Lightweight anonymous authentication method and system based on PUF function
By generating the physical characteristics of sensor network nodes, hiding identifiers and building private channels, combining lightweight hashing operations and dynamic key derivation mechanisms, the security and resource efficiency problems of the smart grid authentication protocol are solved, and hardware-level trust root and low-cost two-way authentication are realized.
Patent Information
- Application Number
- CN202510739189.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-04
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2045-06-04
AI Technical Summary
The existing smart grid authentication protocol has shortcomings in terms of security and resource efficiency, and cannot effectively resist man-in-the-middle attacks and replay attacks, and has not fully utilized the physical characteristics of the equipment to build a root of trust. The computing and communication costs are high, making it difficult to adapt to sensor nodes with limited resources.
By extracting the physical characteristics of the sensor network nodes, a unique hidden identifier is generated, a private channel between the sensor and the gateway is built, and a lightweight hashing operation and dynamic key derivation mechanism is combined to realize two-way authentication, reduce computing and communication resource consumption, and adapt to resource-constrained environments.
It provides a hardware-level trust root, resists physical attacks and identity forgery, reduces computing and communication resource consumption, enhances dynamic defense capabilities, ensures the authenticity and integrity of data transmission, and adapts to smart grid environments with limited resources.
Smart Images

Figure CN120263553A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology. Specifically, it relates to a lightweight anonymous authentication method and system based on the PUF function. Background Art
[0002] During the development of the smart grid towards intelligent interconnection of terminal devices, the open system enables attackers to impersonate legitimate participants and steal power control information, making the importance of device authentication and data protection particularly prominent. At present, the application of wireless sensor networks in the smart grid faces challenges in node authentication under dynamic topologies. Existing authentication protocols have the following significant defects: In terms of security, there is a lack of perfect forward secrecy and user anonymity, and it cannot resist various threats such as man-in-the-middle attacks and impersonation attacks; in terms of performance, the high computational and communication costs are difficult to adapt to resource-constrained devices such as sensor nodes; in terms of physical layer security: the physical characteristics of devices are not utilized to construct a root of trust, and it is vulnerable to physical attacks; in addition, the application of new security technologies such as PUF is insufficient, and the processing mechanism of fuzzy extractors for PUF noise is not yet mature, which has become a technical barrier restricting smart grid security authentication.
[0003] The above information disclosed in the background art section is only used to enhance the understanding of the background of the present application. Therefore, it may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention
[0004] The object of the present invention is to address the deficiencies in security and low resource efficiency in existing smart grid authentication protocols. The present application proposes a lightweight anonymous authentication method and system based on the PUF function. By extracting the physical characteristics of sensor network nodes to generate unique hidden identifiers, hardware-level identity binding is achieved; a private channel between sensors and gateways is dynamically constructed, and handshake information is generated based on initial parameters and geographical characteristics through hash operations. Two-way authentication is completed through a two-level authentication strategy; combined with lightweight hash operations and a dynamic key derivation mechanism, while ensuring the ability to resist man-in-the-middle attacks and replay attacks, the consumption of computational and communication resources is significantly reduced, adapting to the resource-constrained smart grid environment.
[0005] In a first aspect, a technical solution provided in an embodiment of the present invention is: a lightweight anonymous authentication method based on the PUF function, including the following steps: Performing a hash operation on the physical characteristics of sensor network nodes to generate hidden identifiers corresponding to the nodes; wherein, the sensor network nodes include sensor nodes and gateway nodes; Constructing a private channel between the sensor nodes and the gateway nodes, and receiving the public identifiers and hidden identifiers of each other through the private channel to complete the initial parameter configuration of each sensor network node; Perform a hash operation on the geographical characteristics and initial parameters of the sensor node to generate handshake information; the gateway node generates feedback information according to the first authentication policy in response to the handshake information; The sensor node generates an authentication result according to the second authentication policy in response to the feedback information, and the gateway node performs subsequent actions in response to the authentication result.
[0006] Preferably, performing a hash operation on the physical characteristics of the sensor network node to generate a hidden identifier for the corresponding node includes the following steps: Obtain the physical unclonable function seed value according to the physical characteristic difference after the sensor SRAM is powered on , and perform BCH encoding on the physical unclonable function seed value to obtain the consistency parameter and the corresponding auxiliary data ; Generate the sensor physical fingerprint according to the physical unclonable function seed value , the consistency parameter and the auxiliary data ; Obtain the hidden identifier of the corresponding sensor node by performing a hash operation on the sensor physical fingerprint ;
[0007] Preferably, performing a hash operation on the physical characteristics of the sensor network node to generate a hidden identifier for the corresponding node further includes the following steps: Obtain the physical unclonable function seed value according to the physical characteristic difference after the gateway SRAM is powered on , and perform BCH encoding on the physical unclonable function seed value to obtain the consistency parameter and the corresponding auxiliary data ; Generate the gateway physical fingerprint according to the physical unclonable function seed value , the consistency parameter and the auxiliary data ; Obtain the hidden identifier of the corresponding gateway node by performing a hash operation on the gateway physical fingerprint ;
[0008] In this solution, a dynamic security authentication foundation from the physical layer to the protocol layer is constructed through hierarchical hardware feature extraction and cryptographic processing: First, the unique physical property differences generated by the manufacturing process differences after the SRAM of the sensor and gateway nodes is powered on are used to generate PUF seed values, deeply binding the device identity with the non-replicable hardware features, and resisting physical attacks and identity forgery from the root cause; Then, error correction processing is performed on the PUF seed values through BCH coding to generate consistency parameters and auxiliary data, constructing a fuzzy extractor mechanism to effectively overcome the interference of physical noise on the PUF response and ensure the stability and reliability of the identity identifier; Then, physical fingerprints are generated based on the seed values, coding parameters, and auxiliary data to form the unique "digital DNA" of the device at the physical layer, providing an immutable trust root for authentication; Finally, the physical fingerprints are transformed into hidden identifiers through hash operations, protecting the original physical features while providing lightweight identity authentication factors for the authentication protocol, realizing the seamless connection between hardware features and authentication logic, solving the core defects of the lack of a physical layer trust root and vulnerability to physical attacks in the existing technology, and laying a hardware-level security foundation for the subsequent construction of private channels and two-way authentication processes.
