Lightweight anonymous mutual authentication method based on PUF (Physical Unclonable Function) in industrial Internet of Things

By adopting a lightweight anonymous mutual authentication method based on PUF in the industrial Internet of Things, using blinded response and dynamic update mechanisms, the problems of CRP leakage and high computing overhead are solved, and effective protection of IIoT device privacy and efficient anonymous authentication are achieved.

CN120110673APending Publication Date: 2025-06-06ANHUI UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411905852.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-23
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

The prior art PUF-based authentication method in the industrial Internet of Things has the risk of CRP leakage, high computing and communication overhead, and is not suitable for devices with limited resources, and cannot effectively protect device privacy and ensure system security.

Method used

A lightweight anonymous mutual authentication method based on PUF is proposed. By performing mutual authentication on the device side and the server side, and using blinded response and dynamic update mechanisms, it reduces the storage and query overhead of CRP and reduces the computing and communication overhead.

Benefits of technology

It effectively protects the privacy of IIoT devices, reduces the risk of CRP leakage, is suitable for devices with limited resources, realizes efficient anonymous mutual authentication, and meets the security and efficiency requirements of the industrial Internet of Things environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120110673A_ABST
    Figure CN120110673A_ABST
Patent Text Reader

Abstract

The invention discloses a lightweight anonymous mutual authentication method based on a PUF (Physical Unclonable Function) in an industrial Internet of Things. The method comprises the following steps: registering a server by an intelligent device embedded with the PUF; the equipment sends an authentication request to the server, and the server responds to the equipment; mutual authentication is carried out between the equipment and the server, the identity of the opposite side is confirmed, and a session key for subsequent communication is negotiated; after authentication between the equipment and the server, some used variables need to be updated to ensure that the communication process is safe and reliable. The invention provides an anonymous mutual authentication method based on a PUF (Physical Unclonable Function). The PUF is used for realizing credible identity authentication between intelligent equipment and a server. Meanwhile, the problem of CRP leakage in the field of PUF-based methods is solved, and a lightweight CRP blinding method based on zero knowledge proof is designed. According to the invention, the safety and the efficiency are effectively balanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to Internet of Things and information security technology, and in particular to a lightweight anonymous mutual authentication method based on PUF in industrial Internet of Things. Background Art

[0002] With the advancement of modern industry, the Industrial Internet of Things (IIoT) has developed rapidly. In the IIoT system, many devices communicate through the network, generating, processing, and transmitting a large amount of data. The openness of the channel can easily lead to data leakage or tampering, making the IIoT system extremely vulnerable to attacks. Dishonest device nodes can steal or leak sensitive information, causing several security issues, including identity and privacy issues. Before the connected IIoT device accesses the IIoT service, verifying its identity is crucial to the entire system. In addition, the privacy of IIoT devices is also important because external attackers can learn business secrets by analyzing the access pattern of the device. Therefore, it is necessary to design a device anonymous authentication method to protect device privacy and ensure the security of IIoT.

[0003] PUF is an integrated circuit (IC) that accepts an input (challenge) and produces an output (response). The output response is not stored in digital memory. PUF is equivalent to a digital fingerprint of a chip. The characteristics of PUF depend on the random physical factors introduced during its manufacturing, which will cause each PUF to have a different microstructure. Since these factors are unpredictable and uncontrollable, it is almost impossible to copy or clone the structure. In general, PUF has the following characteristics: (1) Uniqueness: Each PUF chip is randomly distributed and unique; (2) Anti-cloning: The chip itself is extracted due to uncertain factors during the chip manufacturing process, and the same PUF value cannot be reproduced; (3) Unpredictability: Due to the characteristics of the chip circuit, there is no way to predict the working mode of PUF before it is manufactured; (4) Tamper-proof: The value of the CR pair of PUF cannot be located and modified; (5) No storage required: Each time the PUF is called, it only needs to be extracted from the circuit structure, and no storage device is required to store it.

[0004] In recent years, Physical Unclonable Function (PUF) has emerged as a potential hardware security primitive, which is often used to design authentication methods with reliable and resilient security properties. PUF can be integrated into IoT devices, and each PUF generates a unique output in response to the same challenge. In addition, it reduces the implementation cost of authentication applications while achieving strong security. Existing methods are mainly based on the security properties of PUF, such as tamperability and no storage requirements, and the device-side verifier needs to store the challenge-response pairs (CRPs) of PUF. However, when devices in IIoT are attacked maliciously, there is a risk of CRP leakage. In contrast, an attacker can obtain the CRP relationship of a small number of PUFs by listening to open channels. Then, the attacker can analyze the CRP and use machine learning to infer the response to any challenge with high accuracy.

