Bidirectional authentication method, device and equipment based on PUF-MAC key and storage medium
By generating PUF-MAC keys in the communication terminal and performing logical XOR operations and message verification code algorithm calculations, the problem of vulnerability in the prior art authentication scheme is solved, and efficient and secure two-way identity authentication is achieved.
Patent Information
- Application Number
- CN202510183263.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-19
- Publication Date
- 2025-06-13
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing authentication scheme for unsecure communication links is vulnerable to man-in-the-middle attacks or replay attacks, and the dynamic key mechanism that coordinates MAC and PUF has not yet been improved, and there are security vulnerabilities.
By generating PUF-MAC keys in the first terminal and the second terminal respectively, calculating the first tag value and the second verification value using a logical XOR operation and message verification code algorithm, bidirectional identity authentication is realized, and security verification is performed by checking the verification value of the tag value.
It realizes efficient and secure two-way identity authentication, effectively defends against physical cloning, man-in-the-middle attacks and replay attacks, and improves the integrity and authenticity of communication data.
Smart Images

Figure CN120150987A_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present application relate to the field of communication security technology, and in particular, to a two-way authentication method, apparatus, device, and storage medium based on a PUF-MAC key. Background Art
[0002] With the rapid development of the Internet of Things, higher requirements are placed on secure communication and identity authentication between devices. Physically unclonable functions (PUF) are widely used in identity authentication because they can generate unique and unreplicable responses through the physical characteristics of the chip. In the existing authentication schemes for insecure communication links, the existential unforgeability against chosen-message attacks (EU-CMA) problem is usually attributed to the weak anti-collision property of PUF and hash functions, which are more vulnerable to man-in-the-middle attacks or replay attacks. Message Authentication Code (MAC) is a symmetric cryptographic algorithm used to verify the integrity and authenticity of data. Its core idea is to generate a fixed-length authentication code by combining a key with a specific algorithm, which is of great significance in ensuring the integrity and authenticity of communication data. However, the dynamic key mechanism of MAC and PUF collaboration has not been perfected and has certain security vulnerabilities.
[0003] Therefore, how to integrate the communication advantages of PUF and MAC and design an efficient and secure two-way authentication method is a technical problem that needs to be solved urgently. Summary of the invention
[0004] According to the embodiments of the present application, a two-way authentication scheme based on PUF-MAC key is provided, which can realize efficient and secure two-way identity authentication and effectively defend against security vulnerabilities such as physical cloning, man-in-the-middle attacks, and replay attacks.
[0005] In a first aspect of the present application, a two-way authentication method based on a PUF-MAC key is provided. The method comprises:
[0006] Generate corresponding first and second keys at the first terminal and the second terminal respectively according to the initial incentive value and the physical unclonable function;
[0007] The first terminal calculates the first key and the second key in sequence through a logical exclusive OR operation and a message authentication code algorithm to obtain a first label value;
[0008] The second terminal calculates the first tag value and the PUF response value in sequence through a logical XOR operation and a message authentication code algorithm to obtain a second verification value;
[0009] Check whether the first verification value in the first tag value is equal to the second verification value, and perform two-way authentication on the first terminal and the second terminal.
[0010] In a possible implementation, according to the initial excitation value and the physically unclonable function, the corresponding first key and second key are generated at the first terminal and the second terminal respectively, and further include:
[0011] The first terminal sends the first key to the second terminal, and the second terminal sends the second key to the first terminal;
[0012] After the first terminal and the second terminal receive the first key and the second key respectively, perform a logical exclusive OR operation on the first key and the second key to generate a first logical exclusive OR value.
