity and untraceability of the server.
[0102] Following the device registration phase, a device authentication phase may also be included. This authentication phase enables two-way authentication between the IoT device and the server, such as... Figure 7 As shown, two-way authentication may include the following specific implementation steps:
[0103] Step 3.1: On the IoT device side, the IoT device can generate a second random authentication code P. D IoT devices can generate a first device verification code A based on a second random authentication code and a pre-stored device identifier corresponding to the current authentication period. D , where A D =P D ⊕PID i ⊕ID i PD PID is the second random authentication code corresponding to the i-th round of identity authentication cycle. i and ID i This is the device identifier (i.e., pseudo-random identity identifier and temporary identity identifier) corresponding to the i-th round of identity authentication cycle.
[0104] IoT devices can use a second random authentication code P D And the first device authentication code A D The determined second verifiable data is written into the device authentication request Q1, and the device authentication request Q1 is sent to the server side.
[0105] Step 3.2: On the server side, the server can authenticate the device authentication request Q1.
[0106] (1) The steps for authenticating device authentication request Q1 can be as follows:
[0107] Step 3.21.1: The server obtains the device identifier corresponding to the current identity authentication period;
[0108] Step 3.21.2: The server generates a second device authentication code A based on the second random authentication code and the device identifier stored in the server that corresponds to the current authentication period. S A S =P D ⊕PID i ⊕ID i .
[0109] Step 3.21.3: Extract the first device authentication code A from the received device authentication request Q1. D and the first device authentication code A D With the second device authentication code A S Compare; if the first device authentication code A D With the second device authentication code A S If they are the same, the device authentication is successful; if the first device authentication code A is the same... D With the second device authentication code A S If they are not the same, authentication fails, and proceed to steps 3.21.31-3.21.34.
[0110] Step 3.21.31: Send the authentication failure message to the IoT device side.
[0111] Step 3.21.32: On the IoT device side, use the device identifier of the current authentication round and the device authentication code A calculated in the previous authentication process. D The generated third verifiable data is written into the device authentication request Q2 for the second time, and the device authentication request Q2 is sent to the server side.
[0112] Step 3.21.33: On the server side, extract the device authentication code A calculated during the previous authentication process from the received device authentication request Q2. D And use the device authentication code A calculated during the previous authentication process. D Second device authentication code A corresponding to the current identity authentication cycle S Compare; if the device authentication code A calculated during the previous authentication process... D Second device authentication code A corresponding to the current identity authentication cycle S If the authentication codes are the same, the authentication is successful, and a success message is sent to the IoT device. If the device authentication code A calculated during the previous authentication process is the same... D Second device authentication code A corresponding to the current identity authentication cycle S If they are different, authentication will fail.
[0113] Step 3.21.34: On the IoT device side, if device authentication is successful in step 3.22.23, the device authentication code A calculated in the current authentication round will be used. D Replace with the device authentication code A calculated during the previous authentication process. D .
[0114] Thus, a lightweight public-key encryption algorithm is employed during system initialization, improving authentication efficiency while resisting quantum computing attacks. During device registration, a physically unclonable function is introduced, utilizing its "incentive-response value" mechanism to ensure key security and prevent attackers from modeling the device. In the device authentication phase, a two-way authentication method between the IoT device and the server is adopted, which can resist DoS attacks and desynchronization attacks. Furthermore, the use of backup authentication codes during the two-way authentication process prevents inconsistent code updates from affecting the authentication result.
[0115] In addition, an emergency authentication process can be executed in the event of authentication failure. The emergency authentication process may include the following specific steps:
[0116] Step 3.22.1: On the server side, retrieve the stored temporary stimulus C. T and temporary response value R T .
[0117] Step 3.22.2: The server generates a new pseudo-random identity PID and extracts the temporary incentive C. T and temporary response value R T The new pseudo-random identity PID is sent to the IoT device.
[0118] Step 3.22.3: Delete temporary stimulus CT and temporary response value R T This is to defend against DoS attacks and desynchronization attacks, thereby ensuring the anonymity and untraceability of the server.
[0119] In practical applications, the specific processing method for determining the second incentive based on the first random authentication code and the first incentive in step S104 above can vary. One optional processing method is provided below, such as... Figure 8 As shown, the process may specifically include the following steps S1042 and S1044.
[0120] In step S1042, the first stimulus is divided into a first sub-stimulus and a second sub-stimulus according to a preset splitting rule.
[0121] In step S1044, the second incentive is determined based on the first random authentication code and the first sub-incentive.
[0122] In implementation, the server can split the first stimulus into the first sub-stimulus C according to the bitwise selection method. i1 Second sub-excitation C i2 And then substitute the first random authentication code and the first sub-incentive into the formula,
[0123] C Di =C i1 ⊕P S ,
[0124] The second incentive is obtained, where C Di For the second incentive corresponding to the i-th round of identity authentication, P S This is the first random authentication code.
[0125] In practical applications, the specific processing method for sending the first random authentication code and the first response value to the IoT device in step S106 above can vary. The following provides another optional processing method, such as... Figure 8 As shown, the process may specifically include the following steps, S1062.
[0126] In step S1062, the preset splitting rules, the first random authentication code, and the first response value are sent to the IoT device.
[0127] In practice, the server can package the preset splitting rules, the first random authentication code, and the first response value into a server authentication message M, and send the server authentication message M to the IoT device.
[0128] In practical applications, after step S106 above, if two-way authentication is successful, a communication connection can be established between the IoT device and the server to transmit data based on this connection. Figure 8As shown, the specific process may include the following steps S802 to S806.