[0005] Some existing methods currently prevent such machine learning attacks by obfuscating the CRP relationship of PUF. However, existing schemes have problems such as low efficiency and excessive resource consumption, and these methods are not suitable for resource-constrained IIoT devices. On the one hand, some methods solve the CRP leakage problem from a hardware perspective. Different hardware components are used to design the PUF structure to prevent CRP from leaking from the PUF. However, the hardware cost of resource-constrained devices is very high. In addition, the main problem of these methods is that the deployed IIoT devices cannot update the hardware. On the other hand, some methods also use complex cryptographic operations such as bilinear mapping. Most industrial IoT devices are terminal devices with weak communication and computing capabilities and limited resources. The resource consumption of these methods is high and is unaffordable for resource-constrained devices. In addition, anonymity is not considered in most methods, which is also important for IIoT, as mentioned earlier.

[0006] For example, patent CN114389812B discloses a PUF-based lightweight privacy protection batch authentication method for the Internet of Vehicles. The verifier end of this technical solution needs to store the CRP pairs of the PUF, which may cause CRP leakage problems, and the computational overhead and communication overhead of the entire process are high, which is not suitable for the industrial Internet of Things environment; patent CN118138253B discloses a PUF-based power Internet of Things smart terminal authentication method and system. When calculating the extended CRP, both parties to the verification need to perform multiple PUF function calculations, and the cost of PUF calculation is not very low, so both parties to the verification have a large computational overhead, which is not applicable to devices with limited resources and weak computing power.

[0007] In summary, existing technologies require high overall overhead, cannot meet the lightweight requirements of resource-constrained devices, and also face the CRP leakage problem. Summary of the invention

[0008] Purpose of the invention: The purpose of the present invention is to solve the deficiencies in the prior art and to provide a lightweight anonymous mutual authentication method based on PUF in the industrial Internet of Things.

[0009] Technical solution: A lightweight anonymous mutual authentication method based on PUF in an industrial Internet of Things of the present invention comprises the following steps:

[0010] Step (1): The system initiator completes the initialization of related entities, that is, the system server S generates global parameters Paras = {q, G, h, k, H 1 ,H 2 ,H 3}; H 1 ,H 2 ,H 3 are three one-way hash functions, the parameters of the elliptic curve (G, q), and two generators k and h are randomly selected from g;

[0011] Step (2), the registration phase, i.e. the i-th smart device D embedded with PUF i Based on identity information ID i Register with server S through a secure channel to generate a pseudonymous PID for the device i and the blinded response A i ;

[0012] PID i =H 1 (C i ||D i ||b) (1)

[0013]

[0014] Among them, C i is a randomly selected challenge, b is a random number, R i For C i The corresponding response, a i is a random number;

[0015] Step (3), server S and device D i Mutual authentication is performed. Only after mutual authentication is successful can the key negotiation phase be carried out. The specific method is as follows:

[0016] Step (3.1), device selects random number Compute authentication request By E i Initiate an authentication request to the server; at the same time, send the pseudonym PID i and E i Send it to server S through a public channel for authentication, that is, send message M 4 ={PIDi 、E i} to server S;

[0017] Step (3.2), server S receives message M 4 After that, the request information M 4 Perform authentication; if authentication is successful, send the i Return message M 5 ;

[0018] Step (3.3), device D i Received message M 5 After that, the message M 5 The specific steps are as follows:

[0019] The device first records the current time as Then check the freshness of the timestamp to see if the transmission delay is within the allowed time interval ΔT; the device recovers the blind response from the received message and then splices it into Comparison A i and If they are equal, the device successfully authenticates the server; otherwise, the device fails to authenticate the server. After the server authenticates successfully, device D i Generate proof π 1 , and the message M 6 ={π 1 、T D}Send to server S;

[0020] Step (3.4), the server receives the message M 6 After that, the message M 6 To process, the specific steps are as follows:

[0021] First, the server records the current time as Check the transmission delay T again D Is it within the allowed time interval ΔT? Then read the corresponding blind response A of the device from the database i , calculate e 1 , e 1 Compare it with the e sent by the device. If they are equal, the next authentication operation is carried out. If they are not equal, the authentication fails and the server uses e 1 Proceed to the next step of authentication;

[0022] Step (4): After completing the mutual authentication of step (3), the device and the server negotiate the session key. The resulting session key is SK = (A i ) e For subsequent communications;

[0023] Step (5), after the entire session process ends, the CRP, pseudonym and session key are dynamically updated to ensure that the same CR pair is not reused. The specific method is as follows:

[0024] Step (5.1), the device uses the challenge C stored in the database i Generate blind response A i and use A i Generate update request req=E SK (A i ), record the current time as Then the message Send to the server;

[0025] Step (5.2), the server receives the message M 7 After that, record the current time as Generate new blinded response Challenge C i ′ and the ciphertext x, and the message Send to device;

[0026] Step (5.3), the device receives the message M 8 After that, the server records the current time as Decrypt the ciphertext x using the session key SK and get the new challenge C i ′, new response R i ′, the response update increment ΔR, the random number increment is Δa, use the update increment and the random number increment to generate Z, and then use Z and the new challenge C i 'Generate encrypted ciphertext m, generate V = H 3 (SK||m||C i ′);

[0027] Step (5.4), the server uses the ciphertext m and the new challenge C i ′ and the session key to generate V′, compare V and V′, if they are equal, the server recovers Z from the ciphertext m and calculates the new blinded response A′ i , generate a new session key SK 2 ;

[0028] Finally, the device pseudonym and session key are updated.

