Distributed Internet of Things equipment authentication method based on lightweight message

By introducing an IoT device authentication method with lightweight messages and a distributed architecture and utilizing the PUF characteristics, the problem of low efficiency in large-scale terminal device authentication is solved, an efficient and reliable authentication process is achieved, and the fast and stable operation of the IoT system in large-scale scenarios is ensured.

CN120710679AActive Publication Date: 2025-09-26GUANGZHOU JIXIANG TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510720098.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-30
Publication Date
2025-09-26
Estimated Expiration
2045-05-30

AI Technical Summary

Technical Problem

The existing IoT device authentication mechanism is inefficient in large-scale terminal device scenarios, resulting in a time-consuming authentication process, affecting the response speed of the IoT system and increasing system load and resource consumption.

Method used

A distributed IoT device authentication method based on lightweight messages is adopted. The unique physical properties of the physically unclonable function (PUF) and the lightweight message transmission method are utilized to reduce the amount of data transmission and avoid complex asymmetric encryption operations. The authentication tasks are reasonably distributed through a distributed architecture.

Benefits of technology

It improves the efficiency of IoT device authentication, reduces system load and resource consumption, enhances the real-time and scalability of the IoT system, and ensures that large-scale terminal devices can access the network quickly and stably.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120710679A_ABST
    Figure CN120710679A_ABST
Patent Text Reader

Abstract

The invention relates to a distributed Internet of Things equipment authentication method based on a lightweight message, which is characterized in that a lightweight message mechanism is introduced, key information in an authentication process is packaged and transmitted in a simple and efficient manner, the data transmission quantity is greatly reduced, the communication overhead is reduced, the authentication message is transmitted more quickly in a network, and the authentication efficiency is improved. And the data transmission time in the authentication process is effectively shortened. Meanwhile, authentication is carried out by utilizing unique physical characteristics of the physical unclonable function, so that complex asymmetric encryption operation is avoided, the computing resource consumption of the terminal equipment and the authentication service equipment is reduced, and the authentication efficiency is improved. Under a large-scale Internet of Things equipment authentication scene, the authentication efficiency is greatly improved, the system load and the resource consumption are reduced, the real-time performance and the expandability of the Internet of Things system are enhanced, and the large-scale terminal equipment is ensured to be quickly and stably accessed to the network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of Internet of Things communication technology, and in particular to a distributed Internet of Things device authentication method based on lightweight messages. Background Art

[0002] In the IoT (Internet of Things) sector, device authentication is a critical step in ensuring network security and trusted data transmission. Existing IoT device authentication mechanisms generally use asymmetric encryption between end devices and authentication devices, with data transmitted using standard communication formats. While asymmetric encryption offers enhanced security, it also carries high computational complexity and results in relatively large amounts of communication data.

[0003] This traditional authentication method exhibits significant efficiency issues in large-scale terminal device applications. Each terminal device must perform complex asymmetric encryption and transmit a large amount of authentication data, resulting in a lengthy authentication process and difficulty completing large-scale authentication. This not only impacts the responsiveness of IoT systems but also increases system load and resource consumption, limiting the widespread application of IoT technology in large-scale scenarios. Therefore, a more efficient solution suitable for large-scale terminal device authentication is urgently needed. Summary of the Invention

[0004] Based on this, the purpose of this application is to provide a distributed IoT device authentication method based on lightweight messages to improve the efficiency of IoT device authentication and meet the needs of rapid authentication of large-scale IoT devices.

[0005] The distributed IoT device authentication method based on lightweight messages described in the embodiment of the present application includes the following steps:

[0006] The terminal device responds to the authentication request instruction by obtaining a device identifier, a PUF identifier, and a preset authentication request identifier; uses the authentication request identifier as a message type portion, and the device identifier and the PUF identifier as a message payload portion, and splices them into a first lightweight message, which is then sent to the authentication service device; wherein the terminal device has a built-in PUF hardware module; the device identifier and the PUF identifier uniquely identify the terminal device and the PUF hardware module, respectively;

[0007] The authentication service device parses the first lightweight message, and if the authentication request identifier is obtained, requests the security management center to obtain PUF fingerprint information based on the device identifier and the PUF identifier, wherein the PUF fingerprint information includes PUF challenge information and a first hash value, and the first hash value is obtained based on the first PUF response information; calculates first verification information corresponding to the first hash value; uses the preset challenge information identifier as the message type part and the PUF challenge information as the message payload part, splices them into a second lightweight message, and then sends it to the terminal device;

