Industrial control equipment trusted firmware updating method based on physical unclonable function (PUF)
By adopting two-way identity authentication and encryption signature technology based on the physically uncloned function PUF during the firmware update process of industrial control equipment, the problem of lack of authentication mechanism and insufficient security during the firmware update process of industrial control equipment is solved, and the security and integrity of the equipment firmware update process is guaranteed.
Patent Information
- Application Number
- CN202510098923.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-22
- Publication Date
- 2025-05-27
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
There are multiple attack windows during the firmware update process of industrial control devices, and lack a complete two-way identity authentication mechanism, which makes the device susceptible to eavesdropping, replaying, cloning and other attacks, and conventional firmware updates are difficult to meet their security requirements.
The trusted firmware update method of industrial control equipment based on the physically uncloned function PUF is adopted. By generating corresponding response and help data pairs in the initialization and registration stages, two-way identity authentication between the device and the server is ensured, and a temporary session key is used for encryption signature during the firmware update stage.
Effectively prevent external attacks such as eavesdropping attacks, playback attacks, cloning attacks, etc., ensure the security and integrity of the firmware update process of industrial control equipment, and reduce the risk of equipment being maliciously attacked.
Smart Images

Figure CN120046158A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information security of industrial control systems, and particularly relates to a method for updating a trusted firmware of an industrial control device based on a Physical Unclonable Function (PUF). Background Art
[0002] With the continuous progress of technology, more and more advanced technologies such as computers, electrical equipment, and mechanical devices are adopted in industrial production to monitor the physical processes in production. Through a network integrated with intelligent computing, data can be collected and monitored in real time to achieve automated operation, process control, and monitoring of industrial infrastructure, and the network is called the Industrial Internet of Things. The main objectives of traditional Industrial Control Systems (ICS) are to control the production process, reduce resource consumption, and achieve an automated production mode. These systems are widely used in fields such as oil and gas, electricity, water conservancy, transportation, chemical industry, instrumentation, and high-end manufacturing. As the core industrial control device of the industrial control system, it can monitor the production status in real time, execute control and management tasks, and collect and detect various real-time data required in the production process. Industrial control devices are the basic devices of industrial control systems.
[0003] Industrial control devices can be regarded as a type of embedded device and also face related attack threats. Among them, the firmware, as the core foundation for the operation of the device, is crucial for its stability and security. The information contained in the firmware is usually closely related to the normal operation of the device and the privacy protection of users. In addition, firmware update is regarded as an important means to quickly solve software problems, repair security vulnerabilities, and can also add new functions for users to the device and improve the operation experience. Currently, more and more industrial control devices perform firmware updates through the Over The Air (OTA) method. Although OTA upgrades bring convenience to firmware updates, they also place the device on a public network connected to the server, facing additional attack risks and increasing the possibility of malicious attacks on each device by attackers. Among them, security problems caused by network attacks on devices such as eavesdropping, replay, and cloning are becoming increasingly severe. However, due to the limited hardware resources and harsh working environment of industrial control devices, conventional firmware updates are difficult to meet their security requirements.
[0004] The current mainstream OTA firmware upgrade solutions are In-System Programmability (ISP) and In-Application Programming (IAP). Both ISP and IAP technologies can achieve device firmware download, storage, and replacement. However, during the firmware upgrade process of embedded devices, there are multiple attack windows that can be maliciously exploited, such as the initiation of update requests, the transmission, storage, and replacement of firmware data. For example, when the device receives a firmware update request and lacks a perfect two-way authentication mechanism, an attacker can disguise as a server and take the opportunity to send illegal firmware, gaining full control of the device. During the firmware transmission process, an attacker may eavesdrop on the transmission bus or channel, intercept or tamper with the transmitted firmware data packets, and then use reverse engineering to extract local user personal privacy. In addition, an attacker may directly physically attack the device's firmware. If the firmware data is executed without legal and integrity verification, the device may become paralyzed due to loading invalid firmware. Therefore, an industrial control device urgently needs a secure and effective authentication protocol for firmware updates. Summary of the Invention
[0005] Object of the Invention: The object of the present invention is to provide a trusted firmware update method for industrial control devices based on a Physical Unclonable Function (PUF). It provides security for industrial control devices during firmware updates and can prevent external attacks such as eavesdropping attacks, replay attacks, and cloning attacks.