[0013] Optionally, the first terminal sequentially calculates the first key and the second key through a logical exclusive OR operation and a message authentication code algorithm to obtain a first tag value, including:
[0014] Generate a second logical exclusive OR value according to the first key and the first logical exclusive OR value;
[0015] Input the first key and the PUF response value into the hash function in the message authentication code algorithm to generate a first excitation value;
[0016] Input the first excitation value into the physically unclonable function to generate a first PUF generated value;
[0017] Input the first excitation value and the first PUF generated value into the hash function in the message authentication code algorithm to generate a first verification value;
[0018] Input the first key and the second logical exclusive OR value into the hash function in the message authentication code algorithm to generate a second excitation value;
[0019] Generate a third logical exclusive OR value according to the second excitation value and the first PUF generated value;
[0020] Concatenate the first verification value and the third logical exclusive OR value to obtain a first tag value.
[0021] Optionally, the PUF response value is the real-time read response value of the physically unclonable function at the first terminal.
[0022] Optionally, the first terminal sequentially calculates the first key and the second key through a logical exclusive OR operation and a message authentication code algorithm to obtain a first tag value, and further includes:
[0023] The first terminal sends the first tag value and the PUF response value to the second terminal.
[0024] Optionally, the second terminal calculates the first tag value and the PUF response value in sequence through an exclusive OR operation and a message authentication code algorithm to obtain a second verification value, including:
[0025] Generate a fourth exclusive OR value according to the second key and the first exclusive OR value;
[0026] Input the fourth exclusive OR value and the PUF response value into the hash function in the message authentication code algorithm to generate a third excitation value;
[0027] Input the second key and the fourth exclusive OR value into the hash function in the message authentication code algorithm to generate a fourth excitation value;
[0028] Generate a fifth exclusive OR value according to the fourth excitation value and the third exclusive OR value;
[0029] Input the third excitation value and the fifth exclusive OR value into the hash function in the message authentication code algorithm to generate a second verification value.
[0030] In a possible implementation manner, check whether the first verification value in the first tag value is equal to the second verification value, and perform mutual authentication on the first terminal and the second terminal, including:
[0031] If the first verification value is equal to the second verification value, the mutual authentication between the first terminal and the second terminal is successful; if the first verification value is not equal to the second verification value, the mutual authentication between the first terminal and the second terminal is unsuccessful.
[0032] In the second aspect of the present application, a mutual authentication device based on a PUF-MAC key is provided. The device includes:
[0033] A key generation module, configured to generate corresponding first and second keys in the first terminal and the second terminal respectively according to an initial excitation value and a physical unclonable function;
[0034] A first message authentication code generation module, where the first terminal calculates the first key and the second key in sequence through an exclusive OR operation and a message authentication code algorithm to obtain a first tag value;
[0035] A second message authentication code generation module, where the second terminal calculates the first tag value and the PUF response value in sequence through an exclusive OR operation and a message authentication code algorithm to obtain a second verification value;
[0036] An authentication module, configured to check whether the first verification value in the first tag value is equal to the second verification value, and perform mutual authentication on the first terminal and the second terminal.
[0037] In a third aspect of the present application, an electronic device is provided. The electronic device includes: a memory and a processor, where a computer program is stored on the memory, and when the processor executes the program, the methods described above are implemented.
[0038] In a fourth aspect of the present application, a computer-readable storage medium is provided, on which a computer program is stored, and when the program is executed by a processor, the method according to the first aspect of the present application is implemented.
[0039] The two-way authentication method based on the PUF-MAC key provided by the embodiments of the present application generates corresponding first and second keys at a first terminal and a second terminal respectively according to an initial excitation value and a physical unclonable function. The first terminal sequentially calculates the first and second keys through exclusive OR operations and a message authentication code algorithm to obtain a first tag value. The second terminal sequentially calculates the first tag value and a PUF response value through exclusive OR operations and a message authentication code algorithm to obtain a second verification value. By checking whether the first verification value in the first tag value is equal to the second verification value, two-way authentication of the first terminal and the second terminal is performed, achieving efficient two-way authentication. By combining the physical unclonable function and the message authentication code algorithm, the security of message transmission is ensured, and security vulnerabilities such as physical cloning, man-in-the-middle attacks, and replay attacks are effectively defended against.