[0129] In step S802, if it is determined, based on the first identity authentication result, that a communication connection with the IoT device is to be established, a communication connection with the IoT device is established.
[0130] In step S804, upon receiving a processing request for a target service from an IoT device, the target service is processed, and the service processing result is determined.
[0131] The target business can be any business, such as user authentication business, resource transfer business, instant messaging business, etc.
[0132] In step S806, the business processing result is encrypted using the first key to obtain the encrypted business processing result, and then the encrypted business processing result is returned to the IoT device through the communication connection.
[0133] Lightweight public-key encryption algorithms use only simple polynomial multiplication for encryption and decryption, which is faster than the dot product operation of ECC algorithms. They are also resistant to quantum computing attacks. Compared with other public-key encryption systems, lightweight public-key encryption algorithms require less memory and are faster in encryption, decryption, and signing.
[0134] For the numerous small, low-powered, and resource-constrained IoT devices, lightweight physically unclonable functions can ensure key security attributes, including anonymity, availability, confidentiality, and forward / backward secrecy. Furthermore, physically unclonable functions can leverage uncontrollable random process variations during chip manufacturing to generate unique digital signatures for each device. This ensures attackers cannot obtain any stimulus-response values, protecting the privacy of sensitive information such as device identity and location. Attackers cannot trace device behavior from intercepted messages.
[0135] The two-way authentication between IoT devices and servers can detect unauthorized data operations and prevent modification of communication data in the IoT system. Furthermore, the use of backup authentication codes during the two-way authentication process ensures that information from previous session keys cannot help attackers obtain session keys for subsequent authentications, thereby guaranteeing the security of future communications and preventing devices from being subjected to desynchronization attacks and DoS attacks during the authentication process.
[0136] As more and more devices connect to the Internet of Things (IoT) for remote access and control, various security mechanisms are needed to prevent malicious damage and misuse. As an emerging communication network, the IoT enables interconnection of any object based on the internet, including sensors, tags, and smart devices. The IoT plays a crucial role in various application scenarios in people's lives and work, including smart cities, smart shopping malls, smart banks, smart agriculture, and home automation. Since most IoT devices are unattended, in many cases, specific users need to remotely manage and control the devices via the network, or the devices need to share collected information with specific users. Therefore, various security mechanisms such as identity recognition and access control are required. A common security mechanism is to assign a unique identifier to each IoT device and user to distinguish different users and IoT devices. Furthermore, when IoT devices and users connect to different IoT networks, a specific password is also needed to prevent malicious users or identity forgery.
[0137] In view of this, the technical solution can effectively improve the efficiency of IoT device authentication and prevent malicious attacks during the authentication process, ensuring the security and timeliness of the authentication process.
[0138] This specification provides an identity authentication method. Upon successful authentication of an IoT device during the current authentication cycle, a first random authentication code corresponding to the current authentication cycle is generated. A first incentive corresponding to the current authentication cycle is retrieved from pre-stored incentives. A second incentive is determined based on the first random authentication code and the first incentive. The second incentive is input into a physically unclonable function to generate a first response value. The first random authentication code and the first response value are sent to the IoT device. The system receives the authentication result from the IoT device against the server during the current authentication cycle. The authentication result is determined by the IoT device based on the matching detection result of the first and second response values. The second response value is determined by the IoT device based on the physically unclonable function. The LONDON function generates a response value corresponding to the third incentive. The third incentive is determined by the IoT device based on the first random authentication code and the fourth incentive corresponding to the current identity authentication cycle from the pre-stored incentives. Based on the first identity authentication result, it is determined whether to establish a communication connection with the IoT device. In this way, on the one hand, the identity authentication security for IoT devices can be guaranteed through the "incentive-response value" mechanism, which solves the problem that complex security authentication collaboration is difficult to play a role in resource-constrained IoT devices. On the other hand, through two-way authentication between the server and the IoT device, unauthorized data operations can be detected, preventing unauthorized parties from tampering with the communication data between the IoT device and the server, thereby improving the data transmission security of IoT devices.
[0139] like Figure 9As shown in the embodiments of this specification, an identity authentication method is provided. The subject of this method can be an Internet of Things (IoT) device, which can be any IoT device configured with a SIM card. The method specifically includes the following steps:
[0140] In step S902, the receiving server sends a first random authentication code and a first response value if the IoT device is successfully authenticated in the current authentication cycle.
[0141] The first response value can be the response value generated by the server inputting the second incentive into the physical non-cloning function. The second incentive can be determined based on the first random authentication code and the first incentive. The first incentive can be the incentive corresponding to the current identity authentication cycle from the incentives pre-stored by the server.
[0142] In step S904, the fourth incentive corresponding to the current identity authentication cycle is obtained, and the third incentive is determined based on the fourth incentive and the first random authentication code.
[0143] In S906, the second response value corresponding to the third excitation is determined based on the IoT non-cloning function.
[0144] In S908, the first authentication result for the server is determined based on the matching detection result of the first response value and the second response value, and the first authentication result is returned to the server.
[0145] The first authentication result can be used to trigger the server to determine whether to establish a communication connection with the IoT device.
[0146] The specific processing procedures for steps S902 to S908 can be found in the aforementioned related content, and will not be repeated here.
