Lightweight anonymous authentication method and system based on PUF function
By generating the physical characteristics of sensor network nodes, hiding identifiers and building private channels, combining lightweight hashing operations and dynamic key derivation mechanisms, the security and resource efficiency problems of the smart grid authentication protocol are solved, and hardware-level trust root and low-cost two-way authentication are realized.
Patent Information
- Application Number
- CN202510739189.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-04
- Publication Date
- 2025-08-15
- Estimated Expiration
- 2045-06-04
AI Technical Summary
The existing smart grid authentication protocol has shortcomings in terms of security and resource efficiency, and cannot effectively resist man-in-the-middle attacks and replay attacks, and has not fully utilized the physical characteristics of the equipment to build a root of trust. It has high computing and communication costs, making it difficult to adapt to sensor nodes with limited resources.
By extracting the physical characteristics of the sensor network nodes, a unique hidden identifier is generated, a private channel between the sensor and the gateway is built, and a lightweight hashing operation and dynamic key derivation mechanism is combined to realize two-way authentication, reduce computing and communication resource consumption, and adapt to resource-constrained environments.
It provides a hardware-level trust root, resists physical attacks and identity forgery, reduces computing and communication resource consumption, enhances dynamic defense capabilities, ensures forward confidentiality, and adapts to smart grid environments with limited resources.
Smart Images

Figure CN120263553B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to a lightweight anonymous authentication method and system based on a PUF function. Background Art
[0002] As smart grids evolve towards intelligent interconnection of terminal devices, open systems allow attackers to impersonate legitimate participants and steal power control information, making device authentication and data protection particularly important. Currently, wireless sensor network applications in smart grids face challenges in node authentication under dynamic topologies. Existing authentication protocols have the following significant flaws:
[0003] In terms of security, it lacks perfect forward secrecy and user anonymity, and cannot defend against various threats such as man-in-the-middle attacks and impersonation attacks; in terms of performance, the high computing and communication costs make it difficult to adapt to resource-constrained devices such as sensor nodes; in terms of physical layer security: the trust root is not established by utilizing the physical characteristics of the device, making it vulnerable to physical attacks; in addition, the application of new security technologies such as PUF is insufficient, and the fuzzy extractor's processing mechanism for PUF noise is not yet mature, which has become a technical barrier restricting the security certification of smart grids.
[0004] The above information disclosed in this Background section is only for enhancement of understanding of the background of the application and therefore it may contain information that does not form the prior art that is already known to a person of ordinary skill in the art. Summary of the Invention
[0005] The purpose of the present invention is to address the defects of insufficient security and low resource efficiency in existing smart grid authentication protocols. This application proposes a lightweight anonymous authentication method and system based on PUF function, which generates a unique hidden identifier by extracting the physical characteristics of the sensor network nodes to achieve hardware-level identity binding; dynamically builds a private channel between the sensor and the gateway, generates handshake information based on the hash operation of initial parameters and geographical characteristics, and completes two-way identity authentication through a two-level authentication strategy; combines lightweight hash operation with dynamic key derivation mechanism, while ensuring the ability to resist man-in-the-middle attacks and replay attacks, significantly reduces the consumption of computing and communication resources, and adapts to the resource-constrained smart grid environment.
[0006] In a first aspect, a technical solution provided in an embodiment of the present invention is: a lightweight anonymous authentication method based on a PUF function, comprising the following steps:
[0007] Performing a hash operation on the physical characteristics of a sensor network node to generate a hidden identifier of the corresponding node; wherein the sensor network node includes a sensor node and a gateway node;
[0008] Build a private channel between the sensor node and the gateway node, receive each other's public identifiers and hidden identifiers through the private channel to complete the initial parameter configuration of each sensor network node;
[0009] Performing a hash operation on the geographical characteristics and initial parameters of the sensor node to generate a handshake message; the gateway node generates feedback information in response to the handshake message according to the first authentication strategy;
[0010] The sensor node generates an authentication result in response to the feedback information according to the second authentication strategy, and the gateway node performs subsequent actions in response to the authentication result.
[0011] Preferably, performing a hash operation on the physical characteristics of the sensor network node to generate a hidden identifier of the corresponding node comprises the following steps:
[0012] Get the physical unclonable function seed value based on the physical characteristics difference after the sensor SRAM is powered on , for the physical unclonable function seed value Perform BCH encoding to obtain consistency parameters And the corresponding auxiliary data ;
[0013] Seed value according to physical unclonable function , consistency parameters and auxiliary data Generate sensor physical fingerprint ;
[0014] By physically fingerprinting the sensor Perform hash operation to obtain the hidden identifier of the corresponding sensor node .
[0015] Preferably, the step of performing a hash operation on the physical characteristics of the sensor network node to generate a hidden identifier of the corresponding node further comprises the following steps:
[0016] Get the physical unclonable function seed value based on the physical characteristics difference after the gateway SRAM is powered on , for the physical unclonable function seed value Perform BCH encoding to obtain consistency parameters And the corresponding auxiliary data ;
[0017] Seed value according to physical unclonable function , consistency parameters and auxiliary data Generate gateway physical fingerprint ;
[0018] By physical fingerprinting the gateway Perform hash operation to obtain the hidden identifier of the corresponding gateway node .