[0040] It should be understood that the content described in the summary of the invention section is not intended to limit the key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become easily understandable through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] In combination with the accompanying drawings and with reference to the following detailed description, the above and other features, advantages, and aspects of the embodiments of the present application will become more apparent. In the drawings, the same or similar reference numerals represent the same or similar elements, where:
[0042] Figure 1 is a flowchart of a two-way authentication method based on the PUF-MAC key according to an embodiment of the present application;
[0043] Figure 2 is a flowchart of a first terminal obtaining a first tag value according to an embodiment of the present application;
[0044] Figure 3 is a flowchart of a second terminal obtaining a second verification value according to an embodiment of the present application;
[0045] Figure 4 is a schematic diagram of a two-way authentication method based on the PUF-MAC key according to an embodiment of the present application;
[0046] Figure 5 Block diagram of a two-way authentication device based on a PUF-MAC key according to an embodiment of the present application;
[0047] Figure 6 Structural schematic diagram of a terminal device or a server suitable for implementing the embodiments of the present application. Detailed implementation manners
[0048] To make the objectives, technical solutions, and advantages of the embodiments of the present disclosure clearer, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present disclosure. Apparently, the described embodiments are some but not all of the embodiments of the present disclosure. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present disclosure without creative efforts shall fall within the protection scope of the present disclosure.
[0049] In addition, the term "and / or" in this article is merely a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article generally represents an "or" relationship between the associated objects before and after.
[0050] Figure 1 Flowchart of a two-way authentication method based on a PUF-MAC key according to an embodiment of the present application. Refer to Figure 1 The method includes:
[0051] S101, generate a corresponding first key and a second key in a first terminal and a second terminal respectively according to an initial excitation value and a physical unclonable function.
[0052] Among them, the physical unclonable function (PUF) is a security primitive based on hardware physical characteristics. Its core idea is to generate a unique and unpredictable response value by using the random physical differences in the microstructures during the manufacturing process (such as transistor threshold voltage fluctuations, metal wire delay differences, wafer surface roughness, etc.). Each PUF will naturally form a unique "digital fingerprint" due to process fluctuations during manufacturing. Even if an attacker fully masters its design principle, it is impossible to generate the same response through physical replication or simulation. The working mechanism of PUF is usually based on a "challenge-response" model: when an excitation signal (challenge) is input, PUF will output a response value determined by the hardware physical characteristics. The non-clonability of PUF stems from the fact that the microscopic randomness of the physical structure has a very high entropy value macroscopically and cannot be accurately reproduced through reverse engineering.
[0053] In this embodiment, since the output of the physically unclonable function PUF depends on its inherent physical characteristics, the keys generated by each terminal are unique, improving the security and uniqueness of two-way authentication.
[0054] Optionally, according to the initial excitation value and the physically unclonable function, the corresponding first key and second key are generated at the first terminal and the second terminal respectively, and it further includes:
[0055] The first terminal sends the first key to the second terminal, and the second terminal sends the second key to the first terminal;
[0056] After the first terminal and the second terminal respectively receive the first key and the second key, a logical exclusive OR operation is performed on the first key and the second key to generate a first logical exclusive OR value.
[0057] In a possible implementation manner, there are a first terminal A and a first terminal B. According to the initial excitation value C 0 and the physically unclonable function PUF, the first key and the second key generated at the first terminal A and the first terminal B can be respectively expressed as R A = PUF A (C 0 ), R B = PUF B (C 0 ). Then, a logical exclusive OR operation is respectively performed on the first key and the second key at the first terminal and the second terminal to generate a first logical exclusive OR value T 1 which can be expressed as:
[0058] T 1 = R A ⊕ R B .
[0059] In this embodiment, the two terminals complete the synchronization of the first key and the second key before authentication, avoiding the trust imbalance that may be caused by unilateral key generation and increasing the difficulty of man-in-the-middle attacks.