[0029] When selecting the CRP for verification, the present invention does not choose to store a large amount of data, but selects a pair of CRPs, and does not display the stored response. Secondly, a blinding mechanism is adopted to store only the blinded response, eliminating the risk of CRP leakage. The computational overhead and communication overhead of the present invention are very low, and it is suitable for resource-constrained environments. The computational overhead of the present invention is mainly placed on the server side with rich resources and strong computing power, and only a small amount of PUF calculation operations are performed on the device side. The overall computational overhead is very small, which is more suitable for resource-constrained devices.

[0030] Furthermore, in step (3.2), the server receives a message M sent by the device. 4 After that, the request information is authenticated. The authentication process is as follows;

[0031] Step (3.2.1), the server first records the current time as T s ; Then, server S uses device D i PID sent i Query the corresponding ID in the database i , and the E sent from the device i Extract the random number s; after the extraction is completed, the server S selects the relevant blind response A from the database i Proceed to the next identity verification;

[0032] Step (3.2.2), server S will blindly respond to A i Split into two characters of equal length and in Then, the server S calculates the random number s according to the parsed random number and in and is the intermediate calculation amount, and the calculation formula is as follows:

[0033]

[0034] Step (3.2.3), then, the server S selects a random number And the message Send to device D i .

[0035] Further, the device receives the message M 5 The specific processing steps are as follows:

[0036] Step (3.3.1), the device first records the current time as Then check the freshness of the timestamp to see if the transmission delay is within the allowed time interval ΔT, that is,

[0037] ΔT is the average time threshold (experience value) for the server and the device to complete multiple authentications. To prevent the message from being replayed, the device records the time value T at that moment. D ;

[0038] Step (3.3.2), the device recovers the blind response from the received message, and then splices it into in The device reads the corresponding challenge C from the database i , input the challenge into PUF and get the response R i , with the response R i Generate blind response A i , the calculated value A i Sent by the server Compare them. If they are equal, the authentication of the device to the server succeeds; otherwise, the authentication of the device to the server fails.

[0039] Step (3.3.2), after the server authentication is successful, the device selects two random numbers r 1 and r 1 , calculate the following formula and generate proof π 1 =(t||S 1 ||S 2 ) is used for authentication, where t, e, S 1 ,S 2 is an intermediate variable; the device converts the message M 6 ={π 1 、T d}Send to server:

[0040]

[0041] e=H 2 (t||Nd||A i ) (6)

[0042] S 1 =r 1 +R i e (7)

[0043] S 2 =r 2 +a i e (8).

[0044] Furthermore, the server responds to the message M 6 ={π 1 、T D The specific processing steps are as follows:

[0045] Step (3.4.1), the server first records the current time as Check the transmission delay T again D Is it within the allowed time interval ΔT, that is

[0046] Step (3.4.2), then read the blind response A corresponding to the device from the database i , then from π 1 Analyze t and S 1 and S 2 ; Then calculate e 1 =H 2 (t||Nd||A i ), the calculated value e 1 Compare it with the e sent by the device. If they are equal, proceed to the next authentication operation. If they are not equal, the authentication fails.

[0047] Step (3.4.3), the server uses the calculated e 1 Proceed to the next step of authentication and calculate whether formula (9) is valid:

[0048]

[0049] If the above formula is true, the server successfully authenticates the device; otherwise, the server fails to authenticate the device.

[0050] Furthermore, in step (5.2), the server responds to the message M 7 The specific processing process is as follows:

[0051] Step (5.2.1), the server receives message M 7 After that, first check the transmission delay Is it within the allowed time interval ΔT, that is If it is within the time interval, the server records the current time as

[0052] Step (5.2.2), the server finds the corresponding blinded response A in the database according to the pseudonym of the device i , and use the negotiated session key to decrypt the update request sent by the device to obtain in To decrypt the update request, the blind response is obtained. and A i , see if they are equal, if they are equal, then agree to the device's update request;

[0053] Step (5.2.3), the server selects a new challenge C i ′, encrypt with the session key to get the ciphertext x, x = E SK(C i ′); The server sends the message Send to device.

[0054] Furthermore, the device responds to the message M 8 The processing process is:

[0055] Step (5.3.1), first check the transmission delay Is it within the allowed time interval ΔT, that is If it is within the time interval, the server records the current time as

[0056] Step (5.3.2), then the device uses the negotiated session key SK = (A i ) e Decrypt the message x sent by the server and get a new challenge C i ′, the equipment will bring new challenges to C i ′ Input PUF to get a new response R i ′, and then get the corresponding update increment ΔR = R i ′-R i , and generate a random number a′ i , the increment of the random number is calculated as Δa=a′ i -a i ;

[0057] Step (5.3.3), the device then generates Z using the update increment and the random number increment, and then uses Z and the new challenge C i+1 Generate encrypted ciphertext m, the calculation formula is as follows:

[0058] Z=k ΔR h Δa (10)

[0059]

[0060] Finally, V=H 3 (SK||m||C′ i ), then the device sends the message M 9 ={m,V} is sent to the server.