[0019] This solution constructs a dynamic security authentication foundation from the physical layer to the protocol layer through hierarchical hardware feature extraction and cryptographic processing. First, the PUF seed value is generated by leveraging the unique physical characteristic differences between the sensor and gateway node SRAMs due to manufacturing process differences after power-on. This deeply binds the device identity to the non-replicable hardware characteristics, fundamentally resisting physical attacks and identity forgery. The PUF seed value is then error-corrected through BCH encoding to generate consistency parameters and auxiliary data. A fuzzy extractor mechanism is then constructed to effectively overcome the interference of physical noise on the PUF response, ensuring the stability and reliability of identity identification. A physical fingerprint is then generated based on the seed value, encoding parameters, and auxiliary data, forming the device's unique "digital DNA" at the physical layer and providing an unalterable root of trust for authentication. Finally, a hash operation is used to convert the physical fingerprint into a hidden identifier. While protecting the original physical characteristics, it provides a lightweight identity authentication factor for the authentication protocol, achieving a seamless integration of hardware characteristics and authentication logic. This addresses the core flaw of existing technologies, which lack a physical layer root of trust and are vulnerable to physical attacks, and lays a hardware-level security foundation for subsequent private channel construction and two-way authentication processes.
[0020] Preferably, the step of establishing a private channel between the sensor node and the gateway node comprises the following steps:
[0021] Generate pseudo handshake information based on the computing resources and network resources required by the sensor node, the gateway node receives the pseudo handshake information through a public channel and determines the bandwidth and transmission rate of the channel to be divided based on the pseudo handshake information; generate a binary random number L1 based on the bandwidth and transmission rate, and use the binary random number L1 to encrypt the pseudo handshake information to obtain a pseudo encrypted block and send it to the sensor node;
[0022] The pseudo-encryption block is XORed with the pseudo-handshake information to obtain a binary random number L1, and the public channel is encrypted with the binary random number L1 to obtain a private channel.
[0023] As a preference, the initial parameters of the sensor node are The initial parameters of the gateway node are ;
[0024] in, is the public identifier of the sensor node; is the public identifier of the gateway node; is the synchronization sequence number of the sensor / gateway node; is the hidden identifier of the sensor node; is the hidden identifier of the gateway node; is the consistency parameter of the sensor node; is the consistency parameter of the gateway node; Auxiliary data for sensor nodes; Auxiliary data for the gateway node.
[0025] Preferably, performing a hash operation on the geographical characteristics and initial parameters of the sensor node to generate handshake information comprises the following steps:
[0026] Sensor nodes generate random location information , for the initial parameters 、 and Perform hash operation to get fuzzy position ,remember ; For the initial parameters 、 Combined with random position information Perform hash operation to get the position verification value V, record ; Based on the initial parameters , fuzzy location , position verification value V generates handshake information .
[0027] Preferably, the gateway node generates feedback information in response to the handshake information according to the first authentication policy, comprising the following steps:
[0028] Handshake information After being sent to the gateway node through a private channel, if If the comparison fails, the authentication is terminated;
[0029] like If the comparison is successful, the initial parameters are extracted. 、 and the serial number of the gateway node Perform hash operation to get the original location ,remember ; According to the initial parameters , the serial number of the gateway node , original position Perform hash operation to obtain the location verification value ,remember ;
[0030] like , then re-initiate authentication and change the initial parameters 、 and the serial number of the gateway node pass Encryption algorithms are packaged into encrypted information blocks ,remember ; The gateway node will and As feedback information, it is sent to sensor nodes through private channels;
[0031] like , the gateway node generates a random number , according to the initial parameters 、 , random numbers Perform hash operation to obtain identity derivation factor ,remember ; Based on the original position , identity-derived factors Perform hash operation to obtain the initial session key ,remember ; Change the initial parameters 、 , original position The result of the hash operation and the random number Perform XOR operation to get the encrypted random number M, record ;Original position , initial session key pass Encryption algorithms are packaged into encrypted information blocks ,remember , set the session key ; The gateway node will , and It is used as feedback information and sent to the sensor nodes through private channels.
[0032] Preferably, the sensor node generates an authentication result in response to the feedback information according to the second authentication strategy, and the gateway node performs subsequent actions in response to the authentication result; the steps include:
[0033] According to the initial parameters , the serial number of the sensor node , random position Perform hash operation to obtain the location verification value ,remember ;
[0034] like , sensor node computing , if the public identifier of the decrypted sensor node ,set up , the authentication result is sent through a private channel and Feedback to the gateway node and re-initiate the authentication application; if , the sensor node transmits the authentication result through a private channel and Feedback to the gateway node and re-initiate the authentication application;
[0035] like , the sensor node calculates the original random number , original identity derived factors ; Original session key ; Original random position ;
[0036] like , the authentication fails and the authentication result is sent to the private channel. After feedback to the gateway node, re-initiate the authentication application; if , set the session key , and send the authentication result through a private channel After feedback to the gateway node, re-initiate the authentication application;
[0037] The gateway node receives the authentication result After that, set .