[0060] S102. The first terminal sequentially calculates the first key and the second key through a logical exclusive OR operation and a message authentication code algorithm to obtain a first tag value.
[0061] In this embodiment, the first tag value is generated through a logical exclusive OR operation and a message authentication code algorithm, ensuring that the data source is trustworthy and not tampered with. Moreover, the one-way nature of the message authentication code algorithm makes it impossible for an attacker to reverse-derive the original first key.
[0062] Optionally, the first terminal sequentially calculates the first key and the second key through a logical exclusive OR operation and a message authentication code algorithm to obtain a first tag value, including:
[0063] Generate a second exclusive - OR value according to the first key and the first exclusive - OR value;
[0064] Input the first key and the PUF response value into the hash function in the message authentication code algorithm to generate a first excitation value;
[0065] Input the first excitation value into the physically unclonable function to generate a first PUF generated value;
[0066] Input the first excitation value and the first PUF generated value into the hash function in the message authentication code algorithm to generate a first verification value;
[0067] Input the first key and the second exclusive - OR value into the hash function in the message authentication code algorithm to generate a second excitation value;
[0068] Generate a third exclusive - OR value according to the second excitation value and the first PUF generated value;
[0069] Concatenate the first verification value and the third exclusive - OR value to obtain a first tag value.
[0070] Figure 2 It is a flowchart for obtaining the first tag value for the first terminal according to an embodiment of the present application, as Figure 2 shown.
[0071] In a possible implementation manner, the first terminal generates a second exclusive - OR value according to the first key R A and the first exclusive - OR value T 1 Then, input the first key R and the PUF response value M into the hash function H(·) in the message authentication code algorithm to generate a first excitation value C A , which can be expressed as C 1 =H(M||R 1 ). Then input the first excitation value C A into the physically unclonable function PUF to generate a first PUF generated value R 1 , that is, R 1 =PUF 1 (C A ). Input the first excitation value C 1 and the first PUF generated value R 1 into the hash function in the message authentication code algorithm to generate a first verification value t 1 , that is, t 1 =H(C 1 ||R 1 ). Secondly, input the first key R 1 and the second exclusive - OR value T A and the first PUF generated value R 2Input it into the hash function in the message authentication code algorithm to generate the second excitation value C 2 , that is, C 2 = H(R A ||T 2 ), then, according to the second excitation value C 2 and the first PUF generated value R 1 generate the third logical exclusive - OR value T 3 , that is, Finally, concatenate the first verification value t 1 and the third logical exclusive - OR value T 3 to obtain the first tag value Tag 1 =(t 1 , T 3 ).
[0072] Among them, the Message Authentication Code (MAC) algorithm is a cryptographic tool used to verify the integrity and authenticity of messages. Its core goal is to ensure that the receiving party can confirm that the message has not been tampered with during transmission by generating an authentication tag (i.e., the MAC value) bound to the message and the key. In the MAC algorithm, the two communicating parties pre - share a key (in the symmetric key scenario) or negotiate the key through a security protocol. Then, the sender uses the key and the message as inputs, generates an authentication tag of a fixed length through the MAC algorithm. Finally, the receiving party uses the same key to recalculate the MAC value for the received message and compares it with the tag provided by the sender. If they are the same, the verification passes. The hash function is the core component of the MAC algorithm. It maps an input of any length (message) to an output of a fixed length (hash value), generates an authentication tag of a fixed length (i.e., the MAC value) by combining the key and the message, ensuring that the receiving party can verify the legality of the message source and the integrity of the content, and has characteristics such as one - wayness, collision resistance, and anti - tampering sensitivity.
[0073] In this embodiment, through the collaborative design of PUF hardware binding, multi - level logical exclusive - OR operations, and hash integrity protection in the message authentication code algorithm, a tag generation framework for the first terminal with dynamicity, anti - reverseability, and physical security is constructed.
