PUF (Physical Unclonable Function)-based intelligent trusted sensing module, equipment trusted registration and dynamic authentication system and method
By integrating PUF-based intelligent trusted perception modules into IoT devices, the problem of traditional IoT devices lacking security mechanisms in data acquisition is solved, and the device identity uniqueness and data source credibility are achieved, avoiding the risk of data fraud and relying on external auxiliary devices.
Patent Information
- Application Number
- CN202510324069.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-19
- Publication Date
- 2025-06-03
AI Technical Summary
Traditional IoT devices lack effective security mechanisms in the data acquisition process, resulting in the risk of data fraud and relying on external auxiliary equipment to improve data credibility, increasing system complexity and cost, and possibly introducing new security risks.
It adopts an intelligent trusted perception module based on PUF, integrates encryption chip unit, PUF chip unit, microprocessor unit and memory chip unit, and device identity registration and dynamic authentication are carried out through PUF output to ensure the uniqueness of the device identity and the trustworthiness of the data source.
The uniqueness of the device identity is realized, the risk of copying and counterfeiting is avoided, and the dynamic generation of secret keys reduces the security risks of fixed secret key storage, and ensures the authenticity and integrity of the data from the source of data collection without relying on external auxiliary devices.
Smart Images

Figure CN120090807A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security, and more specifically, to an intelligent trusted perception module based on PUF, a device trusted registration and dynamic authentication system, and a method thereof. Background Art
[0002] In recent years, with the rapid development of Internet of Things technology, more and more traditional devices have been connected to the network to achieve intelligent management and data collection. However, there are the following significant problems in the process of source data collection by traditional Internet of Things devices:
[0003] Risk of data fraud: Since traditional devices lack effective security mechanisms, attackers can generate false data by tampering with sensor data or forging device identities. Such data fraud behavior may lead to incorrect system decisions and even cause serious security problems.
[0004] Dependence on auxiliary devices: In order to improve data credibility, many traditional Internet of Things devices need to rely on additional auxiliary devices to provide security guarantees. This method not only increases the complexity and cost of the system, but also may introduce new security risks due to the vulnerabilities of the auxiliary devices themselves.
[0005] Therefore, how to provide an intelligent trusted perception module based on PUF, a device trusted registration and dynamic authentication system, and a method thereof is an urgent problem to be solved by those skilled in the art. Summary of the Invention
[0006] In view of this, the present invention provides an intelligent trusted perception module based on PUF, a device trusted registration and dynamic authentication system, and a method thereof.
[0007] In order to achieve the above object, the present invention adopts the following technical solutions:
[0008] An intelligent trusted perception module based on PUF, comprising:
[0009] An encryption chip unit: for performing cryptographic transformation on the superposition of a random number and a unique ID number according to the registration and authentication process to generate a PUF input;
[0010] A PUF chip unit: for processing the PUF input according to the registration and authentication process to obtain a PUF output;
[0011] A microprocessor unit: for controlling the encryption chip unit, the PUF chip unit, and the storage chip unit, and interacting with Internet of Things devices;
[0012] A storage chip unit: for storing the unique ID number.
[0013] Preferably, the unique ID number includes an intelligent trusted perception module number and an Internet of Things device number.
[0014] A device trusted registration and dynamic authentication system includes: an intelligent trusted perception module, an Internet of Things device, and a cloud server. The intelligent trusted perception module is integrated into the Internet of Things device to form an improved Internet of Things device, and the improved Internet of Things device communicates with the cloud server.
[0015] Preferably, the improved Internet of Things device includes an MCU, a communication module, and the intelligent trusted perception module;
[0016] The MCU is used to receive service data and is connected to the microprocessor unit of the intelligent trusted perception module;
[0017] The communication module is used to communicate with the cloud server and is connected to the MCU.
[0018] A device trusted registration and dynamic authentication method includes:
[0019] Based on the intelligent trusted perception module, the identity registration of the improved Internet of Things device is completed on the cloud server;
[0020] After the identity registration is completed, based on the intelligent trusted perception module, the dynamic authentication process between the cloud server and the improved Internet of Things device is realized.