[0038] In a second aspect, an embodiment of the present invention further provides a technical solution: a lightweight anonymous authentication system, applicable to a lightweight anonymous authentication method based on a PUF function, comprising:
[0039] Computation module: Generates hidden identifiers of corresponding nodes based on the physical characteristics of sensor network nodes combined with hash functions; sensor network nodes include sensor nodes and gateway nodes;
[0040] Channel construction module: builds private channels between sensor nodes and gateway nodes;
[0041] Parameter configuration module: completes the initial parameter configuration of each sensor network node through public identifiers and hidden identifiers;
[0042] The first generation module: generates handshake information based on the geographical characteristics and initial parameters of the sensor node combined with the hash function;
[0043] Second generation module: The gateway node generates feedback information in response to the handshake information according to the first authentication policy;
[0044] Execution module: The sensor node generates an authentication result in response to the feedback information according to the second authentication strategy, and the gateway node executes subsequent actions in response to the authentication result.
[0045] In the third aspect, a technical solution provided in an embodiment of the present invention is: an electronic device, comprising a memory and a processor, wherein a computer program is stored in the memory, and when the processor calls the computer program in the memory, it implements the steps of a lightweight anonymous authentication method based on PUF function.
[0046] In a fourth aspect, a technical solution provided in an embodiment of the present invention is: a storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are loaded and executed by a processor, the steps of a lightweight anonymous authentication method based on PUF function are implemented.
[0047] The present invention has at least the following substantial beneficial effects:
[0048] (1) To address the problem that existing smart grid authentication protocols do not use the physical characteristics of devices to build a root of trust and are vulnerable to physical attacks, this application obtains a PUF seed value based on the difference in physical characteristics of the sensor and gateway SRAM after power-on, performs BCH encoding on it to obtain consistency parameters and auxiliary data to generate a physical fingerprint, and then performs a hash operation on the physical fingerprint to obtain a hidden identifier, deeply binding the device identity with the physical characteristics. This achieves the technical effect of building a unique identity from the hardware physical layer, resisting physical attacks and identity forgery, and providing a reliable hardware-level root of trust for authentication;
[0049] (2) In order to solve the problem that most existing smart grid authentication protocols have high computational and communication costs and are not suitable for resource-constrained environments, this application generates pseudo-handshake information based on the resources required by the sensor nodes. The gateway node determines the channel parameters based on this information and generates a binary random number encryption to obtain a private channel. In the authentication process, a lightweight hash function, XOR operation and LEA encryption algorithm are used, combined with a dynamically constructed private channel for initial parameter configuration and authentication information transmission. This achieves the technical effect of reducing computational and communication resource consumption, adapting to resource-constrained smart grid environments, and meeting the low power consumption requirements of sensor nodes and other devices.
[0050] (3) In response to the problem that existing smart grid protocols lack perfect forward secrecy and cannot effectively resist threats such as replay attacks, this application uses sensor nodes to generate random location information during the authentication process, combines the hidden identifier and synchronization sequence number in the initial parameters to perform hash operations to generate handshake information, and the gateway node and sensor node perform hash operations and key derivation in the response process based on dynamic parameters such as random numbers and synchronization sequence number updates. The handshake information and keys of each authentication session change dynamically, achieving the technical effects of enhancing dynamic defense capabilities, ensuring forward secrecy, and effectively resisting replay attacks and man-in-the-middle attacks, thereby ensuring the authenticity and integrity of data transmission.
[0051] The above content of the invention is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] Other features, objects, and advantages of the present invention will become more apparent upon reading the detailed description of the non-limiting embodiments made with reference to the following drawings. The drawings are for the purpose of illustrating preferred embodiments only and are not to be construed as limiting the present invention. Like reference characters are used throughout the drawings to designate like parts.
[0053] Figure 1 This is a flow chart of the lightweight anonymous authentication method based on PUF function of the present invention.
[0054] Figure 2 This is a structural block diagram of the lightweight anonymous authentication system of the present invention. DETAILED DESCRIPTION
[0055] In order to make the objectives, technical solutions and advantages of the present invention more clear, the present invention is further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific implementation method described herein is only an optimal embodiment of the present invention, which is only used to explain the present invention and does not limit the scope of protection of the present invention. All other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.
[0056] Before discussing the exemplary embodiments in more detail, it should be mentioned that some exemplary embodiments are described as processes or methods depicted as flow charts. Although the flow charts describe the operations (or steps) as sequential processes, many of the operations (or steps) therein can be performed in parallel, concurrently, or simultaneously. In addition, the order of the operations can be rearranged. The process can be terminated when its operations are completed, but can also have additional steps not included in the figures; the process can correspond to a method, function, procedure, subroutine, subprogram, etc.
[0057] As a crucial component of modern power systems, smart grids are evolving towards intelligent interconnection of end devices, playing a key role in optimizing energy distribution. Due to the open nature of smart grid systems, attackers can access data in public channels and impersonate legitimate participants. However, the power control information transmitted within smart grid environments is crucial. Leakage of this information can lead to financial losses, confidential information disclosure, and power control issues.