[0006] Technical Solution: A trusted firmware update method for industrial control devices based on a Physical Unclonable Function (PUF) of the present invention includes the following steps:
[0007] Step 1: Before starting the protocol, a pre-initialization stage is carried out on the trusted key registration centers of both the industrial control device and the server;
[0008] Step 2: After the initialization stage is completed, the industrial control device is registered to generate IDs for both the industrial control device and the server. At the same time, the SRAM PUF generation module on the industrial control device is called to generate corresponding response and helper data pairs through the preselected bit screening algorithm and BCH error correction code. After the registration is completed, a session root key and long-term private key pairs for both parties are generated;
[0009] Step 3: After the industrial control device is registered, the firmware of the industrial control device is updated;
[0010] Step 4: The authentication information of the industrial control device is updated, and the industrial control device update key and the server update key are set according to security requirements.
[0011] Further, Step 1 specifically includes the following steps:
[0012] Step 1.1: On a non-singular elliptic curve E, select a cyclic additive group G of large prime order q, a cyclic multiplicative group G T , and a bilinear pairing e: G×G→G T . Let a generator of G be P, and a generator of G T be g;
[0013] Step 1.2: Select a random number s as the system master private key, and calculate Ppub = sP, where P is used as the system master public key; pub
[0014] Step 1.3: Select hash functions {h 0 , h 1 , h 2} that satisfy
[0015] Step 1.4: Secretly store the master private key s, and publicly disclose the parameters {P pub , G, G T , e, P, g, h 0 , h 1 , h 2}.
[0016] Furthermore, Step 2 specifically includes the following steps:
[0017] Step 2.1: Generation of device ID and random stimuli: At the start of the registration phase, the server reads the timestamp of the current environment to generate a random number T 1 , and uses this random number as a seed to generate two random stimuli C 1 , C 2 . The server sends the two stimuli C 1 , C 2 to the device;
[0018] Step 2.2: Generation of physical unclonable function PUF and generation of device registration information: After the device receives the two stimuli, it calls the SRAM PUF generation module on the device. During the process, the device restarts, and through the preselected bit screening algorithm and BCH error correction code, it generates corresponding response and helper data pairs <C 1 , HD 1 > and <C 2 , HD 2 >. The helper data needs to be associated with the stimuli to reproduce the same response for the same stimuli in subsequent phases. Its generation is prepared for the preselection algorithm and error correction algorithm in PUF generation to cope with the possible impacts of environmental temperature, device voltage, and aging on the SRAM hardware, ensuring the accuracy of response restoration. Subsequently, use one of the responses R 1 to generate IDA , then calculate the intermediate parameter D according to the master private key s and the digest of ID A = s + h 0 (ID A ), and then use the intermediate parameter to calculate the long-term private key s of the device respectively A = D A - 1 and the long-term public key P A pub = h 0 (ID A ), the device stores the device identity identifier, the incentive assistance information pair and the device long-term public and private key pair, and then sends the device identifier and two responses R 1 , R 2 to the server;
[0019] Step 2.3, Device registration information generation: After the server receives the responses R 1 , R 2 sent by the device, use one of the responses R 2 to generate ID B , and then generate the root key K of the two identity information of the server and the device; at the same time, the mechanism for registering with the device is the same, calculate the intermediate parameter D according to the master private key s and the digest of ID B = s + h 1 (ID B ), and then use the intermediate parameter to calculate the long-term private key s of the device respectively B = D B - 1 and the long-term public key P B pub = h 1 (ID B ), and then complete the registration.