[0008] The terminal device parses the second lightweight message, and if the challenge information identifier is obtained, inputs the PUF challenge information into the PUF hardware module to obtain second PUF response information; calculates second verification information corresponding to the second PUF response information; and uses the preset response information identifier as the message type part and the second verification information as the message payload part to splice them into a third lightweight message and send it to the authentication service device;

[0009] The authentication service device parses the third lightweight message, and if the response information identifier is obtained, determines whether the second verification information matches the first verification information; if they match, determines that the terminal device authentication is successful, and sends the authentication pass result to the security management center, and the security management center sets the binding status in the binding record corresponding to the device identifier and the PUF identifier to the authentication success status; if they do not match, determines that the terminal device authentication has failed, and sends the authentication failure result to the security management center, and the security management center clears the binding record corresponding to the device identifier and the PUF identifier.

[0010] The embodiment of the present application introduces a lightweight message mechanism to encapsulate and transmit the key information in the authentication process in a concise and efficient manner, which greatly reduces the amount of data transmission, reduces the communication overhead, makes the transmission of authentication messages in the network faster, and effectively shortens the data transmission time in the authentication process. At the same time, the unique physical properties of the physical unclonable function (PUF) are used for authentication, which avoids complex asymmetric encryption operations, reduces the computing resource consumption of terminal devices and authentication service devices, and improves authentication efficiency. In addition, the design of the distributed architecture enables the authentication service device to more reasonably allocate authentication tasks, collaborate with the security management center to complete the authentication process, and further improve the authentication speed. In the scenario of large-scale IoT device authentication, the present application achieves a significant improvement in authentication efficiency, reduces system load and resource consumption, enhances the real-time and scalability of the IoT system, ensures that large-scale terminal devices can quickly and stably access the network, and provides a solid guarantee for the efficient operation of IoT technology in large-scale application scenarios such as smart cities and industrial IoT.

[0011] For better understanding and implementation, the present application is described in detail below with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] Figure 1 This is a flow chart of a distributed IoT device authentication method based on lightweight messages according to an embodiment of the present application;

[0013] Figure 2 This is a schematic diagram of the steps of performing communication verification on a message from a terminal device by an authentication service device in an embodiment of the present application;

[0014] Figure 3 Schematic diagram of the steps for the authentication service device to determine the local cache in an embodiment of the present application;

[0015] Figure 4 Schematic diagram of the steps for the authentication service device to determine the cache priority and cache validity period in an embodiment of the present application. DETAILED DESCRIPTION

[0016] To make the objectives, technical solutions, and advantages of this application more clear, the following will further describe the embodiments of this application in detail with reference to the accompanying drawings. In the following description, when referring to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements.

[0017] It should be understood that the embodiments described in the following examples do not represent all embodiments consistent with this application. Rather, they are merely examples of devices and methods consistent with certain aspects of this application, as detailed in the appended claims. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of this application without inventive effort are intended to fall within the scope of protection of this application.

[0018] The terms used in this application are for the purpose of describing specific embodiments only and are not intended to limit this application. The singular forms of "a", "the" and "the" used in this application are also intended to include plural forms, unless the context clearly indicates otherwise. In addition, in the description of this application, unless otherwise stated, "a plurality" refers to two or more. It should also be understood that the term "and / or" used herein refers to and includes any or all possible combinations of one or more associated listed items, for example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone; the character " / " generally indicates that the objects associated before and after are in an "or" relationship.

[0019] It should be understood that although the terms first, second, third, etc. may be used in this application to describe various information, this information should not be limited to these terms. Moreover, these terms are only used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence, nor can they be understood to indicate or imply relative importance. For those of ordinary skill in the art, the specific meanings of the above terms in this application can be understood according to the specific circumstances. Depending on the context, the words "if" / "if" used in this application can be interpreted as "at the time of" or "when" or "in response to determining".

[0020] In the IoT (Internet of Things) sector, device authentication is a critical step in ensuring network security and trusted data transmission. Existing IoT device authentication mechanisms generally use asymmetric encryption between end devices and authentication devices, with data transmitted using standard communication formats. While asymmetric encryption offers enhanced security, it also carries high computational complexity and results in relatively large amounts of communication data.