[0009] Preferably, the construction of the private channel between the sensor node and the gateway node includes the following steps: Generate pseudo-handshake information according to the computing resources and network resources required by the sensor node. The gateway node receives the pseudo-handshake information through the public channel and determines the bandwidth and transmission rate of the sub-channel to be divided according to the pseudo-handshake information; Generate a binary random number L1 according to the bandwidth and transmission rate and encrypt the pseudo-handshake information with the binary random number L1 to obtain a pseudo-encrypted block and send it to the sensor node; Obtain the binary random number L1 through the exclusive OR operation of the pseudo-encrypted block with the pseudo-handshake information, and encrypt the public channel with the binary random number L1 to obtain a private channel.
[0010] Preferably, the initial parameters of the sensor node are The initial parameters of the gateway node are ; Among them, is the public identifier of the sensor node; is the public identifier of the gateway node; is the synchronization serial number of the sensor / gateway node; is the hidden identifier of the sensor node; is the hidden identifier of the gateway node; is the consistency parameter of the sensor node; is the consistency parameter of the gateway node; is the auxiliary data of the sensor node; is the auxiliary data of the gateway node.
[0011] Preferably, a hash operation is performed on the geographical characteristics and initial parameters of the sensor node to generate a handshake message, including the following steps: The sensor node generates random location information , and performs a hash operation on , and in the initial parameters to obtain a fuzzy location , denoted as ; perform a hash operation on , in the initial parameters combined with the random location information to obtain a location verification value V, denoted as ; generate a handshake message based on in the initial parameters, the fuzzy location, and the location verification value V .
[0012] Preferably, the gateway node generates a feedback message according to the first authentication policy in response to the handshake message, including the following steps: After the handshake message is sent to the gateway node through a private channel, if the comparison fails, the authentication is terminated; If the comparison is successful, extract , in the initial parameters and the serial number of the gateway node to perform a hash operation to obtain the original location , denoted as ; perform a hash operation on in the initial parameters, the serial number of the gateway node , and the original location to obtain a location verification value , denoted as ; If , re-initiate the authentication, and pack , in the initial parameters and the serial number of the gateway node into an encrypted information block through an encryption algorithm, denoted as ; the gateway node sends and as feedback messages and sends them to the sensor node through a private channel; If , the gateway node generates a random number , and according to , in the initial parameters, the random number Perform a hashing operation to obtain an identity-derived factor , denoted as ; Based on the original location , identity-derived factor Perform a hashing operation to obtain an initial session key , denoted as ; Among the initial parameters , , original location Perform an exclusive OR operation on the operation result of the hashing operation with the random number to obtain the encrypted random number M, denoted as ; Original location , initial session key are packaged into an encrypted information block through the encryption algorithm , denoted as , and set the session key ; The gateway node sends , and as feedback information to the sensor node through the private channel.
[0013] Preferably, the sensor node generates an authentication result in response to the feedback information according to the second authentication policy, and the gateway node performs subsequent actions in response to the authentication result; including the following steps: Based on the initial parameters , the serial number of the sensor node , random location perform a hashing operation to obtain a location verification value , denoted as ; If , the sensor node calculates . If the public identifier of the decrypted sensor node , set , and feedback the authentication result and to the gateway node through the private channel, and re-initiate an authentication application; if , the sensor node feedbacks the authentication result and to the gateway node through the private channel, and re-initiate an authentication application; If , the sensor node calculates the original random number , original identity-derived factor ; Original session key ; Original random location ; If , the authentication fails, and the authentication result is fed back to the gateway node through the private channel and then a new authentication application is initiated; if the session key is set and the authentication result is fed back to the gateway node through the private channel and then a new authentication application is initiated; After receiving the authentication result
[0014] In a second aspect, a technical solution provided in an embodiment of the present invention is: a lightweight anonymous authentication system applicable to a lightweight anonymous authentication method based on the PUF function, including: A calculation module: generating a hidden identifier corresponding to a node based on the physical characteristics of the sensor network node in combination with a hash function; wherein, the sensor network node includes a sensor node and a gateway node; A channel construction module: constructing a private channel between the sensor node and the gateway node; A parameter configuration module: completing the initial parameter configuration of each sensor network node through a public identifier and a hidden identifier; A first generation module: generating a handshake message based on the geographical characteristics of the sensor node and the initial parameters in combination with a hash function; A second generation module: the gateway node generating a feedback message in response to the handshake message according to the first authentication policy; An execution module: the sensor node generating an authentication result in response to the feedback message according to the second authentication policy, and the gateway node executing subsequent actions in response to the authentication result.