[0020] Furthermore, step 3 specifically includes the following steps:
[0021] Step 3.1, Device notification publishing: In the device notification publishing stage, the device first reads the identification information stored in the registration stage and sends ID A to the server for verification. The server matches the records in the database. If it is confirmed that ID A is valid and the match is successful, the device is allowed to enter the communication preparation stage; if ID A is invalid or the match fails, it is determined as an illegal device request, and the immediate authentication process is terminated and the service is refused;
[0022] Step 3.2, Server authentication information generation: When the server receives the device identification information, find the associated identity authentication information <C, R>, and then generate the root key After that, generate the time stamp T 2 , and generate the verification information and S 1 = Hmac(K, T 2 )S1, and finally send the server identification information ID B and the verification information H 1 , S 1 to the device;
[0023] Step 3.3, Device authentication information generation: After the device receives the ID B , H 1 , S 1 sent by the server, since the root key K is not stored in the device's memory, according to the PUF generation module, read the <C, HD> information to generate the corresponding R 1 , R 2 ; then generate K according to the same generation rule of the server key, and use the key to restore the server timestamp T 2 ; then restore the authentication information S 1 * = Mmac(K, T 2 ), check whether S 1 * = S 1 is true to verify the server identity; then obtain the current timestamp, check whether T 2 * - T 2 < Δt is true to check the freshness of this message, where Δt represents the maximum allowable delay of the message; after passing the two checks, the device uses a random number generator to generate a random number seed K A for the temporary communication key on the device side this time, and calculate the intermediate parameters R A = K A P, X A = K A s A , Z A = K A (P pub + h 0 (ID B )P), then obtain the verification information S 2 = hash(ID A || R A || K); finally, send the intermediate information R A , X A , Z A and the verification information S 2 and the timestamp T 3 to the server;
[0024] Step 3.4, Firmware encryption and sending: After the server receives the T 3 and S 2After that, the authentication information S is restored using the root key 2 * = hash(ID A ||R A ||K), check if S 2 * = S 2 is true to verify the device identity, then obtain the current timestamp, and check if T 3 * - T 3 < Δt is true to check the message freshness. After the device verification information passes, at this time, the entities of both communication parties obtain authentication. The server uses a random number generator to generate a random number seed K for the temporary key of the server-side communication this time B , and calculate the intermediate parameter C B = K B Z A s B , Z B = K B (P pub + h 0 (ID A )P), then the server obtains the session key SK B = h 2 (R 1 ||R 2 ||C B ), and finally generate the verification information S 3 = hash(ID B ||C B ||K); Sign the firmware using SK B and send the firmware firmware, the signature information H 2 , the intermediate information Z A , the verification information S 2 and the timestamp T 4 to the device;
[0025] Step 3.5. The device accepts the firmware and verifies the signature: After the device receives the information, first calculate C B using the intermediate information Z A = K A Z B s A and S 3 * = hash(ID B ||C A ||K), check if S 3 * = S 3 is true to verify the information of the firmware, then obtain the current timestamp, and check T 4 * - T4 Check the message freshness based on whether Δt is true, and then the device obtains the session key SK for this session. A = h 2 (R 1 || R 2 || C A ) to generate the signature information H 2 * Verify whether the signature is true. After the signature information is confirmed, ensure the integrity and security of the firmware, and the device receives the firmware content.
[0026] Furthermore, step 4 specifically includes the following steps:
[0027] Step 4.1: Device key update: First, update the identification information of the device Then, calculate the intermediate parameter D based on the main private key s and the updated ID A ' A ' = s + h 0 (ID A '), and then use the intermediate parameter to calculate the long-term private key s of the device A ' = D A ' -1 and the long-term public key P A pub' = h 0 (ID A ');
[0028] Step 4.2: Server key update: First, update the identification information of the device Then, calculate the intermediate parameter D based on the main private key s and the updated ID B ' B ' = s + h 0 (ID B '), and then use the intermediate parameter to calculate the long-term private key s of the device B ' = D B ' -1 and the long-term public key P B pub' = h 0 (ID B ');
[0029] After each firmware update, the identification information of both parties is updated using the corresponding incentive C, forming an update chain.
[0030] The present invention also discloses a computer device, including a memory, a processor, and a computer program stored on the memory, and the processor executes the computer program to implement the steps of the method of the present invention.
[0031] The present invention also discloses a computer-readable storage medium, on which computer programs / instructions are stored, and when the computer programs / instructions are executed by a processor, the steps of the method of the present invention are implemented.
[0032] The present invention also discloses a computer program product, including computer programs / instructions, and when the computer programs / instructions are executed by a processor, the steps of the method of the present invention are implemented.
[0033] Beneficial effects: Compared with the prior art, the present invention has the following remarkable advantages:
[0034] (1) The present invention designs a new lightweight trusted firmware update method based on physical unclonable functions, which can provide security for industrial control devices during firmware update and prevent external attacks such as eavesdropping attacks, replay attacks, and cloning attacks.
[0035] (2) The present invention introduces an advanced PUF stable bit selection algorithm to ensure the stability of the PUF produced by the device.
[0036] (3) The present invention guarantees the physical security of industrial control devices, and relevant firmware update information and local update storage cannot be parsed through side-channel attacks or probe attacks.
[0037] (4) The present invention has relatively small computational overhead and communication overhead, meeting the requirements of device lightweighting.