[0021] This traditional authentication method exhibits significant efficiency issues in large-scale terminal device applications. Each terminal device must perform complex asymmetric encryption and transmit a large amount of authentication data, resulting in a lengthy authentication process and difficulty completing large-scale authentication. This not only impacts the responsiveness of IoT systems but also increases system load and resource consumption, limiting the widespread application of IoT technology in large-scale scenarios. Therefore, a more efficient solution suitable for large-scale terminal device authentication is urgently needed.

[0022] To this end, the technical concept of this application is to utilize the characteristics of Physical Unclonable Function (PUF) and combine it with the transmission method of lightweight messages to implement a distributed IoT device authentication method. PUF has unique physical properties, and the response information generated by each PUF hardware module is unique and unclonable, which can be used for device identification and authentication. By encapsulating key information in the authentication process into lightweight messages for transmission, the data transmission volume is reduced and communication overhead is lowered.

[0023] Please refer to Figure 1 The distributed IoT device authentication method based on lightweight messages described in the embodiment of the present application includes the following steps:

[0024] S101: The terminal device responds to the authentication request instruction by obtaining a device identifier, a PUF identifier, and a preset authentication request identifier; concatenating the authentication request identifier as a message type portion, the device identifier and the PUF identifier as a message payload portion into a first lightweight message, and sending the message to the authentication service device; wherein the terminal device has a built-in PUF hardware module; the device identifier and the PUF identifier uniquely identify the terminal device and the PUF hardware module, respectively;

[0025] S102: The authentication service device parses the first lightweight message. If the authentication request identifier is obtained, the authentication service device requests the security management center to obtain PUF fingerprint information based on the device identifier and the PUF identifier. The PUF fingerprint information includes PUF challenge information and a first hash value, and the first hash value is obtained based on the first PUF response information; calculates first verification information corresponding to the first hash value; uses the preset challenge information identifier as the message type part and the PUF challenge information as the message payload part, splices them into a second lightweight message, and sends the second lightweight message to the terminal device;

[0026] S103: The terminal device parses the second lightweight message. If the challenge information identifier is obtained, the terminal device inputs the PUF challenge information into the PUF hardware module to obtain second PUF response information; calculates second verification information corresponding to the second PUF response information; and uses the preset response information identifier as the message type part and the second verification information as the message payload part to splice them into a third lightweight message and send it to the authentication service device;

[0027] S104: The authentication service device parses the third lightweight message, and if the response information identifier is obtained, determines whether the second verification information matches the first verification information; if they match, determines that the terminal device authentication is successful, and sends the authentication pass result to the security management center, and the security management center sets the binding status in the binding record corresponding to the device identifier and the PUF identifier to the authentication success status; if they do not match, determines that the terminal device authentication has failed, and sends the authentication failure result to the security management center, and the security management center clears the binding record corresponding to the device identifier and the PUF identifier.

[0028] The embodiment of the present application introduces a lightweight message mechanism to encapsulate and transmit the key information in the authentication process in a concise and efficient manner, which greatly reduces the amount of data transmission, reduces the communication overhead, makes the transmission of authentication messages in the network faster, and effectively shortens the data transmission time in the authentication process. At the same time, the unique physical properties of the physical unclonable function (PUF) are used for authentication, which avoids complex asymmetric encryption operations, reduces the computing resource consumption of terminal devices and authentication service devices, and improves authentication efficiency. In addition, the design of the distributed architecture enables the authentication service device to more reasonably allocate authentication tasks, collaborate with the security management center to complete the authentication process, and further improve the authentication speed. In the scenario of large-scale IoT device authentication, the present application achieves a significant improvement in authentication efficiency, reduces system load and resource consumption, enhances the real-time and scalability of the IoT system, ensures that large-scale terminal devices can quickly and stably access the network, and provides a solid guarantee for the efficient operation of IoT technology in large-scale application scenarios such as smart cities and industrial IoT.

[0029] For step S101, the terminal device responds to the authentication request instruction, obtains the device identifier, the PUF identifier and the preset authentication request identifier; uses the authentication request identifier as the message type part, the device identifier and the PUF identifier as the message payload part, splices them into a first lightweight message and sends it to the authentication service device; wherein, the terminal device is equipped with a PUF hardware module; the device identifier and the PUF identifier uniquely identify the terminal device and the PUF hardware module respectively.