[0074] Optionally, the PUF response value is the real - time read response value of the physical unclonable function at the first terminal.
[0075] In this embodiment, by real - time reading the PUF response value, the hardware uniqueness, dynamic key generation, and anti - physical attack capabilities are deeply integrated, simplifying the key management process while ensuring high security.
[0076] Optionally, the first terminal calculates the first key and the second key in sequence through a logical exclusive OR operation and a message authentication code algorithm to obtain a first tag value, further including:
[0077] The first terminal sends the first tag value and the PUF response value to the second terminal.
[0078] In this embodiment, the first terminal sends the first tag value and the PUF response value to the second terminal, realizing efficient single-round two-way authentication and integrity protection in the message authentication code algorithm.
[0079] S103. The second terminal calculates the first tag value and the PUF response value in sequence through a logical exclusive OR operation and a message authentication code algorithm to obtain a second verification value.
[0080] In this embodiment, the second terminal performs a logical exclusive OR operation and a message authentication code calculation on the received first tag value and PUF response value to obtain a second verification value. This process forms a chain dependency, requiring both parties to strictly interact according to the steps. Tampering in any link will result in a final verification failure, realizing the cross-binding of the keys of both parties and ensuring the two-way nature of authentication.
[0081] Optionally, the second terminal calculates the first tag value and the PUF response value in sequence through a logical exclusive OR operation and a message authentication code algorithm to obtain a second verification value, including:
[0082] Generate a fourth logical exclusive OR value according to the second key and the first logical exclusive OR value;
[0083] Input the fourth logical exclusive OR value and the PUF response value into the hash function in the message authentication code algorithm to generate a third excitation value;
[0084] Input the second key and the fourth logical exclusive OR value into the hash function in the message authentication code algorithm to generate a fourth excitation value;
[0085] Generate a fifth logical exclusive OR value according to the fourth excitation value and the third logical exclusive OR value;
[0086] Input the third excitation value and the fifth logical exclusive OR value into the hash function in the message authentication code algorithm to generate a second verification value.
[0087] Figure 3 It is a flowchart for the second terminal to obtain the second verification value according to the embodiment of the present application, as Figure 3 shown.
[0088] In a possible implementation manner, the second terminal generates a fourth logical exclusive OR value T according to the second key R B and the first logical exclusive OR value T 1 to generate a fourth logical exclusive OR value T 4 = R B ⊕ T1 , then, input the fourth logical exclusive - OR value T 4 and the PUF response value M into the hash function in the message authentication code algorithm to generate the third excitation value C 3 , that is, C 3 =H(M||T 4 ). After that, input the second key R B and the fourth logical exclusive - OR value T 4 into the hash function in the message authentication code algorithm to generate the fourth excitation value C 4 , that is, C 4 =H(R B ||T 4 ). Finally, generate the fifth logical exclusive - OR value T 4 according to the fourth excitation value C 3 and the third logical exclusive - OR value T 5 =C 4 ⊕T 3 . Then, input the third excitation value C 3 and the fifth logical exclusive - OR value T 5 into the hash function in the message authentication code algorithm to generate the second verification value t 2 , that is, t 2 =H(C 3 ||T 5 ).
[0089] In this embodiment, the second terminal calculates the first tag value and the PUF response value in sequence through logical exclusive - OR operations and message authentication code algorithms to obtain the second verification value, realizing high - strength identity authentication and data anti - tampering.
[0090] S104, check whether the first verification value in the first tag value is equal to the second verification value to perform two - way identity authentication on the first terminal and the second terminal.
[0091] In this embodiment, by comparing whether the first verification value is equal to the second verification value, the first terminal and the second terminal synchronously complete identity confirmation, effectively preventing man - in - the - middle attacks (such as disguising one - side terminals, etc.) that may occur in one - way authentication.