[0038] (5) To resist malicious attacks during the firmware update process, the present invention provides a way of trusted firmware update, solving the problems of lack of authentication mechanism during firmware update of industrial control, vulnerability of firmware information to tampering, and inability to ensure the secure startup of devices. Description of the Drawings
[0039] Figure 1 It is the schematic diagram of the PUF of the present invention;
[0040] Figure 2 It is the model diagram of the initial stage of the present invention;
[0041] Figure 3 It is the process diagram of the registration stage of the present invention;
[0042] Figure 4 It is the process diagram of the firmware update stage of the present invention;
[0043] Figure 5 It is the authentication information update stage of the present invention;
[0044] Figure 6 It is the schematic diagram of the KRC initialization stage of the present invention;
[0045] Figure 7 It is the schematic diagram of the server registration stage of the present invention;
[0046] Figure 8 This is a schematic diagram of the server firmware update and key update phases of the present invention. Detailed implementation manners
[0047] The technical solution of the present invention will be further described below in conjunction with the accompanying drawings.
[0048] (1) Physical unclonable function
[0049] The physical unclonable function (PUF) is essentially a hardware difference caused by process defects, resulting in microscopic differences in the physical structure of the device. In the integrated circuit manufacturing process, silicon semiconductors have subtle differences due to natural environments or external conditions (such as doping concentration, doping depth, oxide layer thickness) during production. These differences cause each excitation (Challenge, C) input to the PUF physical object to generate a uniquely corresponding response (Response, R). The mapping function relationship between the PUF can be defined by Equation (1) through the excitation C and the response R. This unique mapping relationship between the excitation and the response forms an excitation-response pair, that is, CRP.
[0050] R i = PUF(C i ) (1)
[0051] In Equation (1.1), PUF represents an abstract function, which is a mapping of the function of a real physical device. Inputting a binary sequence outputs a corresponding string of responses. C i represents the i-th challenge binary sequence input to the PUF function. R i represents the i-th corresponding response sequence. The detailed principle is as Figure 1 shown.
[0052] (2) Detailed scheme design
[0053] The present invention works in four stages: (1) initialization stage; (2) registration stage; (3) firmware update stage; (4) authentication information update stage. The main objects are industrial control devices, servers, and key registration centers. Before the industrial controller is put into use, its main control chip must contain an SRAM generation module, which is used as a PUF. The first two stages need to be initialized and registered under a protected secure channel. The latter two stages can be carried out in an open channel. After each firmware update, the industrial control device and the server will update the various information required for verification.
[0054] (1) Initialization stage
[0055] Before starting the protocol, a pre-initialization stage is required for the key registration center trusted by both the device and the server. The specific process is as follows:
[0056] 1. On a non-singular elliptic curve E, select a cyclic additive group G of order q, a cyclic multiplicative group G T , and a bilinear pairing e: G×G→G T . A generator of G is P, and a generator of G T is g.
[0057] 2. Select a random number s as the system master private key, where calculate P pub = sP, where P pub serves as the system master public key.
[0058] 3. Select hash functions {h 0 , h 1 , h 2}, satisfying
[0059] 4. Secretly store the master private key s, and publicly disclose the parameters {P pub , G, G T , e, P, g, h 0 , h 1 , h 2}.
[0060] After the initialization phase is completed, the system is established, and then both the device and the server can obtain the public-private key pairs by interacting with their identity information. The detailed model is as Figure 2 shown.
[0061] (2) Registration Phase
[0062] After the initialization phase is completed, the device should be registered before it is put into use or enters the system. The purpose is to generate IDs for both the device and the server, and record the incentive response pair <C, R> of the device. At the same time, the session root key and the long-term private key pairs of both parties are also generated. The detailed process is as Figure 3 shown.
[0063] 1. Device ID and random incentive generation: At the beginning of the registration phase, the server generates a random number T 1 by reading the timestamp of the current environment. Use this random number as a seed to generate two random incentives C 1 , C 2 . The server sends the two incentives C 1 , C 2 to the device.