[0021] Preferably, based on the intelligent trusted perception module, the identity registration of the improved Internet of Things device on the cloud server specifically includes:
[0022] The improved Internet of Things device sends the unique ID number to the cloud server through the communication module;
[0023] The cloud server generates a random number corresponding to the unique ID number and sends it to the improved Internet of Things device;
[0024] The encryption chip unit superimposes the random number and the unique ID number and performs a cryptographic transformation to generate a PUF input;
[0025] The PUF chip unit processes the PUF input to obtain a PUF output;
[0026] The PUF output is returned to the cloud server through the microprocessor unit, the MCU, and the communication module;
[0027] The cloud server saves the PUF output and associates it with the unique ID number and the corresponding random number to complete the registration.
[0028] Preferably, after the identity registration is completed, a dynamic authentication process between the cloud server and the improved Internet of Things device is implemented based on the intelligent trusted perception module, which specifically includes:
[0029] The improved Internet of Things device sends a unique ID number to the cloud server through the communication module;
[0030] The cloud server queries the random number stored corresponding to the unique ID number and sends the random number to the improved Internet of Things device;
[0031] The encryption chip unit performs cryptographic transformation after superimposing the random number and the unique ID number to generate a PUF input;
[0032] The PUF chip unit processes the PUF input to obtain a PUF output;
[0033] The PUF output is returned to the cloud server through the microprocessor unit, MCU, and communication module;
[0034] The cloud server verifies whether the PUF output is consistent with the stored PUF output. If the PUF outputs match, the authentication passes, and the service data is uploaded to the cloud server. If they do not match, the connection is rejected.
[0035] As can be seen from the above technical solutions, compared with the prior art, the present invention discloses an intelligent trusted perception module, a device trusted registration and dynamic authentication system and method based on PUF, which has the following effects:
[0036] 1) Uniqueness of device identity: Integrating the PUF (physically unclonable) function endows traditional Internet of Things devices with the ability not to be replicated or counterfeited.
[0037] 2) Dynamic key generation: By combining the PUF chip with a random number and a unique ID number, a key for registration and authentication is dynamically generated, avoiding the security risks brought by the storage of fixed keys.
[0038] 3) Trustworthiness of source data: The intelligent trusted perception module is directly integrated into traditional Internet of Things devices, ensuring the authenticity and integrity of data from the source of data collection without relying on external auxiliary devices. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.
[0040] Figure 1 Schematic diagram of an intelligent trusted perception module based on PUF provided by the present invention.
[0041] Among them, 1. Encryption chip unit, 2. PUF chip unit, 3. Microprocessor unit, 4. Storage chip unit;
[0042] Figure 2 Principle block diagram of an intelligent trusted perception module based on PUF provided by the present invention.
[0043] Figure 3 Schematic diagram of a device trusted registration and dynamic authentication system provided by the present invention.
[0044] Figure 4 Flowchart of a device trusted registration and dynamic authentication method provided by the present invention. Specific implementation manner
[0045] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0046] An embodiment of the present invention discloses an intelligent trusted perception module based on PUF, as Figure 1 and Figure 2 shown, including:
[0047] Encryption chip unit 1: used to perform cryptographic transformation on the superposition of a random number and a unique ID number according to the registration and authentication process to generate a PUF input, and the unique ID number includes an intelligent trusted perception module number and an Internet of Things device number;
[0048] PUF chip unit 2: used to process the PUF input according to the registration and authentication process to obtain a PUF output;
[0049] Microprocessor unit 3: used to control the encryption chip unit 1, the PUF chip unit 2 and the storage chip unit 4, and interact with the Internet of Things device;
[0050] Storage chip unit 4: used to store the unique ID number.
[0051] Moreover, the intelligent and trustworthy perception module is powered through a power interface relying on the power supply of the improved Internet of Things device. The microprocessor unit 3 is connected to the MCU of the improved Internet of Things device through a communication interface to access the processing flow of the original device system. The storage chip unit 4 of the intelligent and trustworthy perception module also stores registration and authentication programs for the improved Internet of Things device to be called by the microprocessor unit 3 of the intelligent and trustworthy perception module.
[0052] The intelligent and trustworthy perception module of the present invention is of a general type and does not limit the types of Internet of Things devices.