[0147] This specification provides an identity authentication method. When a server successfully authenticates an IoT device within the current authentication period, it sends a first random authentication code and a first response value. The first response value is a response value generated by the server using a second incentive input to a physically unclonable function. The second incentive is determined based on the first random authentication code and the first incentive, and is a pre-stored incentive corresponding to the current authentication period. A fourth incentive corresponding to the current authentication period is obtained, and a third incentive is determined based on the fourth incentive and the first random authentication code. A second response value corresponding to the third incentive is determined based on the IoT unclonable function. A first identity authentication result is determined for the server based on a matching detection result of the first and second response values, and the first identity authentication result is returned to the server. The first identity authentication result is used to trigger the server to determine whether to establish a communication connection with the IoT device. In this way, on the one hand, the "incentive-response value" mechanism can ensure the security of identity authentication for IoT devices, solving the problem that complex security authentication collaboration is difficult to play a role in resource-constrained IoT devices. On the other hand, through two-way authentication between the server and IoT devices, unauthorized data operations can be detected, preventing unauthorized parties from tampering with the communication data between IoT devices and servers, and improving the data transmission security of IoT devices.
[0148] The above are the identity authentication methods provided in the embodiments of this specification. Based on the same idea, the embodiments of this specification also provide an identity authentication device, such as... Figure 10 As shown.
[0149] The identity authentication device includes: a first generation module 1001, a second generation module 1002, a first sending module 1003, a first receiving module 1004, and a result determination module 1005, wherein:
[0150] The first generation module 1001 is used to generate a first random authentication code corresponding to the current identity authentication period when the identity authentication of the IoT device is successful in the current identity authentication period, and to obtain the first incentive corresponding to the current identity authentication period from the pre-stored incentives.
[0151] The second generation module 1002 is used to determine a second incentive based on the first random authentication code and the first incentive, and input the second incentive into a physical non-cloning function to generate a first response value.
[0152] The first sending module 1003 is used to send the first random authentication code and the first response value to the Internet of Things device;
[0153] The first receiving module 1004 is configured to receive the identity authentication result of the IoT device for the identity authentication device in the current identity authentication cycle. The identity authentication result is determined by the IoT device based on the matching detection result of the first response value and the second response value. The second response value is the response value generated by the IoT device based on the physical unclonable function and corresponding to the third incentive. The third incentive is determined by the IoT device based on the first random authentication code and the fourth incentive corresponding to the current identity authentication cycle from the pre-stored incentives.
[0154] The result determination module 1005 is used to determine whether to establish a communication connection with the Internet of Things device based on the first identity authentication result.
[0155] In the embodiments described in this specification, the device further includes:
[0156] The second receiving module is configured to receive a device authentication request sent by the IoT device during the current identity authentication period, wherein the device authentication request carries first verifiable data generated by the IoT device in the secure element for the current identity authentication period.
[0157] The first acquisition module is used to acquire the second verifiable data corresponding to the current identity authentication period;
[0158] The first authentication module is used to perform identity authentication processing on the IoT device based on the first verifiable data and the second verifiable data.
[0159] In this embodiment of the specification, the first verifiable data includes a second random authentication code and a first device authentication code generated by the IoT device. The first device authentication code is generated based on the second random authentication code and a device identifier pre-stored that corresponds to the current identity authentication period. The second verifiable data includes a second device authentication code, which is generated by the identity authentication device based on the second random authentication code and a device identifier stored in the identity authentication device that corresponds to the current identity authentication period.
[0160] The first authentication module is used to perform identity authentication processing on the IoT device based on the first device authentication code and the second device authentication code.
[0161] In this embodiment of the specification, the device identifier corresponding to the current identity authentication period stored by the IoT device includes a first device identifier generated by the identity authentication device for the IoT device, and the device identifier corresponding to the current identity authentication period stored by the identity authentication device includes a second device identifier generated by the IoT device based on the first device identifier.
[0162] The device further includes:
[0163] The third generation module is used to generate a first device identifier and the incentive corresponding to the IoT device for each identity authentication cycle;
[0164] The first encryption module is used to generate a first message based on the first device identifier and the incentive, and encrypt the first message with a pre-constructed first key to obtain the encrypted first message;
[0165] The second sending module is used to send the encrypted first message to the Internet of Things device;
[0166] The second receiving module is used to receive an encrypted second message sent by the IoT device. The encrypted second message is obtained by the IoT device encrypting the second message using a pre-built second key. The second message includes a second device identifier generated by the IoT device based on the first device identifier, and a third response value generated by the physical non-cloning function based on the stimulus.
[0167] The first decryption module is used to decrypt the encrypted second message according to the pre-stored second key to obtain the second message;
[0168] The matching detection module is used to generate a fourth response value based on the stimulus using the physical non-cloning function, and to perform matching detection on the third response value and the fourth response value.
[0169] The first storage module is used to store the second device identifier when the third response value and the fourth response value match successfully.
[0170] In the embodiments described in this specification, the device further includes:
[0171] The third receiving module is used to receive the first polynomial sent by the IoT device;
[0172] The fourth generation module is used to generate the second polynomial using the first preset hash function;
[0173] The second sending module is used to generate the first key according to the first polynomial and the second polynomial, and send the first key to the Internet of Things device;
[0174] The third receiving module is used to receive the second key sent by the IoT device. The second key is generated by the IoT device according to the first polynomial and the third polynomial. The third polynomial is generated by the IoT device through a second preset hash function.
[0175] The second storage module is used to store the second key.
[0176] The device further includes:
[0177] The data acquisition module is used to send an authentication failure message to the IoT device when the IoT device fails to authenticate during the current authentication cycle, and to receive third verifiable data sent by the IoT device, wherein the third verifiable data is verifiable data generated by the IoT device in the security element for the previous authentication cycle.