[0064] 2. PUF Generation and Device Registration Information Generation: After the device receives two stimuli, it calls the SRAM PUF generation module on the device. During the main process, when the device restarts, through the preselected bit screening algorithm and BCH error correction code, the corresponding response and helper data pairs <C 1 , HD 1 > and <C 2 , HD 2 > are generated. The helper data needs to be associated with the stimuli to reproduce the same response for the same stimuli in subsequent stages. Its generation is prepared for the preselection algorithm and error correction algorithm in PUF generation to cope with the possible impacts of environmental temperature, device voltage, aging, etc. on the SRAM hardware, ensuring the accuracy of response restoration. Subsequently, one of the responses R 1 is used to generate ID A , and then the intermediate parameter D A = s + h 0 (ID A ) is calculated according to the main private key s and the digest of ID. Then, the long-term private key s A = D A -1 and the long-term public key P Apub = h 0 (ID A ) of the device are calculated using the intermediate parameter respectively. The device stores the device identity identifier, the stimulus-helper information pair, and the device's long-term public and private key pairs, and then sends the device identifier and the two responses R 1 , R 2 to the server.
[0065] 3. Device Registration Information Generation: After the server receives the responses R 1 , R 2 sent by the device, it uses one of the responses R 2 to generate ID B , and then generates the root key K of the two identity information of the server and the device. At the same time, similar to the device registration mechanism, the intermediate parameter D B = s + h 1 (ID B ) is calculated according to the main private key s and the digest of ID. Then, the long-term private key s B = D B - 1 and the long-term public key P B pub = h 1 (ID B ) of the device are calculated using the intermediate parameter respectively, and then the registration is completed.
[0066] Through the above steps, the device and the server have completed the registration process during the registration phase, and a reliable root key K has been established for each industrial controller device on the server. This root key depends on the physical unclonable characteristics of the SRAM PUF.
[0067] (3) Firmware update phase
[0068] After the device has completed the registration phase and requires firmware update. In this phase, the legitimate authentication of both communication parties will be carried out first to ensure that both parties are trusted communication entities. Then, a secure communication will be established, and a temporary session key will be established using the key exchange protocol. The server will encrypt and sign the firmware using the temporary session key, and the device will check the integrity of the firmware using the temporary session key. If both the authentication and integrity verification pass, it indicates that the update data is available, and the device will perform the firmware update. The detailed process is as Figure 4 shown.
[0069] 1. Device notification: In the device notification phase, the device will first read the identification information stored during the registration phase and send the ID A to the server for verification. The server will match the records in the database. If it confirms that the ID A is valid and the match is successful, the device will be allowed to enter the communication preparation phase; if the ID A is invalid or the match fails, it will be determined as an illegal device request, and the immediate authentication process will be terminated and the service will be refused.
[0070] 2. Server authentication information generation: When the server receives the identification information from the device, it will find the associated authentication information <C, R>, and then generate the root key After that, a timestamp T 2 will be generated, and the verification information and S 1 = Hmac(K, T 2 ) S1 will be generated. Finally, the server identification information ID B and the verification information H 1 , S 1 will be sent to the device.
[0071] 3. Device authentication information generation: After the device receives the ID B , H 1 , S 1 sent by the server, since the root key K is not stored in the device's memory, according to the PUF generation module, the <C, HD> information will be read to generate the corresponding R 1 , R 2 . Then, K will be generated according to the same generation rule as the server key, and the server timestamp T 2 will be restored using the key. Then, the authentication information S 1* = Mmac(K, T 2 ), check S 1 * = S 1 to verify the server's identity. Then obtain the current timestamp and check T 2 * - T 2 < Δt to check the freshness of this message (Δt represents the maximum allowable message delay). After passing the two checks, the device uses a random number generator to generate a random number seed K for the device-side communication temporary key A , and sequentially calculate the intermediate parameters R A = K A P, X A = K A s A , Z A = K A (P pub + h 0 (ID B )P), then obtain the verification information S 2 = hash(ID A || R A || K). Finally, send the intermediate information R A , X A , Z A and the verification information S 2 and the timestamp T 3 to the server.
[0072] 4. Firmware Encryption and Sending: After the server receives T 3 and S 2 sent by the device, use the root key to restore the authentication information S 2 * = hash(ID A || R A || K). Check if S 2 * = S 2 to verify the device's identity. Then obtain the current timestamp and check T 3 * - T 3 < Δt to check the message freshness. After the device's verification information passes, the entities of both communication parties are authenticated at this time. The server uses a random number generator to generate a random number seed K for the server-side communication temporary key B , and sequentially calculate the intermediate parameter C B = K B Z A s B , Z B = KB (P pub +h 0 (ID A )P), then the server obtains the session key SK for this session B =h 2 (R 1 ||R 2 ||C B ), and finally generates the verification information S 3 =hash(ID B ||C B ||K). Sign the firmware using SK B and send the firmware, the signature information H 2 , the intermediate information Z A , the verification information S 2 and the timestamp T 4 to the device.