[0015] In a third aspect, a technical solution provided in an embodiment of the present invention is: an electronic device including a memory and a processor, where a computer program is stored in the memory, and when the processor calls the computer program in the memory, the steps of the lightweight anonymous authentication method based on the PUF function are implemented.
[0016] In a fourth aspect, a technical solution provided in an embodiment of the present invention is: a storage medium in which computer-executable instructions are stored, and when the computer-executable instructions are loaded and executed by a processor, the steps of the lightweight anonymous authentication method based on the PUF function are implemented.
[0017] The present invention has at least the following substantial beneficial effects: (1) Aiming at the problems that existing smart grid authentication protocols do not utilize the physical characteristics of devices to construct a root of trust and are vulnerable to physical attacks, this application obtains PUF seed values according to the physical characteristic differences of sensors and gateway SRAMs after power-on, performs BCH encoding on them to obtain consistency parameters and auxiliary data to generate physical fingerprints, and then performs a hash operation on the physical fingerprints to obtain hidden identifiers, deeply binding the device identity with physical characteristics, achieving the technical effects of constructing a unique identity identifier from the hardware physical layer, resisting physical attacks and identity forgery, and providing a reliable hardware-level root of trust for authentication; (2) Aiming at the problems that most existing smart grid authentication protocols have high calculation and communication costs and are not suitable for resource-constrained environments, this application generates pseudo-handshake information according to the resources required by sensor nodes. The gateway node determines channel parameters based on this and generates a private channel by encrypting binary random numbers. And in the authentication process, lightweight hash functions, exclusive OR operations, and LEA encryption algorithms are adopted, combined with the dynamically constructed private channel for initial parameter configuration and authentication information transmission, achieving the technical effects of reducing the consumption of computing and communication resources and adapting to resource-constrained smart grid environments, meeting the low-power requirements of devices such as sensor nodes; (3) Aiming at the problems that existing smart grid protocols lack perfect forward secrecy and cannot effectively resist threats such as replay attacks, this application generates random location information by using sensor nodes during the authentication process, performs a hash operation on the hidden identifier and synchronization sequence number in the initial parameters to generate handshake information. The gateway node and sensor node perform hash operations and key derivation in the response process by combining dynamic parameters such as random numbers and synchronization sequence number updates. The handshake information and keys for each authentication session change dynamically, achieving the technical effects of enhancing dynamic defense capabilities, ensuring forward secrecy, effectively resisting replay attacks and man-in-the-middle attacks, and ensuring the authenticity and integrity of data transmission.
[0018] The above invention content is only an overview of the technical solution of the present invention. In order to be able to more clearly understand the technical means of the present invention, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of the present invention more obvious and understandable, the specific embodiments of the present invention are specifically listed below. Brief Description of the Drawings
[0019] By reading the detailed description of the non-restrictive embodiments with reference to the following drawings, other features, purposes and advantages of the present invention will become more obvious. The drawings are only used for the purpose of showing the preferred embodiments and are not considered as a limitation of the present invention. And throughout the drawings, the same reference symbols are used to represent the same components.
[0020] Figure 1 It is a flowchart of the lightweight anonymous authentication method based on the PUF function of the present invention.
[0021] Figure 2 This is the structural block diagram of the lightweight anonymous authentication system of the present invention. Specific embodiments
[0022] To make the objectives, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only the best embodiments of the present invention, which are only used to explain the present invention and do not limit the protection scope of the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0023] Before discussing the exemplary embodiments in more detail, it should be mentioned that some exemplary embodiments are described as processes or methods depicted as flowcharts. Although the flowcharts describe the operations (or steps) as sequential processes, many of the operations (or steps) can be implemented in parallel, concurrently, or simultaneously. In addition, the order of the operations can be rearranged. The process can be terminated when its operations are completed, but it can also have additional steps not included in the drawings; the process can correspond to a method, function, procedure, subroutine, subprogram, and so on.
[0024] As an important part of the modern power system, the smart grid is developing towards the intelligent interconnection of terminal devices and plays a key role in optimizing energy distribution. Due to the openness of the smart grid system, attackers can access the data in the public channels and impersonate legitimate participants. However, the power control information transmitted in the smart grid environment is very important. Once leaked, it is likely to lead to consequences such as property losses, leakage of confidential information, and power control problems.
[0025] Different from traditional networks and other sensors, the wireless sensor network technology can quickly build a network. The uncertainty of its topological structure determines the flexibility of adding and deleting nodes, and its strength is also very high and difficult to be destroyed. The wireless sensor network mainly consists of three parts: nodes, sensor networks, and users. Among them, the nodes are usually deployed within a certain range according to the requirements of meeting the monitoring needs; the sensor network is the most important part. It collects the information of all nodes through fixed channels, then performs certain analysis and calculations on these node information, and finally summarizes the analysis results to the base station and transmits the data to the designated user terminal through satellite communication to meet the requirements of wireless sensing.