[0061] Furthermore, the server responds to the message M 9 The specific processing steps are as follows:

[0062] First, the server uses the ciphertext m and the new challenge C i ′ and the session key to generate V′, and compare the received V with the generated V′ to see if they are equal. If they are not equal, the update fails;

[0063] If they are equal, the server recovers Z from the ciphertext and then calculates the new blinded response A′ i , the calculation formula is At the same time, a new session key SK is generated using the new blinded response 2 , the calculation formula is as follows:

[0064] e 2 =H 2 (SK′ i ||C′ i ) (12)

[0065]

[0066] Finally, update the used device pseudonym: set the new device pseudonym to PID′ i =H 1 (PID i ||A′ i ), the data format stored by the server is {PID′ i ,A′ i ,SK 2};

[0067] At the same time, a new session key SK is calculated 2 ;

[0068] The data format stored on the device is {PID′ i , C′ i SK 2}.

[0069] Beneficial effects: Compared with the prior art, the present invention has the following advantages:

[0070] (1) In order to protect the privacy of IIoT devices, a lightweight anonymous mutual authentication method is proposed, and PUF is used to realize trust authentication between smart devices and servers. The present invention imposes minimal computational overhead on the device side. In addition, the establishment of random keys adopts forward secrecy and reverse secrecy.

[0071] (2) In order to solve the CRP leakage problem in the field of PUF-based methods, a lightweight CRP blinding method based on zero-knowledge proof is designed, which is anonymous to external attackers. In addition, the present invention reduces the CRP storage and query overhead on the server side, as well as the communication overhead.

[0072] (3) The present invention conducted a formal security analysis to confirm the security of the proposed method, and the performance analysis showed that the method effectively balanced security and efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0073] Figure 1It is a system model diagram of the present invention;

[0074] Figure 2 The computing overhead and communication overhead of the device and server during the authentication process in the embodiment;

[0075] Figure 3 is the total communication overhead between the device and the server during the authentication process in the embodiment; Figure 4 FIG. 4 is a schematic diagram of the total overhead during the authentication process of the embodiment. DETAILED DESCRIPTION

[0076] The technical solution of the present invention is described in detail below, but the protection scope of the present invention is not limited to the embodiments.

[0077] like Figure 1 As shown, the present invention involves two types of entities: industrial Internet of Things devices and servers. One is the device (Di). Di is the terminal intelligent device in our model, and its computing and storage resources are relatively limited. When the device joins the system, the device initiates an authentication request to the server. After the authentication is passed, the device establishes a connection with the server and accesses the service. PUF is embedded in the device and can perform cryptographic hash functions, XOR operations, scalar multiplication operations, etc. The second is the server (S). The server acts as a semi-honest entity in this method, providing effective authentication resources for the device and having sufficient capabilities to manage complex operations. When the device joins the system, the server authenticates it. After the authentication is passed, the server grants the device business access rights and provides the services required by the device. The server has a local data storage database that can perform cryptographic hash functions, XOR operations, scalar multiplication operations, etc.

[0078] In order to solve the identity recognition and privacy problems of widely deployed smart devices in the industrial Internet of Things environment, and to ensure the legitimacy of the device identity, the present invention first uses the characteristics of PUF to construct an authentication algorithm. This mechanism ensures the security of IIoT device identity authentication and protects device privacy. At the same time, on this basis, the present invention takes into account that the authentication algorithms used in the past are complex and have excessive overhead. These methods are a burden for resource-constrained devices. The present invention constructs a lightweight authentication algorithm to reduce the overhead in the authentication process and meet the requirements of resource-constrained environments. In addition, the present invention avoids the exposure of CR pairs and ensures the safe use of PUF.

[0079] In order to facilitate understanding of the technical method of this embodiment, the meaning of the relevant variables is first explained, and the specific content is shown in Table 1.