[0073] 5. The device accepts the firmware and verifies the signature: After receiving the information at the device end, first use the intermediate information Z B to calculate C A =K A Z B s A and S 3 * =hash(ID B ||C A ||K). Check if S 3 * =S 3 is true to verify the information of the firmware. Then obtain the current timestamp and check if T 4 * -T 4 <Δt is true to check the message freshness. Then the device end obtains the session key SK for this session A =h 2 (R 1 ||R 2 ||C A ), generates the signature information H 2 * to compare whether the signature is true. After the signature information is confirmed, the integrity and security of the firmware are ensured, and the device receives the firmware content.
[0074] (4) Authentication information update phase
[0075] Given the sensitive nature of the firmware data and the way it is transmitted through the public channel, this method sets a phase for updating the keys of both parties to meet the high standards of system security. According to specific security requirements, the key update period can be flexibly set. The specific process is as Figure 5 shown.
[0076] 1. Device update key: First, update the identification information of the device Then, calculate the intermediate parameter D according to the master private key s and the updated ID A ' of the digest to calculate the intermediate parameter D A ' = s + h 0 (ID A '), and then use the intermediate parameter to calculate the long-term private key s of the device respectively A ' = D A ' -1 and the long-term public key P A pub' = h 0 (ID A ').
[0077] 2. Server update key: First, update the identification information of the device Then, calculate the intermediate parameter D according to the master private key s and the updated ID B ' of the digest to calculate the intermediate parameter D B ' = s + h 0 (ID B '), and then use the intermediate parameter to calculate the long-term private key s of the device respectively B ' = D B ' -1 and the long-term public key P B pub' = h 0 (ID B )
[0078] The identification information of both parties is updated using the corresponding incentive C each time after the firmware update ends, forming an update chain.
[0079] Embodiment
[0080] The present invention provides an implementation case to demonstrate the interaction process. According to the protocol content, the protocol method simulation between the device and the server is implemented using Python programming. The PyCrypto, ecdsa, and Cryptography libraries are used to simulate the cryptographic security primitive operations. The device and the server are connected through the TCP / IP protocol for network interaction between the two parties. Server environment: windows 11 (64-bit Intel(R) Core(TM) i5-11260H @ 2.60GHz), Vmware Workstation 16.2.4, Ubuntu22.04 (64-bit). The device uses the ccp1080t development board. The device side and the server side are connected to the same network for firmware update protocol authentication, protocol simulation, and overhead calculation. This case uses a bash script to repeat the interaction 100 times.
[0081] First is the initialization phase, which mainly completes the initialization of the encryption system of the non-singular elliptic curve of the Key Registration Center (KRC). As Figure 6 shown, in this case, the KRC is deployed on the server. During the initialization phase, a 256-bit master private key and a master public key are generated and saved in krc_key_pair.json.
[0082] Then, the device registration phase is simulated. This phase is carried out under a secure channel and uses the TCP / IP network for connection. As Figure 7 shown, the server sends an incentive to the device. After receiving it, the device runs the PUF program to generate. The device and the server respectively obtain their own long-term public and private key pairs from the KRC. Then the device sends a response to the server, and the server uses the response to generate the root key.
[0083] Finally, the firmware update phase is simulated. This phase is carried out under an open channel and uses the TCP / IP network for connection. As Figure 8 shown, during this period, the device and the server conduct authentication interactions by themselves. After the authentication is completed, the firmware is transmitted. In this case, a 60.3MB uboot update package is used. The device obtains the firmware package, and at the same time, both parties perform key updates.
[0084] A specific analysis of the time overhead of the firmware update process is carried out. Since the firmware content is large, the time duration of the firmware transmission in the whole process is not included. The average duration of the authentication process is 0.28s, including the time overhead of memory reading and writing, PUF operation, key generation, and various cryptographic calculations. The current test case in this paper is based on software simulation and does not use the cryptographic module or engine inside the development board. In terms of communication overhead, only the messages received by the development board are considered, excluding the firmware size, including (C 1 ,C 2 ,ID B ,H 1 ,S 1 ) and (Z B ,H 2 ,S 3 ,T 4 ), and the total space overhead is 1576bit.
[0085] The calculation of the protocol correctness result of this method is as follows.