[0178] The second authentication module is used to perform identity authentication processing on the IoT device based on the second verifiable data and the third verifiable data.
[0179] In the embodiments described in this specification, the device further includes:
[0180] The message sending module is used to generate a first temporary identity identifier corresponding to the server, a second temporary identity identifier corresponding to the IoT device, and a temporary incentive in the current identity authentication cycle when the identity authentication of the IoT device fails based on the second verifiable data and the third verifiable data.
[0181] The third sending module is used to send the first temporary identity identifier, the second temporary identity identifier, and the temporary incentive to the Internet of Things device.
[0182] In this embodiment of the specification, the second generation module 1002 is used for:
[0183] According to the preset splitting rules, the first incentive is split into a first sub-incentive and a second sub-incentive;
[0184] The second incentive is determined based on the first random authentication code and the first sub-incentive;
[0185] The first sending module 1003 is used to send the preset splitting rule, the first random authentication code and the first response value to the Internet of Things device.
[0186] In the embodiments described in this specification, the device further includes:
[0187] A connection establishment module is used to establish a communication connection with the IoT device when it is determined, based on the first identity authentication result, that a communication connection with the IoT device must be established.
[0188] The business processing module is used to process the target business and determine the business processing result when it receives a processing request for the target business sent by the IoT device.
[0189] The result return module is used to encrypt the business processing result using the first key to obtain the encrypted business processing result, and then return the encrypted business processing result to the IoT device through the communication connection.
[0190] This specification provides an identity authentication device. Upon successful authentication of an IoT device during the current authentication cycle, it generates a first random authentication code corresponding to the current authentication cycle, retrieves a first incentive corresponding to the current authentication cycle from pre-stored incentives, determines a second incentive based on the first random authentication code and the first incentive, inputs the second incentive into a physically unclonable function to generate a first response value, sends the first random authentication code and the first response value to the IoT device, and receives the authentication result from the IoT device against the server during the current authentication cycle. The authentication result is determined by the IoT device based on the matching detection result of the first and second response values. The second response value is determined by the IoT device based on the physically unclonable function. The LONDON function generates a response value corresponding to the third incentive. The third incentive is determined by the IoT device based on the first random authentication code and the fourth incentive corresponding to the current identity authentication cycle from the pre-stored incentives. Based on the first identity authentication result, it is determined whether to establish a communication connection with the IoT device. In this way, on the one hand, the identity authentication security for IoT devices can be guaranteed through the "incentive-response value" mechanism, which solves the problem that complex security authentication collaboration is difficult to play a role in resource-constrained IoT devices. On the other hand, through two-way authentication between the server and the IoT device, unauthorized data operations can be detected, preventing unauthorized parties from tampering with the communication data between the IoT device and the server, thereby improving the data transmission security of IoT devices.
[0191] The above are the identity authentication methods provided in the embodiments of this specification. Based on the same idea, the embodiments of this specification also provide an identity authentication device, such as... Figure 11 As shown.
[0192] The identity authentication device includes: a data receiving module 1101, a data acquisition module 1102, a response value determination module 1103, and a result sending module 1104, wherein:
[0193] The data receiving module 1101 is used to receive a first random authentication code and a first response value sent by the server when the authentication device is successfully authenticated in the current authentication period. The first response value is the response value generated by the server by inputting the second incentive into the physical non-cloning function. The second incentive is determined according to the first random authentication code and the first incentive. The first incentive is the incentive corresponding to the current authentication period from the incentives pre-stored by the server.
[0194] The data acquisition module 1102 is used to acquire the fourth incentive corresponding to the current identity authentication period, and determine the third incentive based on the fourth incentive and the first random authentication code;
[0195] The response value determination module 1103 is used to determine the second response value corresponding to the third stimulus based on the IoT non-cloning function;
[0196] The result sending module 1104 is used to determine the first identity authentication result for the server based on the matching detection result of the first response value and the second response value, and return the first identity authentication result to the server. The first identity authentication result is used to trigger the server to determine whether to establish a communication connection with the identity authentication device.
[0197] This specification provides an identity authentication device that receives a first random authentication code and a first response value sent by a server when the server successfully authenticates an IoT device during the current identity authentication period. The first response value is a response value generated by the server by inputting a second incentive into a physically unclonable function. The second incentive is determined based on the first random authentication code and the first incentive, which is an incentive pre-stored by the server corresponding to the current identity authentication period. A fourth incentive corresponding to the current identity authentication period is obtained, and a third incentive is determined based on the fourth incentive and the first random authentication code. A second response value corresponding to the third incentive is determined based on the IoT unclonable function. A first identity authentication result for the server is determined based on the matching detection result of the first response value and the second response value, and the first identity authentication result is returned to the server. The first identity authentication result is used to trigger the server to determine whether to establish a communication connection with the IoT device. In this way, on the one hand, the "incentive-response value" mechanism can ensure the security of identity authentication for IoT devices, solving the problem that complex security authentication collaboration is difficult to play a role in resource-constrained IoT devices. On the other hand, through two-way authentication between the server and IoT devices, unauthorized data operations can be detected, preventing unauthorized parties from tampering with the communication data between IoT devices and servers, and improving the data transmission security of IoT devices.
[0198] The above are the identity authentication devices provided in the embodiments of this specification. Based on the same idea, the embodiments of this specification also provide an identity authentication device, such as... Figure 12 As shown.
[0199] The identity authentication device can provide terminal devices or servers, etc., for the above embodiments.