[0092] Optionally, checking whether the first verification value in the first tag value is equal to the second verification value to perform two - way identity authentication on the first terminal and the second terminal includes:
[0093] If the first verification value is equal to the second verification value, the two - way identity authentication between the first terminal and the second terminal is successful. If the first verification value is not equal to the second verification value, the two - way identity authentication between the first terminal and the second terminal is unsuccessful.
[0094] In this embodiment, by comparing whether the first verification value (from the first terminal) is equal to the second verification value (from the second terminal), efficient and highly secure two-way authentication is achieved.
[0095] Figure 4 It is a schematic diagram of a two-way authentication method based on a PUF-MAC key according to an embodiment of the present application, as Figure 4 shown:
[0096] First, in the key generation part, according to the initial excitation value C 0 , the physical unclonable function PUF generates the corresponding first key R A = PUF A (C 0 ) and the second key R B = PUF B (C 0 ) in the first terminal A and the second terminal B respectively, and sends the first key R A and the second key R B to each other respectively to achieve key sharing, and then performs a logical exclusive OR operation on the first key and the second key to generate the first logical exclusive OR value T 1 = R A ⊕ R B , superimposing the key entropy value.
[0097] Secondly, in the message authentication code generation part, the first terminal A calculates the first key R A and the second key R B in sequence through logical exclusive OR operations and message authentication code algorithms to obtain the first tag value Tag 1 = (t 1 , T 3 ), where the first tag value Tag 1 is composed of the first verification value t 1 and the third logical exclusive OR value T 3 spliced together. Then, the first terminal sends the PUF response value M and the first tag value Tag 1 to the second terminal. The calculation steps of the first verification value t 1 and the third logical exclusive OR value T 3 are as follows:
[0098] C 1 = H(M||R A ), R 1 = PUF A (C 1 ),
[0099] t 1 = H(C 1 ||R 1), C 2 = H(R A || T 2 ),
[0100] where T 2 is the second exclusive - OR value, and C 1 is the first excitation value, and C 2 is the second excitation value.
[0101] Finally, in the authentication part, the second terminal B calculates the first tag value Tag 1 and the PUF response value M in sequence through the exclusive - OR operation and the message authentication code algorithm to obtain the second verification value t 2 . The calculation steps of the second verification value t 2 are as follows:
[0102] C 3 = H(M || T 4 ), C 4 = H(R B || T 4 ),
[0103] t 2 = H(C 3 || T 5 ),
[0104] where T 4 is the fourth exclusive - OR value, C 3 is the third excitation value, C 4 is the fourth excitation value, and T 5 is the fifth exclusive - OR value. Then, check whether the first verification value t 1 in the first tag value Tag 1 is equal to the second verification value t 2 to perform two - way authentication on the first terminal A and the second terminal B, forming a "challenge - key - tag - verification" dynamic closed - loop to ensure the uniqueness of each session parameter.
[0105] The present invention deeply integrates the physical unclonable function (PUF) and the message authentication code (MAC) technology, and realizes high - security device authentication through dynamic key generation, tag calculation and two - way verification.
[0106] According to the embodiments of the present disclosure, the following technical effects are achieved:
[0107] 1) Dynamically generate keys through the hardware uniqueness of the Physical Unclonable Function (PUF), and combine the two-way authentication mechanism of the Message Authentication Code (MAC) algorithm to effectively defend against physical cloning, man-in-the-middle attacks, and replay attacks, realizing the endogenous security verification of the identity of terminal devices.
[0108] 2) Adopt logical exclusive OR operations and lightweight message authentication code algorithms, with low computational complexity and no need for complex cryptographic protocols, which can adapt to resource-constrained Internet of Things (IoT) terminals, significantly reducing authentication latency while ensuring security, and supporting the instant two-way verification requirements of high-concurrency scenarios.
[0109] 3) The generation of dynamic incentive values supports the on-demand update of challenge-response pairs, which can be seamlessly extended to multi-device and multi-level network environments, while avoiding the difficulties of static key management, providing a flexible and scalable two-way identity authentication framework for scenarios such as edge computing and industrial Internet of Things.