[0053] An embodiment of the present invention discloses a device trustworthy registration and dynamic authentication system, as Figure 3 shown, which includes the intelligent and trustworthy perception module of the above embodiment, and also includes an Internet of Things device and a cloud server. The intelligent and trustworthy perception module is integrated into the Internet of Things device to form an improved Internet of Things device. The improved Internet of Things device communicates with the cloud server, and the identity registration of the improved Internet of Things device is completed on the cloud server based on the intelligent and trustworthy perception module; after the identity registration is completed, the dynamic authentication process between the cloud server and the improved Internet of Things device is realized based on the intelligent and trustworthy perception module.
[0054] The improved Internet of Things device includes an MCU, a communication module, and an intelligent and trustworthy perception module;
[0055] The MCU is used to receive service data and is connected to the microprocessor unit 3 of the intelligent and trustworthy perception module;
[0056] The communication module is used to communicate with the cloud server and is connected to the MCU.
[0057] In this system, before the improved Internet of Things device is initially connected to the cloud server, it needs to complete registration through the PUF chip unit 2 and the encryption chip unit 1 in the bypass-connected intelligent and trustworthy perception module. Among them, the encryption chip unit 1 performs cryptographic transformation on the superposition of the random number and the unique ID number according to the specific registration process to generate the PUF input. The PUF chip unit 2 processes the PUF input according to the specific registration process to obtain the PUF output. The microprocessor unit 3 associates the PUF output with the unique ID number according to the specific registration process and feeds it back to the MCU of the improved Internet of Things device, and uploads it to the cloud server through the communication module, and saves the unique ID number in the local storage chip unit, without locally storing the secret key. In subsequent use, before connecting to the cloud server each time, it needs to complete authentication through the PUF chip unit 2 and the encryption chip unit 1 in the bypass-connected intelligent and trustworthy perception module. The authenticated service data is uploaded to the cloud server through the MCU via the communication module.
[0058] Different from the encryption solutions of traditional Internet of Things devices, once a device installed with an encryption chip is compromised, all devices of the same model are at risk of being replicated and counterfeited; while the intelligent trusted perception module integrated with a PUF (physically unclonable) chip conducts identity authentication based on PUF and thus does not have the above problems.
[0059] Combined with the intelligent trusted perception module, the data collected by the Internet of Things device is processed by the local microprocessor and encryption authentication module within the intelligent trusted perception module and then uploaded to the cloud server through the modified communication module of the device. By combining blockchain technology, human participation is reduced during the process from data generation to storage, thereby realizing the trustworthiness of the entire data process. The characteristics of data immutability and non-repudiation of blockchain are shifted forward to the Internet of Things terminal, ensuring the trustworthiness of the data source at the bottom layer and preventing data fraud.
[0060] The intelligent trusted perception module ensures that the Internet of Things device requires no manual intervention from data collection to cloud storage and can be used in information tracing, identity confirmation, data trusted storage and other links in fields such as high-value commodity traceability and heavy asset management.
[0061] The embodiment of the present invention discloses a method for device trusted registration and dynamic authentication, as Figure 4 shown, including:
[0062] Completing the identity registration of the improved Internet of Things device on the cloud server based on the intelligent trusted perception module;
[0063] After the identity registration is completed, realizing the dynamic authentication process between the cloud server and the improved Internet of Things device based on the intelligent trusted perception module.
[0064] Completing the identity registration of the improved Internet of Things device on the cloud server based on the intelligent trusted perception module specifically includes:
[0065] The improved Internet of Things device sends a unique ID number to the cloud server through the communication module;
[0066] The cloud server generates a random number corresponding to the unique ID number and sends the random number to the improved Internet of Things device, and the improved Internet of Things device sends it to the intelligent trusted perception module;
[0067] The encryption chip unit 1 of the intelligent trusted perception module superimposes the random number and the unique ID number and then conducts a cryptographic transformation to generate a PUF input;
[0068] The PUF chip unit 2 processes the PUF input to obtain a PUF output;
[0069] The PUF output is returned to the cloud server through the microprocessor unit 3, MCU, and communication module;
[0070] The cloud server stores the PUF output and associates it with the unique ID number and the corresponding random number to complete the registration. One or more random numbers can be selected for registration as a backup according to actual requirements.