[0200] Authentication devices can vary significantly in configuration and performance, and may include one or more processors 1201 and memory 1202. Memory 1202 may store one or more application programs or data. Memory 1202 may be temporary or persistent storage. The application programs stored in memory 1202 may include one or more modules (not shown), each module including a series of computer-executable instructions for the authentication device. Furthermore, processor 1201 may be configured to communicate with memory 1202 and execute the series of computer-executable instructions stored in memory 1202 on the authentication device. The authentication device may also include one or more power supplies 1203, one or more wired or wireless network interfaces 1204, one or more input / output interfaces 1205, and one or more keyboards 1206.
[0201] Specifically, in this embodiment, the identity authentication device includes a memory and one or more programs, wherein one or more programs are stored in the memory, and one or more programs may include one or more modules, and each module may include a series of computer-executable instructions for the identity authentication device, and is configured to be executed by one or more processors. The one or more programs include computer-executable instructions for performing the following:
[0202] If the IoT device is successfully authenticated in the current authentication cycle, a first random authentication code corresponding to the current authentication cycle is generated, and the first incentive corresponding to the current authentication cycle is obtained from the pre-stored incentives.
[0203] The second incentive is determined based on the first random authentication code and the first incentive, and the second incentive is input into the physical non-cloning function to generate the first response value;
[0204] Send the first random authentication code and the first response value to the IoT device;
[0205] The system receives the authentication result of the IoT device in the current authentication period. The authentication result is determined by the IoT device based on the matching detection result of the first response value and the second response value. The second response value is the response value generated by the IoT device based on the physical unclonable function and corresponding to the third incentive. The third incentive is determined by the IoT device based on the first random authentication code and the fourth incentive corresponding to the current authentication period from the pre-stored incentives.
[0206] Based on the first identity authentication result, determine whether to establish a communication connection with the IoT device.
[0207] Specifically, in this embodiment, the identity authentication device includes a memory and one or more programs, wherein one or more programs are stored in the memory, and one or more programs may include one or more modules, and each module may include a series of computer-executable instructions for the identity authentication device, and is configured to be executed by one or more processors. The one or more programs include computer-executable instructions for performing the following:
[0208] If the receiving server successfully authenticates the identity authentication device during the current identity authentication period, it sends a first random authentication code and a first response value. The first response value is the response value generated by the server by inputting a second incentive into the physical non-cloning function. The second incentive is determined based on the first random authentication code and the first incentive. The first incentive is an incentive corresponding to the current identity authentication period from the incentives pre-stored by the server.
[0209] Obtain the fourth incentive corresponding to the current identity authentication period, and determine the third incentive based on the fourth incentive and the first random authentication code;
[0210] Based on the IoT non-cloning function, determine the second response value corresponding to the third stimulus;
[0211] Based on the matching detection result of the first response value and the second response value, a first identity authentication result for the server is determined, and the first identity authentication result is returned to the server. The first identity authentication result is used to trigger the server to determine whether to establish a communication connection with the identity authentication device.
[0212] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the identity authentication device embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the method embodiments.
[0213] This specification provides an identity authentication device that, upon successful authentication of an IoT device during the current authentication cycle, generates a first random authentication code corresponding to the current authentication cycle, retrieves a first incentive corresponding to the current authentication cycle from pre-stored incentives, determines a second incentive based on the first random authentication code and the first incentive, inputs the second incentive into a physically unclonable function to generate a first response value, sends the first random authentication code and the first response value to the IoT device, and receives the authentication result from the IoT device against the server during the current authentication cycle. The authentication result is determined by the IoT device based on the matching detection result of the first response value and the second response value, and the second response value is determined by the IoT device based on the physically unclonable function. The LONDON function generates a response value corresponding to the third incentive. The third incentive is determined by the IoT device based on the first random authentication code and the fourth incentive corresponding to the current identity authentication cycle from the pre-stored incentives. Based on the first identity authentication result, it is determined whether to establish a communication connection with the IoT device. In this way, on the one hand, the identity authentication security for IoT devices can be guaranteed through the "incentive-response value" mechanism, which solves the problem that complex security authentication collaboration is difficult to play a role in resource-constrained IoT devices. On the other hand, through two-way authentication between the server and the IoT device, unauthorized data operations can be detected, preventing unauthorized parties from tampering with the communication data between the IoT device and the server, thereby improving the data transmission security of IoT devices.
[0214] Furthermore, based on the above Figures 1 to 7 The method shown in this specification, along with one or more embodiments, also provides a storage medium for storing computer-executable instruction information. In one specific embodiment, the storage medium can be a USB flash drive, optical disc, hard disk, etc. When the computer-executable instruction information stored in the storage medium is executed by a processor, it can achieve the following process:
[0215] If the IoT device is successfully authenticated in the current authentication cycle, a first random authentication code corresponding to the current authentication cycle is generated, and the first incentive corresponding to the current authentication cycle is obtained from the pre-stored incentives.
[0216] The second incentive is determined based on the first random authentication code and the first incentive, and the second incentive is input into the physical non-cloning function to generate the first response value;
[0217] Send the first random authentication code and the first response value to the IoT device;
[0218] The system receives the authentication result of the IoT device against the server during the current authentication period. The authentication result is determined by the IoT device based on the matching detection result of the first response value and the second response value. The second response value is the response value generated by the IoT device based on the physical unclonable function and corresponding to the third incentive. The third incentive is determined by the IoT device based on the first random authentication code and the fourth incentive corresponding to the current authentication period from the pre-stored incentives.
[0219] Based on the first identity authentication result, determine whether to establish a communication connection with the IoT device.