[0080] Table 1

[0081]

[0082] The lightweight anonymous mutual authentication method based on PUF in the industrial Internet of Things of this embodiment includes the following steps:

[0083] Step (1): The system initiator completes the initialization of related entities, that is, the system server S generates global parameters Paras = {q, G, h, k, H 1 ,H 2 ,H 3}; H 1 ,H 2 ,H 3 are three one-way hash functions, the parameters of the elliptic curve (G, q), and two generators k and h are randomly selected from g;

[0084] Step (2), the registration phase, i.e. the i-th smart device D embedded with PUF i Based on identity information ID i Register with server S through a secure channel to generate a pseudonymous PID for the device i and the blinded response A i ;

[0085] PID i =H 1 (C i ||D i ||b) (1)

[0086]

[0087] Among them, C i is a randomly selected challenge, b is a random number, R i For C i The corresponding response, a i is a random number;

[0088] Step (3), server S and device D i Mutual authentication is performed. Only after mutual authentication is successful can the key negotiation phase be carried out. The specific method is as follows:

[0089] Step (3.1), device selects random number Compute authentication request By E i Initiate an authentication request to the server; at the same time, send the pseudonym PID i and E i Send it to server S through a public channel for authentication, that is, send message M 4 ={PID i 、E i} to server S;

[0090] Step (3.2), server S receives message M 4 After that, the request information M4 Perform authentication; if authentication is successful, send the i Return message M 5 ;

[0091] Step (3.3), device D i Received message M 5 After that, the message M 5 To process, the specific steps are as follows:

[0092] The device first records the current time as Then check the freshness of the timestamp to see if the transmission delay is within the allowed time interval ΔT; the device recovers the blind response from the received message and then splices it into Comparison A i and If they are equal, the device successfully authenticates the server; otherwise, the device fails to authenticate the server. After the server authenticates successfully, device D i Generate proof π 1 , and message M 6 ={π 1 , T D}Send to server S;

[0093] Step (3.4), the server receives the message M 6 After that, the message M 6 To process, the specific steps are as follows:

[0094] First, the server records the current time as Check the transmission delay T again D Is it within the allowed time interval ΔT? Then read the corresponding blind response A of the device from the database i , calculate e 1 , e 1 Compare it with the e sent by the device. If they are equal, the next authentication operation is carried out. If they are not equal, the authentication fails and the server uses e 1 Proceed to the next step of authentication;

[0095] Step (4): After completing the mutual authentication of step (3), the device and the server negotiate the session key. The resulting session key is SK = (A i ) e For subsequent communications;

[0096] Step (5), after the entire session process ends, the CRP, pseudonym and session key are dynamically updated to ensure that the same CR pair is not reused. The specific method is as follows:

[0097] Step (5.1), the device uses the challenge C stored in the database iGenerate blind response A i and use A i Generate update request req=E SK (A i ), record the current time as Then the message Send to the server;

[0098] Step (5.2), the server receives the message M 7 After that, record the current time as Generate new blinded response Challenge C i ′ and the ciphertext x, and the message Send to device;

[0099] Step (5.3), the device receives the message M 8 After that, the server records the current time as Decrypt the ciphertext x using the session key SK and obtain the new challenge C′ i , the new response R′ i , the response update increment ΔR, the random number increment is Δa, use the update increment and the random number increment to generate Z, and then use Z and the new challenge C′ i Generate encrypted ciphertext m, generate V = H 3 (SK||m||C′ i );

[0100] Step (5.4), the server uses the ciphertext m and the new challenge C i ′ and the session key to generate V′, compare V and V′, if they are equal, the server recovers Z from the ciphertext m and calculates the new blinded response A′ i , generate a new session key SK 2 ;

[0101] Finally, the device pseudonym and session key are updated.

[0102] In step (3.2) of this embodiment, the server receives the message M sent by the device 4 After that, the request information is authenticated. The authentication process is as follows;

[0103] Step (3.2.1), the server first records the current time as T s ; Then, server S uses device D i PID sent i Query the corresponding ID in the database i , and the E sent from the device i Extract the random number s; after the extraction is completed, the server S selects the relevant blind response A from the database i Proceed to the next identity verification;

[0104] Step (3.2.2), server S will blindly respond to A i Split into two characters of equal length and in Then, the server S calculates the random number s according to the parsed random number and in and is the intermediate calculation amount, and the calculation formula is as follows:

[0105]

[0106] Step (3.2.3), then, the server S selects a random number And the message Send to device D i .

[0107] In this embodiment, the device receives the message M 5 The specific processing steps are as follows:

[0108] Step (3.3.1), the device first records the current time as Then check the freshness of the timestamp to see if the transmission delay is within the allowed time interval ΔT, that is,

[0109] ΔT is the average time threshold (experience value) for the server and the device to complete multiple authentications. To prevent the message from being replayed, the device records the time value T at that moment. D ;

[0110] Step (3.3.2), the device recovers the blind response from the received message, and then splices it into in The device reads the corresponding challenge C from the database i , input the challenge into PUF and get the response R i , with the response R i Generate blind response A i , the calculated value A i Sent by the server Compare them. If they are equal, the authentication of the device to the server succeeds; otherwise, the authentication of the device to the server fails.

[0111] Step (3.3.2), after the server authentication is successful, the device selects two random numbers r 1 and r 1 , calculate the following formula and generate proof π 1 =(t||S1 ||S 2 ) is used for authentication, where t, e, S 1 ,S 2 is an intermediate variable; the device converts the message M 6 ={π 1 , T D}Send to server:

[0112]

[0113] e=H 2 (t||Nd||A i ) (6)

[0114] S 1 =r 1 +R i e (7)

[0115] S 2 =r 2 +a i e (8).