[0026] In the smart grid authentication scenario, the authentication protocol is designed for grid operators, distributed generation units, end - consumers, and various sensors and smart devices. These roles form a complex and dynamic authentication environment. For example, grid operators need to ensure the authenticity and integrity of remote control instructions; distributed generation units need to verify whether the entity receiving their power generation data is a legitimate power grid company; and end - consumers need to confirm that the received power service information comes from a trusted service provider.
[0027] The protocol authentication system of the present invention consists of two entities: the sensor node (SensorNode) and the gateway node (GatewayNode). These two nodes need to generate device numbers through the registration and initialization phases to complete the registration and initialization of the devices, and then complete mutual authentication through the authentication and key negotiation phases. Since the data transmission between nodes is carried out on an open and vulnerable communication channel, this brings challenges in data protection, authentication, and mutual authentication. Therefore, in order to ensure the security of data and the authenticity of the identities of participants in the smart grid environment, there is an urgent need to design a technical solution to achieve mutual authentication between nodes and the establishment of session keys. Based on this, the application is proposed.
[0028] Embodiment 1: In the smart grid scenario, identity authentication and data protection are the main issues to be solved in the process of the smart grid node authentication and key exchange protocol. As Figure 1 shown, to solve the above - mentioned technical problems, this embodiment proposes a lightweight anonymous authentication method based on the PUF function, including the following steps: S1. Perform a hash operation on the physical characteristics of the sensor network nodes to generate a hidden identifier corresponding to the nodes; among them, the sensor network nodes include sensor nodes and gateway nodes.
[0029] As an alternative embodiment, performing a hash operation on the physical characteristics of the sensor network nodes to generate a hidden identifier corresponding to the nodes includes the following steps: Obtain the physical unclonable function seed value according to the physical characteristic differences of the sensor SRAM after power - on , perform BCH encoding on the physical unclonable function seed value to obtain the consistency parameter and the corresponding auxiliary data ; Generate the sensor physical fingerprint according to the physical unclonable function seed value , the consistency parameter and the auxiliary data ; Perform a hash operation on the sensor physical fingerprint to obtain the hidden identifier corresponding to the sensor node 。
[0030] It can be understood that in this embodiment, taking the wireless sensor nodes deployed in the smart grid distribution network as an example, the low-power MCU (such as STM32L433) carried by them has 32KB SRAM built-in. When powered on, due to the transistor threshold voltage deviation (±50mV), the flip time of the storage unit shows differences; the on-chip ADC synchronously samples the rising edges of the voltages of 1024 units, and quantifies and generates a 1024-bit binary sequence as the physical unclonable function seed value (such as 0b101100101...), and uses the non-replicability of the manufacturing process to build the hardware-level identity foundation. Subsequently, the (1024, 512, 10) BCH coding scheme is adopted to generate 512-bit parity bits for the first 512-bit information bits as consistency parameters , and record the coding generation matrix as auxiliary data , which can correct the error codes caused by environmental noise (such as the 3% flip bit error caused by temperature fluctuations), and ensure the consistent extraction of physical characteristics. Then the last 512-bit original data is concatenated with to form a 1024-bit sensor physical fingerprint containing inherent characteristics and error correction capabilities , which resists the feature drift caused by device aging or external interference. Finally, through the lightweight SHA-256 algorithm, is subjected to a hash operation, and the first 256 bits are intercepted as the hidden identifier (such as 0x5a3f9c2d...), which provides anti-collision security while compressing the physical feature dimension. The whole process takes low time and low energy consumption, which not only realizes the dynamic binding of device identity and hardware characteristics, but also adapts to the computing resource limitations of sensor nodes with lightweight design, providing an unforgeable, stable and reliable security environment for subsequent private channel establishment and mutual authentication.
[0031] As an alternative embodiment, performing a hash operation on the physical characteristics of the sensing network nodes to generate the hidden identifier of the corresponding nodes further includes the following steps: Obtaining the physical unclonable function seed value according to the physical characteristic differences after the gateway SRAM is powered on , and performing BCH coding on the physical unclonable function seed value to obtain the consistency parameter and the corresponding auxiliary data ; Generating the gateway physical fingerprint according to the physical unclonable function seed value , the consistency parameter and the auxiliary data ; ; By performing a hash operation on the physical fingerprint of the gateway to obtain the hidden identifier of the corresponding gateway node .