[0220] Furthermore, based on the above Figures 1 to 7 The method shown in this specification, along with one or more embodiments, also provides a storage medium for storing computer-executable instruction information. In one specific embodiment, the storage medium can be a USB flash drive, optical disc, hard disk, etc. When the computer-executable instruction information stored in the storage medium is executed by a processor, it can achieve the following process:
[0221] If the receiving server successfully authenticates the IoT device during the current authentication period, it sends a first random authentication code and a first response value. The first response value is the response value generated by the server by inputting a second incentive into the physical non-cloning function. The second incentive is determined based on the first random authentication code and the first incentive. The first incentive is an incentive corresponding to the current authentication period from the incentives pre-stored by the server.
[0222] Obtain the fourth incentive corresponding to the current identity authentication period, and determine the third incentive based on the fourth incentive and the first random authentication code;
[0223] Based on the IoT non-cloning function, determine the second response value corresponding to the third stimulus;
[0224] Based on the matching detection result of the first response value and the second response value, a first identity authentication result for the server is determined, and the first identity authentication result is returned to the server. The first identity authentication result is used to trigger the server to determine whether to establish a communication connection with the IoT device.
[0225] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the above-described storage medium embodiment is basically similar to the method embodiment, so the description is relatively simple; relevant parts can be referred to the description of the method embodiment.
[0226] This specification provides a storage medium that, upon successful authentication of an IoT device during the current authentication cycle, generates a first random authentication code corresponding to the current authentication cycle, retrieves a first incentive corresponding to the current authentication cycle from pre-stored incentives, determines a second incentive based on the first random authentication code and the first incentive, inputs the second incentive into a physically unclonable function to generate a first response value, sends the first random authentication code and the first response value to the IoT device, and receives the authentication result from the IoT device against the server during the current authentication cycle. The authentication result is determined by the IoT device based on the matching detection result of the first response value and the second response value, and the second response value is determined by the IoT device based on the physically unclonable function. The function generates a response value corresponding to the third incentive, which is determined by the IoT device based on the first random authentication code and the fourth incentive corresponding to the current identity authentication cycle from the pre-stored incentives. Based on the first identity authentication result, it determines whether to establish a communication connection with the IoT device. In this way, on the one hand, the identity authentication security for IoT devices can be guaranteed through the "incentive-response value" mechanism, solving the problem that complex security authentication collaboration is difficult to play in resource-constrained IoT devices. On the other hand, through two-way authentication between the server and the IoT device, unauthorized data operations can be detected, preventing unauthorized parties from tampering with the communication data between the IoT device and the server, thereby improving the data transmission security of IoT devices.
[0227] Furthermore, based on the above Figures 1 to 9 The method shown in this specification, along with one or more embodiments, also provides a computer program product including a computer program that, when executed by a processor, performs the following process:
[0228] If the IoT device is successfully authenticated in the current authentication cycle, a first random authentication code corresponding to the current authentication cycle is generated, and the first incentive corresponding to the current authentication cycle is obtained from the pre-stored incentives.
[0229] The second incentive is determined based on the first random authentication code and the first incentive, and the second incentive is input into the physical non-cloning function to generate the first response value;
[0230] Send the first random authentication code and the first response value to the IoT device;
[0231] The system receives the authentication result of the IoT device against the server during the current authentication period. The authentication result is determined by the IoT device based on the matching detection result of the first response value and the second response value. The second response value is the response value generated by the IoT device based on the physical unclonable function and corresponding to the third incentive. The third incentive is determined by the IoT device based on the first random authentication code and the fourth incentive corresponding to the current authentication period from the pre-stored incentives.
[0232] Based on the first identity authentication result, determine whether to establish a communication connection with the IoT device.
[0233] Furthermore, based on the above Figures 1 to 9 The method shown in this specification, along with one or more embodiments, also provides a computer program product including a computer program that, when executed by a processor, performs the following process:
[0234] If the receiving server successfully authenticates the IoT device during the current authentication period, it sends a first random authentication code and a first response value. The first response value is the response value generated by the server by inputting a second incentive into the physical non-cloning function. The second incentive is determined based on the first random authentication code and the first incentive. The first incentive is an incentive corresponding to the current authentication period from the incentives pre-stored by the server.
[0235] Obtain the fourth incentive corresponding to the current identity authentication period, and determine the third incentive based on the fourth incentive and the first random authentication code;
[0236] Based on the IoT non-cloning function, determine the second response value corresponding to the third stimulus;
[0237] Based on the matching detection result of the first response value and the second response value, a first identity authentication result for the server is determined, and the first identity authentication result is returned to the server. The first identity authentication result is used to trigger the server to determine whether to establish a communication connection with the IoT device.
[0238] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the above-described embodiment of a computer program product is relatively simple in description because it is fundamentally similar to the method embodiment; relevant parts can be referred to the description of the method embodiment.
[0239] This specification provides a computer program product that, upon successful authentication of an IoT device during the current authentication cycle, generates a first random authentication code corresponding to the current authentication cycle, retrieves a first incentive corresponding to the current authentication cycle from pre-stored incentives, determines a second incentive based on the first random authentication code and the first incentive, inputs the second incentive into a physically unclonable function to generate a first response value, sends the first random authentication code and the first response value to the IoT device, and receives the authentication result from the IoT device for the current authentication cycle. The authentication result is determined by the IoT device based on the matching detection result of the first response value and the second response value, and the second response value is determined by the IoT device based on the physically unclonable function. The cloning function generates a response value corresponding to the third incentive, which is determined by the IoT device based on the first random authentication code and the fourth incentive corresponding to the current identity authentication cycle from the pre-stored incentives. Based on the first identity authentication result, it is determined whether to establish a communication connection with the IoT device. In this way, on the one hand, the identity authentication security for IoT devices can be guaranteed through the "incentive-response value" mechanism, solving the problem that complex security authentication collaboration is difficult to play a role in resource-constrained IoT devices. On the other hand, through two-way authentication between the server and the IoT device, unauthorized data operations can be detected, preventing unauthorized parties from tampering with the communication data between the IoT device and the server, thereby improving the data transmission security of IoT devices.