[0116] In this embodiment, the server sends the message M 6 ={π 1 , T D The specific processing steps are as follows:

[0117] Step (3.4.1), the server first records the current time as Check the transmission delay T again D Is it within the allowed time interval ΔT, that is

[0118] Step (3.4.2), then read the blind response A corresponding to the device from the database i , then from π 1 Analyze t and S 1 and S 2 ; Then calculate e 1 =H 2 (t||Nd||A i ), the calculated value e 1 Compare it with the e sent by the device. If they are equal, proceed to the next authentication operation. If they are not equal, the authentication fails.

[0119] Step (3.4.3), the server uses the calculated e 1 Proceed to the next step of authentication and calculate whether formula (9) is valid:

[0120]

[0121] If the above formula is true, the server successfully authenticates the device; otherwise, the server fails to authenticate the device.

[0122] In step (5.2) of this embodiment, the server responds to the message M 7 The specific processing process is as follows:

[0123] Step (5.2.1), the server receives message M 7 After that, first check the transmission delay Is it within the allowed time interval ΔT, that is If it is within the time interval, the server records the current time as

[0124] Step (5.2.2), the server finds the corresponding blinded response A in the database according to the pseudonym of the device i , and use the negotiated session key to decrypt the update request sent by the device to obtain in To decrypt the update request, the blind response is obtained. and A i , see if they are equal, if they are equal, then agree to the device's update request;

[0125] Step (5.2.3), the server selects a new challenge C i ′, encrypt with the session key to get the ciphertext x, x = E SK (C i ′); The server sends the message Send to device.

[0126] In this embodiment, the device sends the message M 8 The processing process is:

[0127] Step (5.3.1), first check the transmission delay Is it within the allowed time interval ΔT, that is If it is within the time interval, the server records the current time as

[0128] Step (5.3.2), then the device uses the negotiated session key SK = (A i ) e Decrypt the message x sent by the server and get a new challenge C i ′, the equipment will bring new challenges to C i ′ Input PUF to get a new response R i ′, and then get the corresponding update increment ΔR = R i ′-R i , and generate a random number a i ′, the increment of the random number is calculated as Δa=a′i -a i ;

[0129] Step (5.3.3), the device then generates Z using the update increment and the random number increment, and then uses Z and the new challenge C i+1 Generate encrypted ciphertext m, the calculation formula is as follows:

[0130] Z=k ΔR h Δa (10)

[0131]

[0132] Finally, V=H 3 (SK||m||C′ i ), then the device sends the message M 9 ={m,V} is sent to the server.

[0133] In this embodiment, the server sends the message M 9 The specific processing steps are as follows:

[0134] First, the server uses the ciphertext m and the new challenge C i ′ and the session key to generate V′, and compare the received V with the generated V′ to see if they are equal. If they are not equal, the update fails;

[0135] If they are equal, the server recovers Z from the ciphertext and then calculates the new blinded response A′ i , the calculation formula is At the same time, a new session key SK is generated using the new blinded response 2 , the calculation formula is as follows:

[0136] e 2 =H 2 (A′ i ||C′ i ) (12)

[0137]

[0138] Finally, update the used device pseudonym: set the new device pseudonym to PID i ′=H 1 (PID i ||A′ x ), the data format stored by the server is {PID i ′,A′ i ,SK 2};

[0139] At the same time, a new session key SK is calculated 2 ;

[0140] The data format stored on the device is {PID i ′、C i ′, SK 2}.

[0141] Example:

[0142] This embodiment runs on the Windows operating system, and the host is equipped with a 2.5 GHz Intel Core i7-11700 CPU and 16 GB RAM. The computational overhead of each operation of this method is shown in Table 2, and the byte size of each operation is shown in Table 3:

[0143] Table 2

[0144]

[0145]

[0146] In Table 3, OP stands for operation, T stands for running time, and T sm Represents the scalar multiplication operation associated with the elliptic curve, T add represents the point addition operation related to the elliptic curve, T PUF represents PUF operation, T h Represents hash, T FHD Indicates FHD operation, T bp Represents the bilinear pairing operation.

[0147] Table 3

[0148]

[0149] According to the above operations, the actual application calculation overhead and communication overhead results of the present invention are shown in Table 4. This result clearly shows that the calculation overhead of the present invention is very lightweight and has obvious advantages over the existing methods.

[0150] Table 4

[0151]

[0152] The calculation of the present invention on the verifier side involves one hash operation, three scalar multiplication operations, and two point addition operations, and the total calculation cost is 3Tsm+1Tadd+1Th=0.654ms. On the IoT device side, it mainly involves two scalar multiplication operations, one point addition operation, and one hash operation, and the total calculation time required is 2T sm +1T add +1T h =0.437ms.