[0071] After the identity registration is completed, a dynamic authentication process between the cloud server and the improved Internet of Things device is implemented based on the intelligent and trusted perception module, which specifically includes:
[0072] The improved Internet of Things device sends the unique ID number to the cloud server through the communication module, and the cloud server stores the unique ID number;
[0073] The cloud server queries the randomly generated number stored corresponding to the unique ID number and sends the randomly generated number to the improved Internet of Things device;
[0074] The encryption chip unit 1 performs a cryptographic transformation after superimposing the randomly generated number and the unique ID number to generate the PUF input;
[0075] The PUF chip unit 2 processes the PUF input to obtain the PUF output;
[0076] The PUF output is returned to the cloud server through the microprocessor unit 3, the MCU, and the communication module;
[0077] The cloud server verifies whether the PUF output is consistent with the stored PUF output. If the PUF outputs match, the authentication is passed; if not, the connection is rejected.
[0078] After passing the authentication, the cloud server issues an instruction to notify the improved Internet of Things device to upload the service data to the cloud server through the communication module, and the cloud server receives and stores the data uploaded by the improved device.
[0079] In this specification, each embodiment is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the description of the method part.
[0080] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A PUF-based intelligent trusted perception module, characterized in that: include: Encryption chip unit: used to perform cryptographic transformation on the random number and unique ID number according to the registration and authentication process to generate PUF input; PUF chip unit: used to process the PUF input according to the registration and authentication process to obtain a PUF output; Microprocessor unit: used to control the encryption chip unit, PUF chip unit and storage chip unit, and interact with IoT devices; Storage chip unit: used to store the unique ID number.
2. The PUF-based intelligent trusted perception module according to claim 1, characterized in that: The unique ID number includes the intelligent trusted sensing module number and the Internet of Things device number.
3. A device trusted registration and dynamic authentication system, characterized in that: include: An intelligent and trusted sensing module, an Internet of Things device and a cloud server, wherein the intelligent and trusted sensing module is integrated into the Internet of Things device to form an improved Internet of Things device, and the improved Internet of Things device communicates with the cloud server.
4. A device trusted registration and dynamic authentication system according to claim 3, characterized in that: The improved Internet of Things device includes an MCU, a communication module and the intelligent trusted perception module; The MCU is used to receive business data and is connected to the microprocessor unit of the intelligent trusted perception module; The communication module is used to communicate with the cloud server and is connected to the MCU.
5. A device trusted registration and dynamic authentication method, implemented based on the system described in claim 3 or 4, characterized in that: include: Complete the identity registration of the improved IoT device on the cloud server based on the intelligent trusted perception module; After identity registration is completed, a dynamic authentication process between the cloud server and the improved Internet of Things device is implemented based on the intelligent trusted perception module.
6. A device trusted registration and dynamic authentication method according to claim 5, characterized in that: The identity registration of the improved IoT device is completed on the cloud server based on the intelligent trusted perception module, specifically including: The improved IoT device sends a unique ID number to the cloud server through the communication module; The cloud server generates a random number corresponding to the unique ID number and sends it to the improved IoT device; The encryption chip unit superimposes the random number and the unique ID number and performs cryptographic transformation to generate PUF input; The PUF chip unit processes the PUF input to obtain a PUF output; The PUF output is returned to the cloud server through the microprocessor unit, MCU, and communication module; The cloud server saves the PUF output and associates it with the unique ID number and the corresponding random number to complete the registration.
7. A device trusted registration and dynamic authentication method according to claim 6, characterized in that: After identity registration is completed, the dynamic authentication process between the cloud server and the improved IoT device is implemented based on the intelligent trusted perception module, which specifically includes: The improved IoT device sends a unique ID number to the cloud server through the communication module; The cloud server queries the random number stored corresponding to the unique ID number, and sends the random number to the improved IoT device; The encryption chip unit superimposes the random number and the unique ID number and performs cryptographic transformation to generate PUF input; The PUF chip unit processes the PUF input to obtain a PUF output; The PUF output is returned to the cloud server through the microprocessor unit, MCU, and communication module; The cloud server verifies whether the PUF output is consistent with the stored PUF output. If the PUF outputs match, the authentication is successful and the business data is uploaded to the cloud server. If they do not match, the connection is rejected.