[0030] The device ID is a set of specific information used to uniquely identify a terminal device. It can be a string of numbers, letters, or a combination of these, similar to a device's "ID number." In an IoT system, each terminal device has a unique device ID, allowing authentication services and other related components to accurately identify it.

[0031] The PUF identifier uniquely identifies the PUF hardware module installed in the terminal device. The PUF hardware module generates a response based on the physical characteristics of the device. Different PUF hardware modules have different physical characteristics, so the PUF identifier is required to distinguish them and ensure that the corresponding PUF hardware module can be correctly associated during the authentication process.

[0032] The PUF hardware module is a hardware component based on physically unclonable function technology. It exploits the inevitable physical differences in device manufacturing, such as differences in transistor threshold voltage and circuit resistance. When a specific challenge is input, it can generate a unique response. This response is unclonable, providing a reliable security foundation for device authentication. In this embodiment, the PUF hardware module registers the PUF challenge information and the corresponding response information (i.e., the first PUF response information) with the security management center during the production registration phase.

[0033] The authentication request identifier is a pre-set specific identifier used to indicate during message transmission that the purpose of the message is to initiate an authentication request.

[0034] A lightweight message is a message that encapsulates key authentication information in a concise and efficient manner. In this embodiment, lightweight messages use a custom format. Compared to traditional authentication methods that require message formats and transmit large amounts of data, this lightweight message significantly reduces data transmission and communication overhead. In this embodiment, the structure of a lightweight message includes at least a message type portion and a message payload portion.

[0035] In this step, after receiving the authentication request, the terminal device retrieves the device identifier, PUF identifier, and pre-set authentication request identifier from its own storage or configuration information. Then, according to the predetermined message format, it concatenates the authentication request identifier as the message type, and the device identifier and PUF identifier as the message payload, forming a first lightweight message. The message type identifies the purpose of the message, while the message payload carries the key information required for authentication. Once concatenated, the terminal device sends the first lightweight message to the authentication service device to initiate the authentication process.

[0036] In one embodiment, the step S101 in which the terminal device uses the authentication request identifier as the message type portion, the device identifier, and the PUF identifier as the message payload portion, splices the first lightweight message into a first lightweight message, and then sends the message to the authentication service device includes:

[0037] Step S1011: The terminal device obtains first message total length information based on the sum of the first message length information of the message payload, the second message length information of the message type portion, and the third message length information of the preset message length portion; the terminal device uses the authentication request identifier as the message type portion, the device identifier and the PUF identifier as the message payload portion, and the first message total length information as the message length portion to splice together to obtain the first lightweight message;

[0038] Among them, the message length part records the length information of the entire message. In this embodiment, the message length part is a fixed-length field in the lightweight message structure. Therefore, the fixed message length information of the message length part (i.e., the third message length information) can be determined in advance for subsequent calculation of the total message length.

[0039] The first message total length information is the sum of the first message length information of the message payload part, the second message length information of the message type part, and the third message length information of the preset message length part. This information is used to determine the length of the entire first lightweight message.

[0040] In this step, the terminal device first calculates the sum of the length of the message payload (device identifier and PUF identifier) ​​(first message length information), the length of the message type (authentication request identifier) ​​(second message length information), and the length of the preset message length (third message length information) to obtain the first message total length information. The terminal device then uses the authentication request identifier as the message type part, the device identifier and PUF identifier as the message payload part, and the first message total length information as the message length part, and splices these parts together to form the first lightweight message.

[0041] The step of parsing the first lightweight message by the authentication service device in step S102 includes:

[0042] In step S1021, if the authentication service device obtains the total length information of the first message after parsing, it determines the parsing termination bit of the first lightweight message according to the total length information of the first message; when the parsing termination bit is reached, it determines that the parsing of the first lightweight message is completed.

[0043] When parsing the first lightweight message, if the authentication service device successfully obtains the total length of the first message, it determines the parsing end bit of the first lightweight message based on the length information. When the parsing end bit is reached, the authentication service device determines that the parsing of the first lightweight message has been completed.