[0058] Unlike traditional networks and other sensor technologies, wireless sensor network technology allows for rapid network construction. Its topological uncertainty allows for flexible addition and deletion of nodes, and its robustness is also extremely difficult to disrupt. A wireless sensor network consists of three main components: nodes, sensor networks, and users. Nodes are typically deployed within a specific range to meet monitoring requirements. The sensor network is the most crucial component, collecting information from all nodes through fixed channels, performing analysis and computation on this information, and ultimately aggregating the results to a base station. This data is then transmitted to designated users via satellite communications, enabling wireless sensing.
[0059] In smart grid authentication scenarios, authentication protocols are designed for grid operators, distributed generation units (DGs), end consumers, and various sensors and smart devices. These roles create a complex and dynamic authentication environment. For example, grid operators need to ensure the authenticity and integrity of remote control commands; DGs need to verify that the grid company is receiving their power generation data; and end consumers need to confirm that the electricity service information they receive comes from a trusted service provider.
[0060] The protocol authentication system of the present invention consists of two main components: a sensor node (SensorNode) and a gateway node (GatewayNode). These two nodes need to generate device numbers through the registration and initialization phases to complete device registration and initialization, and then complete mutual authentication through the authentication and key agreement phases. Since data transmission between nodes is carried out over open and vulnerable communication channels, this brings challenges in data protection, authentication, and mutual authentication. Therefore, in order to ensure the security of data and the authenticity of participant identities in smart grid environments, it is urgently necessary to design a technical solution to achieve mutual authentication and session key establishment between nodes. Based on this, an application is filed.
[0061] Example 1: In the smart grid scenario, identity authentication and data protection are the main issues that need to be addressed in the smart grid node authentication and key exchange protocol process. Figure 1 As shown, in order to solve the above technical problems, this embodiment proposes a lightweight anonymous authentication method based on PUF function, including the following steps:
[0062] S1. Performing a hash operation on the physical characteristics of a sensor network node to generate a hidden identifier of the corresponding node; wherein the sensor network node includes a sensor node and a gateway node.
[0063] As an optional embodiment, performing a hash operation on the physical characteristics of a sensor network node to generate a hidden identifier of the corresponding node includes the following steps:
[0064] Get the physical unclonable function seed value based on the physical characteristics difference after the sensor SRAM is powered on , for the physical unclonable function seed value Perform BCH encoding to obtain consistency parameters And the corresponding auxiliary data ;
[0065] Seed value according to physical unclonable function , consistency parameters and auxiliary data Generate sensor physical fingerprint ;
[0066] By physically fingerprinting the sensor Perform hash operation to obtain the hidden identifier of the corresponding sensor node .
[0067] It is understandable that in this embodiment, the wireless sensor node deployed in the smart grid distribution network is taken as an example. The low-power MCU (such as STM32L433) equipped with it has a built-in 32KBSRAM. When powered on, the transistor threshold voltage deviation (±50mV) causes the storage unit flip time to show differences. The voltage rising edge of 1024 units is synchronously sampled through the on-chip ADC to quantize and generate a 1024-bit binary sequence as the seed value of the physical unclonable function. (such as 0b101100101...), using the non-replicability of the manufacturing process to build a hardware-level identity foundation. Then, the (1024,512,10) BCH encoding scheme is used to The first 512 bits of information generate 512 bits of check bits as consistency parameters , and record the code generation matrix as auxiliary data , can correct the bit errors caused by environmental noise (such as 3% flip bit error caused by temperature fluctuation) to ensure the consistent extraction of physical features. The last 512 bits of raw data are Splicing to form a 1024-bit sensor physical fingerprint with inherent characteristics and error correction capabilities , to resist the characteristic drift caused by device aging or external interference. Finally, the lightweight SHA-256 algorithm is used to Perform hash operation and extract the first 256 bits as hidden identifier (such as 0x5a3f9c2d...), providing anti-collision security while compressing the physical feature dimensions. The entire process is time-efficient and energy-efficient, achieving dynamic binding of device identity and hardware features while adapting to the computing resource limitations of sensor nodes with a lightweight design, providing an unforgeable, stable and reliable security environment for subsequent private channel establishment and two-way authentication.
[0068] As an optional embodiment, performing a hash operation on the physical characteristics of the sensor network node to generate a hidden identifier of the corresponding node further includes the following steps:
[0069] Get the physical unclonable function seed value based on the physical characteristics difference after the gateway SRAM is powered on , for the physical unclonable function seed value Perform BCH encoding to obtain consistency parameters And the corresponding auxiliary data ;
[0070] Seed value according to physical unclonable function , consistency parameters and auxiliary data Generate gateway physical fingerprint ;
[0071] By physical fingerprinting the gateway Perform hash operation to obtain the hidden identifier of the corresponding gateway node .