[0032] It can be understood that in this embodiment, the intelligent grid edge computing node is used as the gateway node (GN), which is equipped with a processor (such as an ARM Cortex-A72 processor) and externally hangs an SRAM chip (such as a 2MB IS61LV25616 type chip). By using the difference in the first flip time of 2048 storage units during the row address scan of the chip (with an accuracy of 50 ps), a 2048-bit binary sequence is collected through the on-chip timer as the physical unclonable function seed value (such as 0b110011010...), ensuring the strong uniqueness of the physical characteristics. The (2048, 1024, 20) BCH coding scheme is used to process the first 1024 information bits to generate 1024 check bits as consistency parameters , and record the segmented coding offset (in groups of 256 bits) as auxiliary data , which can correct error codes caused by power supply ripple or electromagnetic interference, and ensure the feature stability in a complex industrial environment. The last 1024-bit raw data and are cross-stitched by bytes to form a 2048-bit gateway physical fingerprint , integrating the original characteristics and the multi-level error correction mechanism, effectively resisting the feature drift caused by chip aging. By performing an operation on through the SHA-512 hash algorithm, the last 256 bits are intercepted as the hidden identifier (such as 0xe7b41a5f...). By using the collision resistance of the hash function to strengthen the non-forgeability of the identity identifier, the entire processing flow takes a short time and consumes little power. While meeting the high-performance requirements of the gateway node, it realizes the efficient connection between the physical layer identity identifier and the protocol layer authentication logic, providing a hardware-level trust anchor with both security and scalability for the dynamic interconnection of heterogeneous nodes in the intelligent grid.
[0033] S2. Construct a private channel between the sensor node and the gateway node, and receive each other's public identifier and hidden identifier through the private channel to complete the initial parameter configuration of each sensor network node.
[0034] As an alternative embodiment, the construction of the private channel between the sensor node and the gateway node includes the following steps: Generate pseudo handshake information according to the computing resources and network resources required by the sensor node. The gateway node receives the pseudo handshake information through a common channel and determines the bandwidth and transmission rate of the channel to be allocated according to the pseudo handshake information; generate a binary random number L1 according to the bandwidth and transmission rate, and encrypt the pseudo handshake information with the binary random number L1 to obtain a pseudo encryption block and send it to the sensor node; Perform an exclusive OR operation on the pseudo encryption block through the pseudo handshake information to obtain the binary random number L1, and encrypt the common channel with the binary random number L1 to obtain a private channel.
[0035] It can be understood that in the distributed monitoring scenario of the smart grid in this embodiment, the sensor node (SN) generates pseudo handshake information including the device capability vector based on its own resource constraints (such as the computing main frequency of 16 MHz, available RAM of 8 KB, and bandwidth upper limit of 250 kbps) , where is the CPU frequency (16 MHz is quantized to 0x10), is the remaining memory (such as 4 KB is represented as 0x1000), is the instantaneous bandwidth (such as 128 kbps is represented as 0x2000). After the gateway node (GN) receives the pseudo handshake information , calculate the matching channel parameters through a pre-trained resource allocation model (a linear regression model trained based on historical data, the construction and training processes of which are all within the scope of the technical personnel in the field and will not be elaborated here), determine that the bandwidth to be allocated is 100 kbps (0x1900), the transmission rate is 50 kbps (0x0C80), and generate a 128-bit binary random number L1 (such as `0b1011001...`). GN uses L1 to perform exclusive OR encryption to generate a pseudo encryption block (such as `0x3a5f...`), and send it to the sensor node SN through a common channel (such as the ZigBee frequency band). After the sensor node SN receives the pseudo encryption block , use the locally saved pseudo handshake information to perform reverse exclusive OR operation , and quickly recover the random number L1. Subsequently, both parties use L1 as the session key to encrypt the subsequent communication data through the CTR mode of AES-128 to construct a transport layer private channel. The key generation only requires 2 exclusive OR operations, with low power consumption and short time consumption, effectively resisting traffic analysis attacks (because the pseudo handshake information does not contain sensitive content), and because L1 only exists in a single session (TTL = 30 s), even if the key is leaked, the historical communication content cannot be traced, realizing the construction of a lightweight secure channel in a resource-constrained environment and providing dynamic encryption guarantee for the real-time data transmission of the smart grid.
[0036] As an alternative embodiment, after registration and initialization are completed, the initial parameters of the sensor node are ; the initial parameters of the gateway node are ; where is the public identifier of the sensor node; is the public identifier of the gateway node; is the synchronization serial number of the sensor / gateway node; is the hidden identifier of the sensor node; is the hidden identifier of the gateway node; is the consistency parameter of the sensor node; is the consistency parameter of the gateway node; is the auxiliary data of the sensor node; is the auxiliary data of the gateway node.
[0037] S3. Perform a hash operation on the geographical characteristics and initial parameters of the sensor node to generate a handshake message.
[0038] As an alternative embodiment, the performing a hash operation on the geographical characteristics and initial parameters of the sensor node to generate a handshake message includes the following steps: The sensor node generates random location information , and performs a hash operation on , and in the initial parameters to obtain a fuzzy location , denoted as ; performs a hash operation on , in combination with the random location information to obtain a location verification value V, denoted as ; generates a handshake message based on in the initial parameters, the fuzzy location .