[0153] Combination Figure 2It can be seen that the present invention has relatively low overhead on both the device side and the verifier side, and the present invention does not require an additional trusted third party and service provider, further reducing storage overhead and computing overhead. The present invention has very low overhead on the device side, which reduces the computing pressure on the device side and moves the computing pressure to the server side with high computing performance.

[0154] In the analysis process, the present invention takes into account the communication overhead in the AKA process. According to the National Institute of Standards and Technology (NIST) standard, 128 full strength requires the size of the hash function and elliptic curve to be 256 and 256 bytes respectively. In the following comparison, this embodiment only involves the necessary information of AKA. Table 4 shows the final comparison results.

[0155] The device of the present invention needs to send M 4 ={PID i 、E i} and M 6 ={π 1 、T D}, so the communication overhead is On the verifier side, you need to send The communication cost is The total communication cost of this example is 496 bytes, combined with Figure 3 and Figure 4 It can be seen that the communication overhead of the present invention on both the device side and the verifier side is relatively small, meeting the needs of resource-constrained devices.

[0156] Table 4

[0157] Secunty Properties Ours Mutual Authentication √ No Third Party Required √ No Explicit CRP √ No NVM Required √ Session Key Agreement √ Resist Replay Attack √ Forward Secrecy √ Backward Secrecy √ Untraccability √

Claims

1. A lightweight anonymous mutual authentication method based on PUF in industrial Internet of Things, characterized in that: The following steps are involved: Step (1), the system initiator completes the initialization of related entities, that is, the system server S generates global parameters Paras = {q, H, h, k, H1, H2, H3}; H1, H2, H3 are three one-way hash functions, the parameters of the elliptic curve (G, q), and randomly selects two generators k and h; Step (2), the registration phase, i.e. the i-th smart device D embedded with PUF i Based on identity information ID i Register with server S through a secure channel to generate a pseudonymous PID for the device i and the blinded response A i ; PID i =H1(C i ||D i ||b) (1) Among them, C i is a randomly selected challenge, b is a random number, R i For C i The corresponding response, a i is a random number; Step (3), server S and device D i Mutual authentication is performed. Only after mutual authentication is successful can the key negotiation phase be carried out. The specific method is as follows: Step (3.1), device selects random number Compute authentication request By E i Initiate an authentication request to the server; at the same time, send the pseudonym PID i and E i Send it to the server S through the public channel for authentication, that is, send message M4 = {PID i 、E i } to server S; Step (3.2), after receiving the message M4, the server S authenticates the request message M4; if the authentication is successful, it sends a i Return message M5; Step (3.3), device D i After receiving message M5, the message M5 is processed. The specific steps are as follows: The device first records the current time as Then check the freshness of the timestamp to see if the transmission delay is within the allowed time interval ΔT; the device recovers the blind response from the received message and then splices it into Comparison A i and If they are equal, the device successfully authenticates the server; otherwise, the device fails to authenticate the server. After the server authenticates successfully, device D i Generate proof π1, and message M6 = {π1, T D }Send to server S; Step (3.4), after receiving the message M6, the server processes the message M6. The specific steps are as follows: First, the server records the current time as Check the transmission delay T again D Is it within the allowed time interval ΔT? Then read the corresponding blind response A of the device from the database i , calculate e1, compare e1 with the e sent by the device, if they are equal, proceed to the next authentication operation, if they are not equal, the authentication fails, and the server uses e1 for the next authentication; Step (4): After completing the mutual authentication of step (3), the device and the server negotiate the session key. The resulting session key is SK = (A i ) e For subsequent communications; Step (5), after the entire session process ends, the CRP, pseudonym and session key are dynamically updated to ensure that the same CR pair is not reused. The specific method is as follows: Step (5.1), the device uses the challenge C stored in the database i Generate blind response A i and use A i Generate update request req=E SK (A i ), record the current time as Then the message Send to the server; Step (5.2), after the server receives message M7, it records the current time as Generate new blinded response Challenge C′ i and the ciphertext x, and the message Send to device; Step (5.3), after the device receives message M8, the server records the current time as Decrypt the ciphertext x using the session key SK and obtain the new challenge C′ i , the new response R′ i , the response update increment ΔR, the random number increment is Δa, use the update increment and the random number increment to generate Z, and then use Z and the new challenge C′ i Generate encrypted ciphertext m, generate V = H3 (SK || m || C ′ i ); Step (5.4), the server uses the ciphertext m and the new challenge C′ i And the session key generates V', compares V and V', if they are equal, the server recovers Z from the ciphertext m and calculates the new blinded response A' i , generate a new session key SK2; Finally, the device pseudonym and session key are updated.

2. The lightweight anonymous mutual authentication method based on PUF in the industrial Internet of Things according to claim 1 is characterized in that: In step (3.2), after the server receives the message M4 sent by the device, it authenticates the request information. The authentication process is as follows; Step (3.2.1), the server first records the current time as T s ; Then, server S uses device D i PID sent i Query the corresponding ID in the database i , and the E sent from the device i Extract the random number s; after the extraction is completed, the server S selects the relevant blind response A from the database i Proceed to the next identity verification; Step (3.2.2), server S will blindly respond to A i Split into two characters of equal length and in Then, the server S calculates the random number s according to the parsed random number and in and is the intermediate calculation amount, and the calculation formula is as follows: Step (3.2.3), then, the server S selects a random number And the message Send to device D i .