[0072] It is understandable that in this embodiment, the smart grid edge computing node is used as the gateway node (GN), which is equipped with a processor (such as an ARMCortex-A72 processor) and an external SRAM chip (such as a 2MBIS61LV25616 chip). The first flip time difference of 2048 storage cells during the row address scanning of the chip (with an accuracy of 50ps) is used to generate a 2048-bit binary sequence as the seed value of the physical unclonable function through the on-chip timer. (such as 0b110011010...), to ensure the strong uniqueness of physical features. Use (2048,1024,20) BCH encoding scheme to The first 1024 information bits are processed to generate 1024 check bits as consistency parameters , and record the segment coding offset (each 256 bits) as auxiliary data , can correct the bit errors caused by power ripple or electromagnetic interference, and ensure the characteristic stability in complex industrial environments. The last 1024 bits of raw data are Cross-stitching by bytes to form a 2048-bit gateway physical fingerprint , integrating original features with multi-level error correction mechanism, effectively resisting feature drift caused by chip aging. Perform the operation and intercept the last 256 bits as the hidden identifier The anti-collision property of the hash function is used to enhance the unforgeability of the identity. The entire processing flow is time-efficient and consumes little power. While meeting the high-performance requirements of the gateway node, it achieves efficient connection between the physical layer identity and the protocol layer authentication logic, providing a hardware-level trust anchor with both security and scalability for the dynamic interconnection of heterogeneous nodes in the smart grid.
[0073] S2. Build a private channel between the sensor node and the gateway node, and receive each other's public identifiers and hidden identifiers through the private channel to complete the initial parameter configuration of each sensor network node.
[0074] As an optional embodiment, the step of establishing a private channel between the sensor node and the gateway node includes the following steps:
[0075] Generate pseudo handshake information based on the computing resources and network resources required by the sensor node, the gateway node receives the pseudo handshake information through a public channel and determines the bandwidth and transmission rate of the channel to be divided based on the pseudo handshake information; generate a binary random number L1 based on the bandwidth and transmission rate, and use the binary random number L1 to encrypt the pseudo handshake information to obtain a pseudo encrypted block and send it to the sensor node;
[0076] The pseudo-encryption block is XORed with the pseudo-handshake information to obtain a binary random number L1, and the public channel is encrypted with the binary random number L1 to obtain a private channel.
[0077] It is understandable that in this embodiment, in the distributed monitoring scenario of the smart grid, the sensor node (SN) generates a pseudo handshake message containing the device capability vector based on its own resource constraints (such as computing frequency 16MHz, available RAM 8KB, bandwidth upper limit 250kbps). ,in is the CPU frequency (16MHz is quantized to 0x10), The remaining memory (such as 4KB is represented by 0x1000), The instantaneous bandwidth (e.g. 128kbps is represented by 0x2000). The gateway node (GN) receives the pseudo handshake message. Then, the matching channel parameters are calculated using a pre-trained resource allocation model (a linear regression model trained based on historical data. The construction and training process are beyond the purview of those skilled in the art and will not be elaborated on here). The bandwidth to be allocated is determined to be 100kbps (0x1900), the transmission rate is 50kbps (0x0C80), and a 128-bit binary random number L1 (such as `0b1011001...`) is generated. GN uses L1 to Perform XOR encryption to generate pseudo-encrypted blocks (e.g. `0x3a5f...`) is sent to the sensor node SN via a public channel (e.g. ZigBee frequency band). The sensor node SN receives the pseudo encrypted block. Then, use the pseudo handshake information stored locally Performs a reverse XOR operation , quickly recovering the random number L1. Both parties then use L1 as the session key to encrypt subsequent communication data using AES-128 CTR mode, establishing a private transport layer channel. Key generation requires only two XOR operations, which consumes minimal power and is time-efficient, effectively defending against traffic analysis attacks (because the pseudo-handshake information does not contain sensitive content). Furthermore, because L1 only survives a single session (TTL = 30 seconds), even if the key is compromised, historical communication content cannot be traced. This enables the construction of lightweight secure channels in resource-constrained environments, providing dynamic encryption for real-time data transmission in smart grids.
[0078] As an optional embodiment, after registration and initialization are completed, the initial parameters of the sensor node are ; The initial parameters of the gateway node are ;in, is the public identifier of the sensor node; is the public identifier of the gateway node; is the synchronization sequence number of the sensor / gateway node; is the hidden identifier of the sensor node; is the hidden identifier of the gateway node; is the consistency parameter of the sensor node; is the consistency parameter of the gateway node; Auxiliary data for sensor nodes; Auxiliary data for the gateway node.
[0079] S3. Perform hash operation on the geographical characteristics and initial parameters of the sensor node to generate handshake information.
[0080] As an optional embodiment, performing a hash operation on the geographical characteristics and initial parameters of the sensor node to generate handshake information includes the following steps:
[0081] Sensor nodes generate random location information , for the initial parameters 、 and Perform hash operation to get fuzzy position ,remember ; For the initial parameters 、 Combined with random position information Perform hash operation to get the position verification value V, record ; Based on the initial parameters , fuzzy location , position verification value V generates handshake information .