[0039] It can be understood that in the scenario of monitoring the transmission line of the smart grid in this embodiment, the sensor node (SN) generates 128-bit random location information Pos (such as `0x3f5a2d1e...`, which can be the binary encoding corresponding to the longitude and latitude 30.12°N, 120.34°E) in real time based on the Beidou positioning module, in combination with the sensor hidden identifier (256 bits, such as `0x5a3f9c2d...`), the gateway node hidden identifier (256 bits, such as `0xe7b41a5f...`) and the synchronization serial number (32 bits, such as 0x00010203), perform a hash operation on the concatenated value of the three ( , with a total length of 544 bits), take the first 128-bit result and perform an exclusive OR operation with Pos to obtain the fuzzy position MPos (such as `0x2b6d...`), realizing the dynamic binding of the real position and the node identity. At the same time, perform a hash on the concatenated value of (with a total length of 416 bits) through SHA-256 to generate a 256-bit position verification value V (such as `0x9c2d...`), ensuring the consistency of the position information and the node status. Finally, encapsulate the public identifier of the gateway node (such as the hexadecimal encoding of the MAC address `00:1A:2B:3C:4D:5E`), MPos, and V into the handshake information , and transmit it through a private channel (using AES-128 encryption). During this process, Pos is randomly updated each time for authentication (entropy value 128 bits), MPos hides the real coordinates through exclusive OR confusion, and V uses a hash chain to ensure integrity. Even if an attacker intercepts the handshake information, due to the lack of and , it is impossible to reverse-resolve Pos or forge a legitimate V value. While resisting location spoofing attacks (such as GPS forgery), it meets the requirements of node mobility and real-time performance in transmission line monitoring, realizing the lightweight and secure integration of geographical characteristics and identity authentication.
[0040] S4. The gateway node generates feedback information according to the first authentication strategy in response to the handshake information.
[0041] As an alternative embodiment, the gateway node generates feedback information according to the first authentication strategy in response to the handshake information; it includes the following steps: After the handshake information is sent to the gateway node through a private channel, if the comparison fails, the authentication is terminated; If the comparison is successful, then extract , in the initial parameters and the serial number of the gateway node to perform a hash operation to obtain the original position , denoted as ; according to , the serial number of the gateway node, the original position to perform a hash operation to obtain the position verification value , denoted as ; If , then initiate authentication again, and use , and the serial number of the gateway node Through The encryption algorithm is packaged into an encrypted information block , denoted as ; The gateway node will and As feedback information and sent to the sensor node through the private channel; If , the gateway node generates a random number , according to the , in the initial parameters, random number Perform a hash operation to obtain the identity derivation factor , denoted as ; According to the original location , identity derivation factor Perform a hash operation to obtain the initial session key , denoted as ; The , in the initial parameters, original location The operation result of the hash operation is XORed with the random number to obtain the encrypted random number M, denoted as ; Original location , initial session key Through The encryption algorithm is packaged into an encrypted information block , denoted as , set the session key ; The gateway node will , and As feedback information and sent to the sensor node through the private channel.
[0042] In this embodiment, the dynamic update mechanism (incremented after each authentication) of the random number R and the serial number ensures the uniqueness of the session key. Combining the hash chain and XOR confusion technology, attackers cannot reverse-derive the random number R or the initial session key from the intercepted encrypted random number M and feedback information APS, achieving perfect forward secrecy; The lightweight design of the LEA and IEA algorithms takes short time and consumes little power, adapts to the edge computing ability of GN, and can still maintain a high authentication success rate in the substation multi-node concurrent authentication scenario, effectively ensuring the transmission security and integrity of the real-time monitoring data of the smart grid.
[0043] S5. The sensor node generates an authentication result according to the second authentication strategy in response to the feedback information, and the gateway node executes subsequent actions in response to the authentication result.
[0044] As an alternative embodiment, the sensor node generates an authentication result according to the feedback information in response to the second authentication policy, and the gateway node performs subsequent actions in response to the authentication result; the steps are as follows: According to the initial parameters , the serial number of the sensor node , and the random position perform a hash operation to obtain a position verification value , denoted as ; If , the sensor node calculates . If the public identifier of the sensor node after decryption , set . Through the private channel, the authentication result and are fed back to the gateway node, and a new authentication request is initiated; if , the sensor node feeds back the authentication result and to the gateway node through the private channel, and a new authentication request is initiated; If , the sensor node calculates the original random number , the original identity derivation factor ; the original session key ; the original random position ; If , the authentication fails. After feeding back the authentication result to the gateway node through the private channel, a new authentication request is initiated; if , set the session key , , and feed back the authentication result to the gateway node through the private channel and then initiate a new authentication request; After the gateway node receives the authentication result , set .
[0045] In this embodiment, the SN improves the anti-replay attack ability through a three-level verification mechanism (position verification → key verification → serial number synchronization verification). The combination of the IEA and LEA algorithms reduces the key derivation time and meets the response requirements of distribution terminals (such as DTUs); the dynamic update of the serial number (increasing every authentication cycle) combined with timestamp verification greatly reduces the success rate of replay attacks; the use of the CCM mode (AEAD encryption, providing integrity protection) ensures the non-forgeability of ACK messages and maintains a very high authentication success rate in an interference environment, realizing high-strength two-way authentication in a resource-constrained environment and building a reliable security channel for real-time data transmission in the smart grid.
[0046] Embodiment 2: Another technical solution provided in the embodiments of the present invention is: A lightweight anonymous authentication system, applicable to the lightweight anonymous authentication method based on the PUF function, such as Figure 2 as shown, including: Calculation module 101: Generate a hidden identifier corresponding to a node based on the physical characteristics of the sensor network node in combination with a hash function; wherein, the sensor network node includes a sensor node and a gateway node; Channel construction module 102: Construct a private channel between the sensor node and the gateway node; Parameter configuration module 103: Complete the initial parameter configuration of each sensor network node through the public identifier and the hidden identifier; First generation module 104: Generate a handshake message based on the geographical characteristics of the sensor node and the initial parameters in combination with a hash function; Second generation module 105: The gateway node generates a feedback message in response to the handshake message according to the first authentication policy; Execution module 106: The sensor node generates an authentication result in response to the feedback message according to the second authentication policy, and the gateway node executes subsequent actions in response to the authentication result.