[0110] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that this application is not limited by the described action sequence, because according to this application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.
[0111] The above is the introduction of method embodiments. The following further illustrates the solution of this application through device embodiments.
[0112] Figure 5 The block diagram of a two-way authentication device based on PUF-MAC keys according to an embodiment of the present application is shown, as Figure 5 shown, including:
[0113] A key generation module 501, configured to generate corresponding first and second keys at a first terminal and a second terminal respectively according to an initial incentive value and a physical unclonable function;
[0114] A first message authentication code generation module 502, which calculates the first key and the second key in sequence through logical exclusive OR operations and a message authentication code algorithm at the first terminal to obtain a first tag value;
[0115] A second message authentication code generation module 503, which calculates the first tag value and the PUF response value in sequence through logical exclusive OR operations and a message authentication code algorithm at the second terminal to obtain a second verification value;
[0116] An authentication module 504, configured to check whether the first verification value in the first tag value is equal to the second verification value, and perform two-way identity authentication on the first terminal and the second terminal.
[0117] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the described modules can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.
[0118] Figure 6 The figure shows a schematic structural diagram of a terminal device or a server suitable for implementing the embodiments of the present application.
[0119] As Figure 6 shown, the terminal device or the server includes a central processing unit (CPU) 601, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 602 or the program loaded from the storage section 608 into the random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the terminal device or the server are also stored. The CPU 601, the ROM 602, and the RAM 603 are connected to each other via a bus 604. The input / output (I / O) interface 605 is also connected to the bus 604.
[0120] The following components are connected to the I / O interface 605: an input section 606 including a keyboard, a mouse, etc.; an output section 607 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 608 including a hard disk, etc.; and a communication section 609 including a network interface card such as a LAN card, a modem, etc. The communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the I / O interface 605 as required. A removable medium 611, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 610 as required, so that the computer program read from it can be installed into the storage section 608 as required.
[0121] Specifically, according to the embodiments of the present application, the above method flow steps can be implemented as a computer software program. For example, the embodiments of the present application include a computer program product, which includes a computer program carried on a machine-readable medium, and the computer program contains program codes for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication section 609, and / or installed from the removable medium 611. When the computer program is executed by the central processing unit (CPU) 601, the above functions defined in the system of the present application are executed.
[0122] It should be noted that the computer-readable medium shown in this application can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of a computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this application, a computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this application, a computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on a computer-readable medium can be transmitted using any appropriate medium, including but not limited to: wireless, wire, optical fiber, RF, etc., or any suitable combination of the above.
[0123] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram can represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in a block can occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0124] The units or modules involved in the embodiments described in this application can be implemented in software or in hardware. The described units or modules can also be provided in a processor. Among them, the names of these units or modules do not, in some cases, constitute a limitation on the units or modules themselves.
[0125] As another aspect, this application also provides a computer-readable storage medium, which can be included in the electronic device described in the above embodiments; or can exist alone without being assembled into the electronic device. The above computer-readable storage medium stores one or more programs, and when the foregoing programs are executed by one or more processors, they implement the methods described in this application.
[0126] The above description is only a preferred embodiment of this application and an explanation of the technical principles applied. Those skilled in the art should understand that the scope of the application involved in this application is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the foregoing inventive concept. For example, the technical solutions formed by mutually replacing the above features with the technical features (but not limited to) having similar functions described in this application.
Claims
1. A two-way authentication method based on PUF-MAC key, characterized in that: include: Generate corresponding first and second keys at the first terminal and the second terminal respectively according to the initial incentive value and the physical unclonable function; The first terminal calculates the first key and the second key in sequence through a logical exclusive OR operation and a message authentication code algorithm to obtain a first label value; The second terminal calculates the first tag value and the PUF response value in sequence through a logical XOR operation and a message authentication code algorithm to obtain a second verification value; Check whether a first verification value in the first tag value is equal to the second verification value, and perform bidirectional identity authentication on the first terminal and the second terminal.