[0086] (1) For the bilinear pair calculation formula of the server in the firmware update phase (2)
[0087] e(X A P pub ,P pub +P Apub P) = e(R A ,P pub ) (2)
[0088] The calculation results are as follows:
[0089]
[0090] (2) For the firmware update stage, the temporary session key equation (4) used for firmware encryption and decryption received by the industrial control device
[0091] SK A = SK B (4)
[0092] The calculation results are as follows:
[0093] Among them,
[0094]
[0095] That is to prove, C A = C B Among them,
[0096]
[0097] On the premise of satisfying C A = C B As long as the responses R 1 and R 2 generated by the PUF module of the industrial control device are consistent with the responses stored on the server, the keys used by both parties for encrypting and decrypting the firmware are the same, meeting the requirements.
[0098] As a firmware update method, compared with the existing technical methods. The first advantage is that compared with the existing firmware update methods, it solves the problem of secure communication between industrial control devices and servers during firmware updates, reduces the calculation and communication costs of the existing technical methods, and is more in line with the characteristics of firmware update data transmission. The second advantage is that compared with the existing PUF authentication protocol technical methods, it has characteristics such as two-way identity authentication, data integrity, and forward security, and can effectively resist eavesdropping attacks, replay attacks, cloning attacks, and man-in-the-middle attacks.
Claims
1. A trusted firmware update method for industrial control equipment based on physically unclonable function PUF, characterized in that: The steps include: Step 1: Before starting the protocol, the trusted key registration centers of both the industrial control device and the server are initialized. Step 2: After the initialization phase is completed, the industrial control device is registered, and IDs are generated for both the industrial control device and the server. At the same time, the SRAM PUF generation module on the industrial control device is called to generate the corresponding response and help data pairs through the pre-selected bit screening algorithm and BCH error correction code. After the registration is completed, the session root key and the long-term private key pair of both parties are generated; Step 3: After the industrial control device is registered, update the firmware of the industrial control device; Step 4: Update the authentication information of the industrial control device and set the industrial control device update key and server update key according to security requirements.
2. According to claim 1, a method for updating trusted firmware of industrial control equipment based on physically unclonable function PUF, characterized in that: Step 1 specifically includes the following steps: Step 1.
1. On a non-singular elliptic curve E, select a large prime q-order cyclic additive group G and a cyclic multiplicative group G T , a bilinear pairing e:G×G→G T , a generator of G is P, G T One of the generators of is g; Step 1.2, select a random number s as the system master private key, where Calculate Ppub = sP, where P pub As the system master public key; Step 1.
3. Select a hash function {h0, h1, h2} that satisfies Step 1.4: Secretly save the master private key s and make public the parameters {P pub , G, G T ,e,P,g,h0,h1,h2}.
3. According to claim 1, a method for updating trusted firmware of industrial control equipment based on physically unclonable function PUF, characterized in that: Step 2 specifically includes the following steps: Step 2.1, Device ID and random incentive generation: At the beginning of the registration phase, the server generates a random number T1 by reading the timestamp of the current environment, and uses the random number as a seed to generate two random incentives C1 and C2. The server sends the two incentives C1 and C2 to the device; Step 2.2, Physical Unclonable Function PUF Generation and Device Registration Information Generation: After the device receives two stimuli, the SRAM PUF generation module on the device is called; during the process, the device restarts and generates the corresponding response and help data pair through the pre-selected bit screening algorithm and BCH error correction code.<C1,HD1> and<C2,HD2> , helps data need to be associated with the stimulus, and reproduces the same response for the same stimulus in subsequent stages; uses one of the responses R1 to generate an ID A , and then calculate the intermediate parameter D based on the master private key s and the digest of the ID A =s+h0(ID A ), and then use the intermediate parameters to calculate the long-term private key s of the device A =D A - 1 and the long-term public key P A pub=h0(ID A ), the device stores the device identity, the incentive help information pair and the device long-term public and private key pair, and then sends the device identity and two responses R1 and R2 to the server; Step 2.3, Device registration information generation: After receiving the responses R1 and R2 from the device, the server uses one of the responses R2 to generate an ID B , and then generate the root key K of the two identity information of the server and the device; at the same time, the mechanism is the same as the device registration, and the intermediate parameter D is calculated based on the master private key s and the summary of the ID B =s+h1(ID B ), and then use the intermediate parameters to calculate the long-term private key s of the device B =D B - 1 and the long-term public key P B pub=h1(ID B ) and complete the registration.