[0240] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.
[0241] In the 1990s, improvements to a technology could be clearly distinguished as either hardware improvements (e.g., improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to the methodology). However, with technological advancements, many methodological improvements today can be considered direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved methodology into the hardware circuit. Therefore, it cannot be said that a methodological improvement cannot be implemented using a hardware physical module. For example, a Programmable Logic Device (PLD) (e.g., a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logic function is determined by the user programming the device. Designers can program a digital system themselves to "integrate" it onto a PLD, without needing chip manufacturers to design and manufacture dedicated integrated circuit chips. Furthermore, nowadays, instead of manually manufacturing integrated circuit chips, this programming is mostly implemented using "logic compiler" software. Similar to the software compiler used in program development, the original code before compilation must be written in a specific programming language, called a Hardware Description Language (HDL). There are many HDLs, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, and RHDL (Ruby Hardware Description Language). Currently, the most commonly used are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should understand that by simply performing some logic programming on the method flow using one of these hardware description languages and programming it into an integrated circuit, the hardware circuit implementing the logical method flow can be easily obtained.
[0242] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, a computer can be, for example, a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email device, game console, tablet computer, wearable device, or any combination of these devices.
[0243] For ease of description, the above apparatus is described by dividing it into various functional units. Of course, when implementing one or more embodiments of this specification, the functions of each unit can be implemented in one or more software and / or hardware.
[0244] Those skilled in the art will understand that the embodiments of this specification can be provided as methods, systems, or computer program products. Therefore, one or more embodiments of this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, one or more embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0245] Embodiments in this specification are described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this specification. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable parallel device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable parallel device, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0246] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable fraud device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0247] These computer program instructions can also be loaded onto a computer or other programmable device, causing a series of operational steps to be performed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable device for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0248] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0249] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0250] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0251] Those skilled in the art will understand that the embodiments of this specification can be provided as methods, systems, or computer program products. Therefore, one or more embodiments of this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, one or more embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0252] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.
[0253] The above description is merely an embodiment of this specification and is not intended to limit this document. Various modifications and variations can be made to this specification by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this specification should be included within the scope of the claims of this specification.
Claims
1. An identity authentication method, characterized in that, The method is applied to the server side, and the method includes: If the IoT device is successfully authenticated in the current authentication cycle, a first random authentication code corresponding to the current authentication cycle is generated, and the first incentive corresponding to the current authentication cycle is obtained from the pre-stored incentives. The second incentive is determined based on the first random authentication code and the first incentive, and the second incentive is input into the physical non-cloning function to generate the first response value; Send the first random authentication code and the first response value to the IoT device; The system receives the authentication result of the IoT device against the server during the current authentication period. The authentication result is determined by the IoT device based on the matching detection result of the first response value and the second response value. The second response value is the response value generated by the IoT device based on the physical unclonable function and corresponding to the third incentive. The third incentive is determined by the IoT device based on the first random authentication code and the fourth incentive corresponding to the current authentication period from the pre-stored incentives. Based on the authentication result, determine whether to establish a communication connection with the IoT device.
2. The method according to claim 1, characterized in that, Before generating the first random authentication code corresponding to the current identity authentication cycle, if the IoT device is successfully authenticated in the current identity authentication cycle, the method further includes: Receive the device authentication request sent by the IoT device in the current identity authentication cycle, wherein the device authentication request carries first verifiable data generated by the IoT device in the secure element for the current identity authentication cycle; Obtain the second verifiable data corresponding to the current identity authentication period; The IoT device is authenticated based on the first verifiable data and the second verifiable data.
3. The method according to claim 2, characterized in that, The first verifiable data includes a second random authentication code and a first device authentication code generated by the IoT device. The first device authentication code is generated based on the second random authentication code and a device identifier pre-stored that corresponds to the current identity authentication period. The second verifiable data includes a second device authentication code, which is generated by the server based on the second random authentication code and a device identifier stored in the server that corresponds to the current identity authentication period. The step of performing identity authentication processing on the IoT device based on the first verifiable data and the second verifiable data includes: The IoT device is authenticated based on the first device authentication code and the second device authentication code.
4. The method according to claim 3, characterized in that, The device identifier corresponding to the current authentication period stored by the IoT device includes a first device identifier generated by the server for the IoT device, and the device identifier corresponding to the current authentication period stored by the server includes a second device identifier generated by the IoT device based on the first device identifier. Before receiving the device authentication request sent by the IoT device in the current identity authentication cycle, the method further includes: For each authentication cycle, a first device identifier corresponding to the IoT device and the incentive are generated; Based on the first device identifier and the incentive, a first message is generated, and the first message is encrypted using a pre-constructed first key to obtain an encrypted first message; The encrypted first message is sent to the IoT device; The device receives an encrypted second message sent by the IoT device. The encrypted second message is obtained by the IoT device encrypting the second message using a pre-built second key. The second message includes a second device identifier generated by the IoT device based on the first device identifier, and a third response value generated by the physical non-cloning function based on the stimulus. The encrypted second message is decrypted using the pre-stored second key to obtain the second message. A fourth response value is generated based on the excitation using the physical non-cloning function, and a matching detection is performed between the third response value and the fourth response value. If the third response value and the fourth response value match successfully, the second device identifier is stored.