3. The lightweight anonymous mutual authentication method based on PUF in the industrial Internet of Things according to claim 1 or 2, characterized in that: The specific processing steps after the device receives message M5 are as follows: Step (3.3.1), the device first records the current time as Then check the freshness of the timestamp to see if the transmission delay is within the allowed time interval ΔT, that is, ΔT is the average time threshold for the server and the device to complete multiple authentications. The device records the time value T at that moment. D ; Step (3.3.2), the device recovers the blind response from the received message, and then splices it into in The device reads the corresponding challenge C from the database i , input the challenge into PUF and get the response R i , with the response R i Generate blind response A i , the calculated value A i Sent by the server Compare them. If they are equal, the authentication of the device to the server succeeds; otherwise, the authentication of the device to the server fails. Step (3.3.2), after the server authentication is successful, the device selects two random numbers r1 and r1, calculates the following formula, and generates a proof π1 = (t||S1||S2) for authentication, where t, e, S1, S2 are intermediate variables; the device sends the message M6 = {π1, T D }Send to server: e=H2(t||Nd||A i ) (6) S1=r1+R i e (7) S2=r2+a i e (8)。 4. The lightweight anonymous mutual authentication method based on PUF in the industrial Internet of Things according to claim 1 or 3, characterized in that: The server responds to the message M6 = {π1, T D The specific processing steps are as follows: Step (3.4.1), the server first records the current time as Check the transmission delay T again D Is it within the allowed time interval ΔT, that is Step (3.4.2), then read the blind response A corresponding to the device from the database i , and then resolve t, S1 and S2 from π1; then calculate e1=H2(t||Nd||A i ), compare the calculated value e1 with the e sent by the device. If they are equal, the next authentication operation is performed. If they are not equal, the authentication fails; Step (3.4.3), the server uses the calculated e1 to perform the next authentication and calculate whether formula (9) is valid: If the above formula is true, the server successfully authenticates the device; otherwise, the server fails to authenticate the device.

5. The lightweight anonymous mutual authentication method based on PUF in industrial Internet of Things according to claim 1 is characterized in that: The specific processing process of the server for message M7 in step (5.2) is as follows: Step (5.2.1), after receiving message M7, the server first checks the transmission delay Is it within the allowed time interval ΔT, that is If it is within the time interval, the server records the current time as Step (5.2.2), the server finds the corresponding blinded response A in the database according to the pseudonym of the device i , and use the negotiated session key to decrypt the update request sent by the device to obtain in To decrypt the update request, the blind response is obtained. and A i , see if they are equal, if they are equal, then agree to the device's update request; Step (5.2.3), the server selects a new challenge C i ′ , encrypted with the session key, and the ciphertext x is obtained, x = E SK (C i ′ ); the server sends the message Send to device.

6. The lightweight anonymous mutual authentication method based on PUF in the industrial Internet of Things according to claim 1 or 5, characterized in that: The device processes message M8 as follows: Step (5.3.1), first check the transmission delay Is it within the allowed time interval ΔT, that is If it is within the time interval, the server records the current time as Step (5.3.2), then the device uses the negotiated session key SK = (A i ) e Decrypt the message x sent by the server and get a new challenge C′ i , the equipment will bring new challenges C′ i Input PUF to get a new response R′ i , and then get the corresponding update increment ΔR = R′ i -R i , and generate a random number a′ i , the increment of the random number is calculated as Δa=a′ i -a i ; Step (5.3.3), the device then generates Z using the update increment and the random number increment, and then uses Z and the new challenge C i+1 Generate encrypted ciphertext m, the calculation formula is as follows: Z=k ΔR h Δa (10) Finally, V=H3(SK||m||C′ i ), then the device sends message M9={m,V} to the server.

7. The lightweight anonymous mutual authentication method based on PUF in the industrial Internet of Things according to claim 6 is characterized in that: The specific processing steps of the server for message M9 are as follows: First, the server uses the ciphertext m and the new challenge C′ i and the session key V′ is generated, the received V is compared with the generated V′ to see if they are equal, if not, the update fails; If they are equal, the server recovers Z from the ciphertext and then calculates the new blinded response A′ i , the calculation formula is At the same time, a new session key SK2 is generated using the new blinded response, and the calculation formula is as follows: e2=H2(A′ i ||C′ i ) (12) Finally, update the used device pseudonym: set the new device pseudonym to PID′ i =H1(PID i ||A′ i ), the data format stored by the server is {PID′ i ,A′ i ,SK2}; At the same time, a new session key SK2 is calculated; The data format stored on the device is {PID′ i , C′ i , SK2}.