[0082] It is understandable that in this embodiment, in the smart grid transmission line monitoring scenario, the sensor node (SN) generates 128-bit random position information Pos (such as `0x3f5a2d1e...`, which can be a binary code corresponding to the longitude and latitude 30.12°N, 120.34°E) in real time based on the Beidou positioning module, combined with the sensor hidden identifier in the initial parameters (256 bits, such as `0x5a3f9c2d...`), gateway node hidden identifier (256 bits, such as `0xe7b41a5f...`) and synchronization sequence number (32 bits, such as 0x00010203), the three splicing values are concatenated using the SHA-256 algorithm ( , total length 544 bits) is hashed, the first 128 bits are taken and XORed with Pos to obtain the fuzzy position MPos (such as `0x2b6d...`), thus dynamically binding the real position with the node identity. The concatenated value (total length 416 bits) is hashed to generate a 256-bit location verification value V (such as `0x9c2d...`) to ensure the consistency of the location information and the node status. Finally, the gateway node public identifier (such as the hexadecimal encoding of the MAC address `00:1A:2B:3C:4D:5E`), MPos, V encapsulation as handshake information , transmitted through a private channel (using AES-128 encryption). During this process, Pos randomly updates each authentication (entropy value 128 bits), MPos hides the real coordinates through XOR confusion, and V uses hash chains to ensure integrity. Even if an attacker intercepts the handshake information, due to the lack of and It is impossible to reverse-analyze Pos or forge a legitimate V value. While resisting location spoofing attacks (such as GPS forgery), it meets the node mobility and real-time requirements in transmission line monitoring, achieving a lightweight and secure integration of geographic characteristics and identity authentication.
[0083] S4. The gateway node generates feedback information in response to the handshake information according to the first authentication policy.
[0084] As an optional embodiment, the gateway node generates feedback information in response to the handshake information according to the first authentication policy, which includes the following steps:
[0085] Handshake information After being sent to the gateway node through a private channel, if If the comparison fails, the authentication is terminated;
[0086] like If the comparison is successful, the initial parameters are extracted. 、 and the serial number of the gateway node Perform hash operation to get the original location ,remember ; According to the initial parameters , the serial number of the gateway node , original position Perform hash operation to obtain the location verification value ,remember ;
[0087] like , then re-initiate authentication and change the initial parameters 、 and the serial number of the gateway node pass Encryption algorithms are packaged into encrypted information blocks ,remember ; The gateway node will and As feedback information, it is sent to sensor nodes through private channels;
[0088] like , the gateway node generates a random number , according to the initial parameters 、 , random numbers Perform hash operation to obtain identity derivation factor ,remember ; Based on the original position , identity-derived factors Perform hash operation to obtain the initial session key ,remember ; Change the initial parameters 、 , original position The result of the hash operation and the random number Perform XOR operation to get the encrypted random number M, record ;Original position , initial session key pass Encryption algorithms are packaged into encrypted information blocks ,remember , set the session key ; The gateway node will , and It is used as feedback information and sent to the sensor nodes through private channels.
[0089] In this embodiment, the random number R and the serial number The dynamic update mechanism (incremented after each authentication) ensures the uniqueness of the session key. Combined with the hash chain and XOR obfuscation technology, it is impossible for an attacker to reversely deduce the random number R or the initial session key through the intercepted encrypted random number M and the feedback information APS. , achieving perfect forward secrecy; the lightweight design of LEA and IEA algorithms is time-saving and power-efficient, and is adapted to the edge computing capabilities of GN. It can still maintain a high authentication success rate in the substation multi-node concurrent authentication scenario, effectively ensuring the transmission security and integrity of real-time monitoring data of the smart grid.
[0090] S5. The sensor node generates an authentication result in response to the feedback information according to the second authentication strategy, and the gateway node performs subsequent actions in response to the authentication result.
[0091] As an optional embodiment, the sensor node generates an authentication result in response to the feedback information according to the second authentication strategy, and the gateway node performs subsequent actions in response to the authentication result; the steps include:
[0092] According to the initial parameters , the serial number of the sensor node , random position Perform hash operation to obtain the location verification value ,remember ;
[0093] like , sensor node computing , if the public identifier of the decrypted sensor node ,set up , the authentication result is sent through a private channel and Feedback to the gateway node and re-initiate the authentication application; if , the sensor node transmits the authentication result through a private channel and Feedback to the gateway node and re-initiate the authentication application;
[0094] like , the sensor node calculates the original random number , original identity derived factors ; Original session key ; Original random position ;
[0095] like , the authentication fails and the authentication result is sent to the private channel. After feedback to the gateway node, re-initiate the authentication application; if , set the session key , and send the authentication result through a private channel After feedback to the gateway node, re-initiate the authentication application;
[0096] The gateway node receives the authentication result After that, set .
[0097] In this embodiment, SN improves its anti-replay attack capability through a three-level authentication mechanism (location authentication → key authentication → serial number synchronization authentication). The combination of IEA and LEA algorithms reduces the time consumption for key derivation, meeting the response requirements of distribution terminals (such as DTUs). The dynamic update of the serial number (incremented in each authentication cycle) combined with timestamp verification greatly reduces the success rate of replay attacks. The use of CCM mode (AEAD encryption, providing integrity protection) ensures the non-forgeability of ACK messages and maintains a very high authentication success rate even in interference environments, achieving high-intensity two-way authentication in resource-constrained environments and building a reliable and secure channel for real-time data transmission in smart grids.