5. The method according to claim 4, characterized in that, Before encrypting the first message using a pre-constructed first key to obtain the encrypted first message, the method further includes: Receive the first polynomial sent by the IoT device; The second polynomial is generated using the first preset hash function; The first key is generated based on the first polynomial and the second polynomial, and the first key is sent to the IoT device. The device receives a second key sent by the IoT device, the second key being generated by the IoT device based on the first polynomial and the third polynomial, the third polynomial being generated by the IoT device through a second preset hash function; Store the second key.
6. The method according to claim 5, characterized in that, The method further includes: If the IoT device fails to authenticate during the current authentication cycle, an authentication failure message is sent to the IoT device, and the third verifiable data sent by the IoT device is received. The third verifiable data is the verifiable data generated by the IoT device in the security element for the previous authentication cycle. The IoT device is authenticated based on the second verifiable data and the third verifiable data.
7. The method according to claim 6, characterized in that, The method further includes: If the authentication of the IoT device fails based on the second verifiable data and the third verifiable data, a first temporary identity identifier corresponding to the server, a second temporary identity identifier corresponding to the IoT device, and a temporary incentive are generated during the current authentication period. The first temporary identity, the second temporary identity, and the temporary incentive are sent to the IoT device.
8. The method according to claim 7, characterized in that, The step of determining the second incentive based on the first random authentication code and the first incentive includes: According to the preset splitting rules, the first incentive is split into a first sub-incentive and a second sub-incentive; The second incentive is determined based on the first random authentication code and the first sub-incentive; Sending the first random authentication code and the first response value to the IoT device includes: The preset splitting rule, the first random authentication code, and the first response value are sent to the IoT device.
9. The method according to claim 8, characterized in that, The method further includes: If, based on the identity authentication result, it is determined that a communication connection must be established with the IoT device, a communication connection is established with the IoT device. Upon receiving a processing request for a target service from the IoT device, the target service is processed, and the processing result is determined. The business processing result is encrypted using the first key to obtain an encrypted business processing result, and then the encrypted business processing result is returned to the IoT device through the communication connection.
10. An identity authentication method, characterized in that, The method is applied to Internet of Things (IoT) devices, and the method includes: If the receiving server successfully authenticates the IoT device during the current authentication period, it sends a first random authentication code and a first response value. The first response value is the response value generated by the server by inputting a second incentive into the physical non-cloning function. The second incentive is determined based on the first random authentication code and the first incentive. The first incentive is an incentive corresponding to the current authentication period from the incentives pre-stored by the server. Obtain the fourth incentive corresponding to the current identity authentication period, and determine the third incentive based on the fourth incentive and the first random authentication code; Based on the physical non-cloning function, determine the second response value corresponding to the third excitation; Based on the matching detection result of the first response value and the second response value, a first identity authentication result for the server is determined, and the identity authentication result is returned to the server. The identity authentication result is used to trigger the server to determine whether to establish a communication connection with the IoT device.
11. An identity authentication device, the device comprising: The first generation module is used to generate a first random authentication code corresponding to the current identity authentication period when the identity authentication of the IoT device is successful in the current identity authentication period, and to obtain the first incentive corresponding to the current identity authentication period from the pre-stored incentives. The second generation module is used to determine a second incentive based on the first random authentication code and the first incentive, and input the second incentive into a physical non-cloning function to generate a first response value; The first sending module is used to send the first random authentication code and the first response value to the Internet of Things device; The first receiving module is configured to receive the authentication result of the IoT device against the authentication device during the current authentication period. The authentication result is determined by the IoT device based on the matching detection result of the first response value and the second response value. The second response value is a response value generated by the IoT device based on the physical unclonable function and corresponding to the third incentive. The third incentive is determined by the IoT device based on the first random authentication code and a fourth incentive corresponding to the current authentication period from pre-stored incentives. The result determination module is used to determine whether to establish a communication connection with the IoT device based on the identity authentication result.
12. An identity authentication device, the device comprising: The data receiving module is used to receive a first random authentication code and a first response value sent by the server when the authentication device is successfully authenticated in the current authentication period. The first response value is the response value generated by the server by inputting a second incentive into the physical non-cloning function. The second incentive is determined based on the first random authentication code and the first incentive. The first incentive is an incentive corresponding to the current authentication period from the incentives pre-stored by the server. The data acquisition module is used to acquire the fourth incentive corresponding to the current identity authentication period, and determine the third incentive based on the fourth incentive and the first random authentication code; The response value determination module is used to determine the second response value corresponding to the third excitation based on the physical non-cloning function; The result sending module is used to determine the first identity authentication result for the server based on the matching detection result of the first response value and the second response value, and return the first identity authentication result to the server. The first identity authentication result is used to trigger the server to determine whether to establish a communication connection with the identity authentication device.
13. An identity authentication device, characterized in that, It includes a processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the computer program, when executed by the processor, implements the steps of the authentication method as described in any one of claims 1 to 10.
14. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, which, when executed by a processor, implements the steps of the authentication method as described in any one of claims 1 to 10.
Citation Information
Patent Citations
Internet of Things security chip trusted mechanism
CN112152816A
Block chain and PUF (Physical Unclonable Function)-based credible Internet of Things system and method
CN116094723A