4. According to claim 1, a method for updating trusted firmware of industrial control equipment based on physically unclonable function PUF, characterized in that: Step 3 specifically includes the following steps: Step 3.1, Device Release Notification: During the device release notification phase, the device will first read the identification information stored during the registration phase and send the ID A Sent to the server for verification, the server matches the records in the database, and if the ID is confirmed A If the ID is valid and the match is successful, the device is allowed to enter the communication preparation phase; A If it is invalid or the match fails, it is considered as an illegal device request, the immediate authentication process is terminated and the service is denied; Step 3.2, Server authentication information generation: When the server receives the identification information from the device, it finds the identity authentication information associated with it<C,R> , then generate the root key After that, generate timestamp T2 and generate verification information S1=Hmac(K,T2)S1, and finally the server identification information ID B And verification information H1, S1 is sent to the device; Step 3.3, Device authentication information generation: After the device receives the ID sent by the server B , H1, S1, since the root key K is not stored in the device's memory, according to the PUF generation module, read<C,HD> Information is used to generate the corresponding R1 and R2; K is generated according to the same generation rule of the server key, and the key is used to restore the server timestamp T2; then the authentication information S1 is restored * =Mmac(K,T2), check S1 * = Is S1 true to verify the server identity; then get the current timestamp and check T2 * -T2<Δt is true to check the freshness of this message, where Δt represents the maximum delay that the message can be received; after passing the two checks, the device uses a random number generator to generate a random number seed K for the temporary key of this device-side communication A , calculate the intermediate parameters R A =K A P, X A =K A s A , Z A =K A (P pub +h0(ID B )P), then obtain the verification information S2 = hash (ID A ||R A ||K); finally, the intermediate information R A , X A , Z A and verification information S2 and timestamp T3 are sent to the server; Step 3.4, Firmware encryption and sending: After the server receives T3 and S2 from the device, it uses the root key to restore the authentication information S2 * =hash(ID A ||R A ||K), check S2 * =S2 is true to verify the device identity, then get the current timestamp and check T3 * -T3<Δt is true to check the message freshness. After the device verification information is passed, the entities of both parties in communication are authenticated. The server uses a random number generator to generate a random number seed K for the temporary key of this server-side communication. B , calculate the intermediate parameters C in turn B =K B Z A s B , Z B =K B (P pub +h0(ID A )P), then the server obtains the session key SK B =h2(R1||R2||C B ), and finally generate verification information S3 = hash (ID B ||C B ||K); Use SK for the firmware B Sign and send the firmware, signature information H2, intermediate information Z A , verification information S2 and timestamp T4 are sent to the device; Step 3.5: The device accepts the firmware and verifies the signature: After receiving the information on the device side, first use the intermediate information Z B Calculate C A =K A Z B s A and S3 * =hash(ID B ||C A ||K), check S3 * =S3 is true to verify the firmware information, then get the current timestamp, check T4 * -T4<Δt is true to check the message freshness, and then the device obtains the session key SK A =h2(R1||R2||C A ), generate signature information H2 * The signature is compared to see if it is authentic. After the signature information is confirmed, the integrity and security of the firmware are ensured, and the device receives the firmware content.
5. The method for updating trusted firmware of industrial control equipment based on physical unclonable function PUF according to claim 1, characterized in that: Step 4 specifically includes the following steps: Step 4.1, Device update key: First update the device's identification information Then based on the master private key s and the updated ID A 'Summary calculation of intermediate parameters D A '=s+h0(ID A '), and then use the intermediate parameters to calculate the long-term private key s of the device A '=D A ' -1 and the long-term public key P A pub'=h0(ID A '); Step 4.2: Server updates the key: First update the device's identification information Then based on the master private key s and the updated ID B 'Summary calculation of intermediate parameters D B '=s+h0(ID B '), and then use the intermediate parameters to calculate the long-term private key s of the device B '=D B ' -1 and the long-term public key P B pub'=h0(ID B '); Each time after the firmware update is completed, the identification information of both parties is updated using the corresponding stimulus C, forming an update chain.
6. A computer device comprising a memory, a processor and a computer program stored in the memory, characterized in that: The processor executes the computer program to implement the steps of the method of claim 1.
7. A computer-readable storage medium having a computer program / instruction stored thereon, characterized in that: When the computer program / instructions are executed by a processor, the steps of the method according to claim 1 are implemented.
8. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the steps of the method according to claim 1 are implemented.
Citation Information
Cited By
Software upgrading method and device and related equipment
CN120751366A