[0047] In this embodiment, through the synergistic effect of hardware feature binding, lightweight algorithm integration and dynamic key management, the system realizes three-dimensional security protection of "physical layer anti-attack - protocol layer anti-forgery - transmission layer anti-eavesdropping" in the smart grid scenario, and at the same time meets the strict restrictions on the computing resources and communication bandwidth of the sensor node, providing efficient and reliable technical support for the secure interconnection of large-scale distributed intelligent devices.
[0048] Embodiment 3: An optional embodiment provided in the embodiments of the present invention is: An electronic device, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor calls the computer program in the memory, the steps of the lightweight anonymous authentication method based on the PUF function are implemented.
[0049] Embodiment 4: An optional embodiment provided in the embodiments of the present invention is: A storage medium, wherein computer-executable instructions are stored in the storage medium, and when the computer-executable instructions are loaded and executed by a processor, the steps of the lightweight anonymous authentication method based on the PUF function are implemented.
[0050] Through the description of the above embodiments, those skilled in the art can understand that, for the convenience and conciseness of description, only the above division of each functional module is used as an example for illustration. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of a specific device is divided into different functional modules to complete all or part of the functions described above.
[0051] In the embodiments provided in this application, it should be understood that the disclosed structures and methods can be implemented in other ways. For example, the embodiments of the structures described above are only illustrative. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another structure, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of structures or units can be in electrical, mechanical or other forms.
[0052] The units described as separate components may or may not be physically separated. The components displayed as units may be one physical unit or multiple physical units, that is, they can be located in one place, or they can be distributed to multiple different places. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0053] In addition, each functional unit in the embodiments of this application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0054] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiments of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions to enable a device (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the methods of the various embodiments of this application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical discs that can store program codes.
[0055] The above-mentioned specific implementation manners are the preferred implementation manners of the lightweight anonymous authentication method and system based on the PUF function of the present invention, and do not limit the specific implementation scope of the present invention. The scope of the present invention includes but is not limited to this specific implementation manner. All equivalent changes made according to the shape and structure of the present invention are within the protection scope of the present invention.
Claims
1. A lightweight anonymous authentication method based on the PUF function, characterized in that: It includes the following steps: Performing a hash operation on the physical characteristics of the sensor network nodes to generate hidden identifiers corresponding to the nodes; wherein, the sensor network nodes include sensor nodes and gateway nodes; Constructing a private channel between the sensor nodes and the gateway nodes, and receiving the public identifiers and hidden identifiers of each other through the private channel to complete the initial parameter configuration of each sensor network node; Performing a hash operation on the geographical characteristics and initial parameters of the sensor nodes to generate handshake information; the gateway node generates feedback information in response to the handshake information according to the first authentication policy; The sensor node generates an authentication result in response to the feedback information according to the second authentication policy, and the gateway node performs subsequent actions in response to the authentication result.
2. The lightweight anonymous authentication method based on the PUF function according to claim 1, characterized in that: The performing a hash operation on the physical characteristics of the sensor network nodes to generate hidden identifiers corresponding to the nodes includes the following steps: Obtain the physical unclonable function (PUF) seed value based on the physical characteristic differences of the sensor SRAM after power-on , for the physical unclonable function seed value perform BCH encoding to obtain the consistency parameter and the corresponding auxiliary data ; Generate a sensor physical fingerprint based on the physical unclonable function seed value , the consistency parameter , and the auxiliary data ; By performing a hash operation on the physical fingerprint of the sensor to obtain the hidden identifier corresponding to the sensor node .
3. The lightweight anonymous authentication method based on the PUF function according to claim 1, characterized in that: The performing a hash operation on the physical characteristics of the sensor network nodes to generate hidden identifiers corresponding to the nodes further includes the following steps: Obtain the physical unclonable function (PUF) seed value based on the physical characteristic differences after the gateway SRAM is powered on , for the physical unclonable function seed value Perform BCH encoding to obtain the consistency parameter and the corresponding auxiliary data ; Generate a gateway physical fingerprint based on the physical unclonable function seed value , consistency parameter and auxiliary data ; By performing a hash operation on the physical fingerprint of the gateway to obtain the hidden identifier of the corresponding gateway node .
4. The lightweight anonymous authentication method based on the PUF function according to claim 1, wherein: The constructing a private channel between the sensor nodes and the gateway nodes includes the following steps: Generating pseudo-handshake information according to the computing resources and network resources required by the sensor nodes, the gateway node receives the pseudo-handshake information through the public channel and determines the bandwidth and transmission rate of the channel to be divided according to the pseudo-handshake information; generating a binary random number L1 according to the bandwidth and transmission rate and encrypting the pseudo-handshake information with the binary random number L1 to obtain a pseudo-encrypted block and sending it to the sensor node; Performing an exclusive OR operation on the pseudo-encrypted block with the pseudo-handshake information to obtain the binary random number L1, and encrypting the public channel with the binary random number L1 to obtain a private channel.