[0098] Embodiment 2: A technical solution also provided in the embodiment of the present invention is: a lightweight anonymous authentication system, which is suitable for a lightweight anonymous authentication method based on PUF function, such as Figure 2 Shown, including:
[0099] Computing module 101: Generates a hidden identifier of a corresponding node based on the physical characteristics of the sensor network node in combination with a hash function; wherein the sensor network node includes a sensor node and a gateway node;
[0100] Channel construction module 102: constructs a private channel between the sensor node and the gateway node;
[0101] Parameter configuration module 103: completes initial parameter configuration of each sensor network node through public identifiers and hidden identifiers;
[0102] The first generating module 104 generates handshake information based on the geographical characteristics and initial parameters of the sensor node in combination with a hash function;
[0103] Second generating module 105: The gateway node generates feedback information in response to the handshake information according to the first authentication policy;
[0104] Execution module 106: The sensor node generates an authentication result in response to the feedback information according to the second authentication strategy, and the gateway node executes subsequent actions in response to the authentication result.
[0105] In this embodiment, the system realizes the three-dimensional security protection of "physical layer anti-attack - protocol layer anti-forgery - transport layer anti-eavesdropping" in the smart grid scenario through the synergy of hardware feature binding, lightweight algorithm integration and dynamic key management, while meeting the strict limitations of sensor node computing resources and communication bandwidth, providing efficient and reliable technical support for the secure interconnection of large-scale distributed smart devices.
[0106] Example 3: An optional embodiment provided in the embodiments of the present invention is: an electronic device comprising a memory and a processor, wherein a computer program is stored in the memory, and when the processor calls the computer program in the memory, the steps of a lightweight anonymous authentication method based on a PUF function are implemented.
[0107] Example 4: An optional embodiment provided in the embodiments of the present invention is: a storage medium, which stores computer-executable instructions. When the computer-executable instructions are loaded and executed by a processor, the steps of a lightweight anonymous authentication method based on PUF function are implemented.
[0108] Through the description of the above implementation methods, technical personnel in the relevant field can understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional modules as needed, that is, the internal structure of the specific device can be divided into different functional modules to complete all or part of the functions described above.
[0109] In the embodiments provided in this application, it should be understood that the disclosed structures and methods can be implemented in other ways. For example, the embodiments of the structure described above are merely illustrative. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another structure, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interface, structure or unit, which can be electrical, mechanical or other forms.
[0110] Units described as separate components may or may not be physically separate, and components shown as units may be one physical unit or multiple physical units, that is, they may be located in one place or distributed in multiple places. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0111] In addition, the functional units in the embodiments of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated units may be implemented in the form of hardware or software functional units.
[0112] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling a device (which can be a single-chip microcomputer, chip, etc.) or a processor (processor) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk, and other media that can store program code.
[0113] The specific implementation described above is a preferred implementation of the lightweight anonymous authentication method and system based on the PUF function of the present invention, and is not intended to limit the specific implementation scope of the present invention. The scope of the present invention includes but is not limited to this specific implementation. Any equivalent changes made in accordance with the shape and structure of the present invention are within the scope of protection of the present invention.
Claims
1. A lightweight anonymous authentication method based on PUF function, characterized by: The steps include: Performing a hash operation on the physical characteristics of a sensor network node to generate a hidden identifier of the corresponding node; wherein the sensor network node includes a sensor node and a gateway node; Build a private channel between the sensor node and the gateway node, receive each other's public identifiers and hidden identifiers through the private channel to complete the initial parameter configuration of each sensor network node; Performing a hash operation on the geographical characteristics and initial parameters of the sensor node to generate a handshake message; the gateway node generates feedback information in response to the handshake message according to the first authentication strategy; The sensor node generates an authentication result in response to the feedback information according to the second authentication strategy, and the gateway node performs subsequent actions in response to the authentication result; The process of establishing a private channel between the sensor node and the gateway node comprises the following steps: Generate pseudo handshake information based on the computing resources and network resources required by the sensor node, the gateway node receives the pseudo handshake information through a public channel and determines the bandwidth and transmission rate of the channel to be divided based on the pseudo handshake information; generate a binary random number L1 based on the bandwidth and transmission rate, and use the binary random number L1 to encrypt the pseudo handshake information to obtain a pseudo encrypted block and send it to the sensor node; The pseudo-encryption block is XORed with the pseudo-handshake information to obtain a binary random number L1, and the public channel is encrypted with the binary random number L1 to obtain a private channel.
2. The lightweight anonymous authentication method based on PUF function according to claim 1, characterized in that: The step of performing a hash operation on the physical characteristics of a sensor network node to generate a hidden identifier of the corresponding node includes the following steps: Get the physical unclonable function seed value based on the physical characteristics difference after the sensor SRAM is powered on , for the physical unclonable function seed value Perform BCH encoding to obtain consistency parameters And the corresponding auxiliary data ; Seed value according to physical unclonable function Consistency parameters and auxiliary data Generate sensor physical fingerprint ; By physically fingerprinting the sensor Perform hash operation to obtain the hidden identifier of the corresponding sensor node .