2. The two-way authentication method based on PUF-MAC key according to claim 1, characterized in that: The method further comprises: generating corresponding first keys and second keys at the first terminal and the second terminal respectively according to the initial incentive value and the physical unclonable function; The first terminal sends the first key to the second terminal, and the second terminal sends the second key to the first terminal; After receiving the first key and the second key respectively, the first terminal and the second terminal perform a logical exclusive OR operation on the first key and the second key to generate a first logical exclusive OR value.
3. The two-way authentication method based on PUF-MAC key according to claim 2, characterized in that: The first terminal calculates the first key and the second key in sequence through a logical exclusive OR operation and a message authentication code algorithm to obtain a first label value, including: Generate a second logical XOR value according to the first key and the first logical XOR value; Inputting the first key and the PUF response value into a hash function in the message authentication code algorithm to generate a first incentive value; Inputting the first stimulus value into the physical unclonable function to generate a first PUF generation value; Inputting the first stimulus value and the first PUF generated value into a hash function in the message authentication code algorithm to generate a first verification value; Inputting the first key and the second logical XOR value into a hash function in the message authentication code algorithm to generate a second incentive value; Generate a third logical XOR value according to the second stimulus value and the first PUF generated value; The first verification value and the third logical XOR value are concatenated to obtain the first label value.
4. The two-way authentication method based on PUF-MAC key according to claim 3 is characterized in that: The PUF response value is a real-time read response value of the physical unclonable function at the first terminal.
5. The two-way authentication method based on PUF-MAC key according to claim 3, characterized in that: The first terminal calculates the first key and the second key in sequence through a logical exclusive OR operation and a message authentication code algorithm to obtain a first tag value, further comprising: The first terminal sends the first tag value and the PUF response value to the second terminal.
6. The two-way authentication method based on PUF-MAC key according to claim 2, characterized in that: The second terminal calculates the first tag value and the PUF response value in sequence through a logical XOR operation and a message authentication code algorithm to obtain a second verification value, including: Generate a fourth logical XOR value according to the second key and the first logical XOR value; Inputting the fourth logical XOR value and the PUF response value into a hash function in the message authentication code algorithm to generate a third incentive value; Inputting the second key and the fourth logical XOR value into a hash function in the message authentication code algorithm to generate a fourth incentive value; generating a fifth logical XOR value according to the fourth stimulus value and the third logical XOR value; The third stimulus value and the fifth logical XOR value are input into a hash function in the message authentication code algorithm to generate a second authentication value.
7. The two-way authentication method based on PUF-MAC key according to claim 1, characterized in that: The checking whether the first verification value in the first tag value is equal to the second verification value, and performing bidirectional identity authentication on the first terminal and the second terminal, includes: If the first verification value is equal to the second verification value, the two-way identity authentication between the first terminal and the second terminal is successful; if the first verification value is not equal to the second verification value, the two-way identity authentication between the first terminal and the second terminal is unsuccessful.
8. A two-way authentication device based on PUF-MAC key, characterized in that: include: A key generation module, used to generate corresponding first keys and second keys at the first terminal and the second terminal respectively according to the initial incentive value and the physical unclonable function; A first message authentication code generation module, in which the first terminal calculates the first key and the second key in sequence through a logical exclusive OR operation and a message authentication code algorithm to obtain a first label value; A second message authentication code generation module, in which the second terminal calculates the first tag value and the PUF response value in sequence through a logical XOR operation and a message authentication code algorithm to obtain a second authentication value; An authentication module is used to check whether a first verification value in the first tag value is equal to the second verification value, and perform two-way identity authentication on the first terminal and the second terminal.
9. An electronic device comprising a memory and a processor, wherein a computer program is stored in the memory, wherein: When the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.