5. The lightweight anonymous authentication method based on the PUF function according to claim 1, wherein: The initial parameters of the sensor node are The initial parameters of the gateway node are ; wherein, is the public identifier of the sensor node; is the public identifier of the gateway node; is the synchronization serial number of the sensor / gateway node; is the hidden identifier of the sensor node; is the hidden identifier of the gateway node; is the consistency parameter of the sensor node; is the consistency parameter of the gateway node; is the auxiliary data of the sensor node; is the auxiliary data of the gateway node.
6. The lightweight anonymous authentication method based on the PUF function according to claim 5, wherein: The performing a hash operation on the geographical characteristics and initial parameters of the sensor nodes to generate handshake information includes the following steps: The sensor node generates random location information , and performs a hash operation on , and to obtain the fuzzy location , denoted as ; for , in the initial parameters, combine with the random location information to perform a hash operation to obtain the location verification value V, denoted as ; based on in the initial parameters, the fuzzy location , and the location verification value V, generate the handshake information .
7. The lightweight anonymous authentication method based on the PUF function according to claim 5, wherein: The gateway node generates feedback information in response to the handshake information according to the first authentication policy includes the following steps: Handshake information After being sent to the gateway node through the private channel, if the comparison fails, the authentication is terminated; If the comparison is successful, extract the , and the serial number of the gateway node to perform a hash operation to obtain the original location , denoted as ; According to the in the initial parameters, the serial number of the gateway node , and the original location to perform a hash operation to obtain the location verification value , denoted as ; If , re-initiate authentication, and pack the , in the initial parameters and the serial number of the gateway node into an encrypted information block APS through the encryption algorithm, denoted as ; the gateway node sends and as feedback information to the sensor node through the private channel; If the gateway node generates a random number and performs a hash operation based on the and in the initial parameters and the random number to obtain an identity derivation factor denoted as ; and performs a hash operation based on the original location and the identity derivation factor to obtain an initial session key denoted as ; Perform a hash operation on the , , and the original position . The operation result is XORed with the random number to obtain the encrypted random number M, denoted as ; The original position and the initial session key are packed into an encrypted information block APS through , denoted as , and the session key is set; The gateway node sends , and as feedback information to the sensor node through a private channel.
8. The lightweight anonymous authentication method based on the PUF function according to claim 5, wherein: The sensor node generates an authentication result in response to the feedback information according to the second authentication policy, and the gateway node performs subsequent actions in response to the authentication result includes the following steps: According to the initial parameters , the serial number of the sensor node , the random position , perform a hash operation to obtain a position verification value , denoted as ; If , the sensor node calculates . If the public identifier of the decrypted sensor node , set . The authentication result and are fed back to the gateway node through a private channel, and an authentication application is initiated again; if , the sensor node feeds back the authentication result and to the gateway node through a private channel and initiates an authentication application again; If , the sensor node calculates the original random number , the original identity derivation factor ; the original session key ; the original random position ; If , the authentication fails, and the authentication result is fed back to the gateway node through the private channel and then a new authentication request is initiated; if , set the session key , , and the authentication result is fed back to the gateway node through the private channel and then a new authentication request is initiated; The gateway node receives the authentication result and then sets .
9. A lightweight anonymous authentication system applicable to the lightweight anonymous authentication method based on the PUF function according to any one of claims 1 to 8, wherein: Computing module: Generating hidden identifiers corresponding to the nodes based on the physical characteristics of the sensor network nodes in combination with a hash function; wherein, the sensor network nodes include sensor nodes and gateway nodes; Channel construction module: Constructing a private channel between the sensor nodes and the gateway nodes; Parameter configuration module: Completing the initial parameter configuration of each sensor network node through the public identifier and the hidden identifier; The first generation module: Generate handshake information based on the geographical characteristics of sensor nodes and initial parameters in combination with a hash function; The second generation module: The gateway node generates feedback information in response to the handshake information according to the first authentication policy; The execution module: The sensor node generates an authentication result in response to the feedback information according to the second authentication policy, and the gateway node executes subsequent actions in response to the authentication result.
10. An electronic device, characterized in that: It includes a memory and a processor. A computer program is stored in the memory. When the processor calls the computer program in the memory, the steps of the lightweight anonymous authentication method based on the PUF function described in any one of claims 1 to 8 are implemented.
11. A storage medium, characterized in that: Computer-executable instructions are stored in the storage medium. When the computer-executable instructions are loaded and executed by a processor, the steps of the lightweight anonymous authentication method based on the PUF function described in any one of claims 1 to 8 are implemented.
Citation Information
Patent Citations
Pseudo random sequence generation method for wireless sensor network nodes and application method thereof
CN103826218A
Physical layer modulation scrambling method based on pseudorandom sequence
CN111711587A
Lightweight anonymous identity authentication scheme for Internet of Things
CN119051868A
Lightweight dynamic security authentication method and system implemented based on PUF (Physical Unclonable Function)
CN119402205A
IWSN sensor access authentication protocol method of TCA and PUF
CN119767305A