[0044] In summary, this embodiment accurately parses lightweight messages by introducing a message length component when the terminal device splices the first lightweight message to convey the total message length. This information is then used by the authentication service device to determine the parsing termination bit when parsing the message. This solution ensures the integrity and correctness of the message during transmission, avoiding authentication failures or other issues caused by message parsing errors. Furthermore, the lightweight message design reduces the message data size, improves message transmission efficiency, and reduces communication overhead, making the entire authentication process more efficient and reliable.

[0045] In one embodiment, in step S103, the terminal device uses a preset response information identifier as a message type portion and the second verification information as a message payload portion, splicing a third lightweight message and sending the message to the authentication service device includes:

[0046] In step S1031, the terminal device obtains the second message total length information based on the sum of the fourth message length information of the message payload part, the fifth message length information of the message type part, and the third message length information of the preset message length part; with the preset response information identifier as the message type part, the second verification information as the message payload part, and the second message total length information as the message length part, the message type part, the message length part, and the message payload part are spliced ​​to obtain the third lightweight message.

[0047] In this step, the terminal device first calculates the sum of the length of the message payload (the second verification information) (the fourth message length information), the length of the message type (the preset response information identifier) ​​(the fifth message length information), and the length of the preset message length (the third message length information) to obtain the total length of the second message. The terminal device then uses the preset response information identifier as the message type, the second verification information as the message payload, and the second message total length as the message length, and concatenates these parts to form a third lightweight message.

[0048] The step of parsing the third lightweight message by the authentication service device in step S104 includes:

[0049] In step S1041, if the authentication service device obtains the total length information of the second message after parsing, it determines the parsing termination bit of the third lightweight message according to the total length information of the second message; when the parsing termination bit is reached, it determines that the parsing of the third lightweight message is completed.

[0050] In this step, when parsing the third lightweight message, if the authentication service device successfully obtains the total length of the second message, it determines the parsing end bit of the third lightweight message based on this length information. When the parsing end bit is reached, the authentication service device determines that the parsing of the third lightweight message has been completed.

[0051] In summary, this embodiment achieves accurate parsing of lightweight messages by introducing a message length portion (information about the total length of the second message) when the terminal device splices the third lightweight message, and using this length information to determine the parsing termination bit when the authentication service device parses the message. This solution ensures the integrity and correctness of the message during transmission, avoiding authentication failures or other problems caused by message parsing errors. At the same time, due to the adoption of a lightweight message design, the amount of message data is reduced, the efficiency of message transmission is improved, and communication overhead is reduced, making the entire authentication process more efficient and reliable.

[0052] For step S102, the authentication service device parses the first lightweight message. If the authentication request identifier is obtained, the device requests the security management center to obtain PUF fingerprint information based on the device identifier and the PUF identifier. The PUF fingerprint information includes PUF challenge information and a first hash value, and the first hash value is obtained based on the first PUF response information; the first verification information corresponding to the first hash value is calculated; the preset challenge information identifier is used as the message type part and the PUF challenge information is used as the message payload part, and the two are spliced ​​into a second lightweight message and sent to the terminal device.

[0053] The PUF fingerprint information is a set of key information related to a specific PUF hardware module stored in the security management center, which includes the PUF challenge information and the first hash value.

[0054] The PUF challenge information is specific input data used to stimulate the PUF hardware module to generate response information. In this embodiment, the PUF challenge information and the corresponding first PUF response information are pre-registered in the security management center.

[0055] The first hash value is calculated using a hash algorithm based on the first PUF response information generated by the PUF hardware module during the production registration phase. The hash algorithm can map data of any length to a hash value of fixed length, is irreversible and collision-resistant, and is commonly used for data integrity verification and identity authentication. In one embodiment, the first hash value is a hash value obtained by calculating the combined value of the first PUF response information and the PUF challenge information using the SM3 cryptographic hash algorithm.

[0056] The first verification information is obtained by the authentication service device based on the first hash value in the PUF fingerprint information obtained from the security management center, further processed by a specific algorithm or rule. The first verification information is used to compare with the verification information subsequently generated by the terminal device to verify the identity of the terminal device.

[0057] The challenge information identifier is a pre-set specific identifier used to indicate during message transmission that the message carries PUF challenge information.