3. The lightweight anonymous authentication method based on PUF function according to claim 1, characterized in that: The step of performing a hash operation on the physical characteristics of the sensor network node to generate a hidden identifier of the corresponding node further includes the following steps: Get the physical unclonable function seed value based on the physical characteristics difference after the gateway SRAM is powered on , for the physical unclonable function seed value Perform BCH encoding to obtain consistency parameters And the corresponding auxiliary data ; Seed value according to physical unclonable function Consistency parameters and auxiliary data Generate gateway physical fingerprint ; By physical fingerprinting the gateway Perform hash operation to obtain the hidden identifier of the corresponding gateway node .
4. The lightweight anonymous authentication method based on PUF function according to claim 1, characterized in that: The initial parameters of the sensor node are The initial parameters of the gateway node are ; in, is the public identifier of the sensor node; is the public identifier of the gateway node; is the synchronization sequence number of the sensor / gateway node; is the hidden identifier of the sensor node; is the hidden identifier of the gateway node; is the consistency parameter of the sensor node; is the consistency parameter of the gateway node; Auxiliary data for sensor nodes; Auxiliary data for the gateway node.
5. The lightweight anonymous authentication method based on PUF function according to claim 4, characterized in that: The process of performing a hash operation on the geographical characteristics and initial parameters of the sensor node to generate handshake information comprises the following steps: Sensor nodes generate random location information , for the initial parameters 、 and Perform hash operation to get fuzzy position ,remember ; For the initial parameters 、 Combined with random position information Perform hash operation to get the position verification value V, record ; Based on the initial parameters , fuzzy location , position verification value V generates handshake information .
6. The lightweight anonymous authentication method based on PUF function according to claim 4, characterized in that: The gateway node generates feedback information in response to the handshake information according to the first authentication policy, including the following steps: Handshake information After being sent to the gateway node through a private channel, if If the comparison fails, the authentication is terminated; like If the comparison is successful, the initial parameters are extracted. 、 and the serial number of the gateway node Perform hash operation to get the original location ,remember ; According to the initial parameters , the serial number of the gateway node , original position Perform hash operation to obtain the location verification value ,remember ; like , then re-initiate authentication and change the initial parameters and the serial number of the gateway node pass The encryption algorithm is packaged into an encrypted information block APS, ; The gateway node will and As feedback information, it is sent to sensor nodes through private channels; like , the gateway node generates a random number , according to the initial parameters 、 , random numbers Perform hash operation to obtain identity derivation factor ,remember ; Based on the original position , identity-derived factors Perform hash operation to obtain the initial session key ,remember ; The initial parameters 、 , original position The result of the hash operation and the random number Perform XOR operation to get the encrypted random number M, record ;Original position , initial session key pass The encryption algorithm is packaged into an encrypted information block APS, , set the session key ; The gateway node will , and It is used as feedback information and sent to the sensor nodes through private channels.
7. The lightweight anonymous authentication method based on PUF function according to claim 4, characterized in that: The sensor node generates an authentication result in response to the feedback information according to the second authentication strategy, and the gateway node performs subsequent actions in response to the authentication result; the steps include: According to the initial parameters , the serial number of the sensor node , random position Perform hash operation to obtain the location verification value ,remember ; like , sensor node computing , if the public identifier of the decrypted sensor node ,set up , the authentication result is sent through a private channel and Feedback to the gateway node and re-initiate the authentication application; if , the sensor node transmits the authentication result through a private channel and Feedback to the gateway node and re-initiate the authentication application; like , the sensor node calculates the original random number , original identity derived factors ; Original session key ; Original random position ; like , the authentication fails and the authentication result is sent to the private channel. After feedback to the gateway node, re-initiate the authentication application; if , set the session key , and send the authentication result through a private channel After feedback to the gateway node, re-initiate the authentication application; The gateway node receives the authentication result After that, set .
8. A lightweight anonymous authentication system, applicable to the lightweight anonymous authentication method based on PUF function according to any one of claims 1 to 7, characterized in that: Computation module: Generates hidden identifiers of corresponding nodes based on the physical characteristics of sensor network nodes combined with hash functions; sensor network nodes include sensor nodes and gateway nodes; Channel construction module: builds private channels between sensor nodes and gateway nodes; Parameter configuration module: completes the initial parameter configuration of each sensor network node through public identifiers and hidden identifiers; The first generation module: generates handshake information based on the geographical characteristics and initial parameters of the sensor node combined with the hash function; Second generation module: The gateway node generates feedback information in response to the handshake information according to the first authentication policy; Execution module: The sensor node generates an authentication result in response to the feedback information according to the second authentication strategy, and the gateway node executes subsequent actions in response to the authentication result.
9. An electronic device, characterized in that: The method comprises a memory and a processor, wherein a computer program is stored in the memory, and when the processor calls the computer program in the memory, the steps of the lightweight anonymous authentication method based on the PUF function are implemented as described in any one of claims 1 to 7.
10. A storage medium, characterized in that: The storage medium stores computer-executable instructions, which, when loaded and executed by the processor, implement the steps of the lightweight anonymous authentication method based on the PUF function as claimed in any one of claims 1 to 7.
Citation Information
Patent Citations
Pseudo random sequence generation method for wireless sensor network nodes and application method thereof
CN103826218A
Physical layer modulation scrambling method based on pseudorandom sequence
CN111711587A