[0058] In this step, after receiving the first lightweight message, the authentication service device parses it. By checking the message type part, if it is determined that the authentication request identifier is obtained, then according to the device identifier and PUF identifier in the message payload part, a request is made to the security management center to obtain the corresponding PUF fingerprint information. After receiving the request, the security management center searches for and returns the corresponding PUF fingerprint information based on the device identifier and PUF identifier, which includes the PUF challenge information and the first hash value calculated based on the first PUF response information. After receiving the PUF fingerprint information, the authentication service device calculates the first verification information corresponding to the first hash value. Then, according to the predetermined message format, the challenge information identifier is used as the message type part and the PUF challenge information is used as the message payload part to splice into a second lightweight message, and the message is sent to the terminal device so that the terminal device can respond.

[0059] In one embodiment, before the step of step S102 in which the authentication service device uses a preset challenge information identifier as a message type portion and the PUF challenge information as a message payload portion, splicing the second lightweight message into a second lightweight message and sending the message to the terminal device, the method includes:

[0060] In step S1022, the authentication service device obtains the third message total length information based on the sum of the sixth message length information of the message payload part, the seventh message length information of the message type part, and the third message length information of the preset message length part; using the preset challenge information identifier as the message type part, the PUF challenge information as the message payload part, and the third message total length information as the message length part, the message type part, the message length part, and the message payload part are spliced ​​to obtain the second lightweight message.

[0061] In this step, the authentication service device first calculates the sum of the length of the message payload (PUF challenge information) (sixth message length information), the length of the message type (preset challenge information identifier) ​​(seventh message length information), and the length of the preset message length (third message length information) to obtain the third message total length information. The authentication service device then uses the preset challenge information identifier as the message type, the PUF challenge information as the message payload, and the third message total length information as the message length, and concatenates these parts to form a second lightweight message.

[0062] The step of parsing the second lightweight message by the terminal device in step S103 includes:

[0063] Step S1032: If the terminal device obtains the total length information of the third message after parsing, it determines the parsing termination bit of the second lightweight message according to the total length information of the third message; when the parsing termination bit is reached, it determines that the parsing of the second lightweight message is completed.

[0064] When the terminal device parses the second lightweight message, if it successfully parses the third message total length information, it will determine the parsing end bit of the second lightweight message based on the length information. When the end bit is parsed, the terminal device determines that the second lightweight message has been parsed.

[0065] This embodiment achieves accurate parsing of lightweight messages by introducing a message length portion (information about the total length of the third message) when the authentication service device splices the second lightweight message, and using this length information to determine the parsing termination bit when the terminal device parses the message. This solution ensures the integrity and correctness of the message during transmission, avoiding authentication failures or other issues caused by message parsing errors. Furthermore, the lightweight message design reduces the message data size, improves message transmission efficiency, and reduces communication overhead, making the entire authentication process more efficient and reliable.

[0066] Please refer to Figure 2 In one embodiment, the step S101 in which the terminal device uses the authentication request identifier as the message type portion, the device identifier, and the PUF identifier as the message payload portion, concatenates the first lightweight message, and then sends the message to the authentication service device includes:

[0067] In step S1012, the terminal device calculates the first communication verification information based on the message type part and the message payload part through a preset communication encryption algorithm; uses the first communication verification information as the message verification part; and splices the message type part, the message payload part, and the message verification part to obtain the first lightweight message.

[0068] The communication encryption algorithm is an algorithm used to encrypt data. It converts raw data into ciphertext through specific mathematical operations to ensure the security and integrity of the data during transmission and prevent data theft or tampering. In this embodiment, the terminal device and the authentication service device use the same communication encryption algorithm to calculate the communication verification information.

[0069] The message verification part is the part of the message used to verify whether the message has been tampered with during transmission. The receiver can use this information to check the integrity of the message.

[0070] In this step, the terminal device uses a preset communication encryption algorithm to calculate the first communication verification information based on the message type part (authentication request identifier) ​​and the message payload part (device identifier and PUF identifier), and uses this first communication verification information as the message verification part. The terminal device then concatenates the message type part, message payload part, and message verification part to form a first lightweight message and sends it to the authentication service device.

[0071] Before the step of step S102 in which the authentication service device requests the security management center to obtain PUF fingerprint information according to the device identifier and the PUF identifier, the method includes:

[0072] Step S10201: The authentication service device calculates second communication verification information based on the message type part and the message payload part using the communication encryption algorithm, and determines whether the second communication verification information matches the first communication verification information.

[0073] Step S10202: If a match is found, a request is made to the security management center to obtain PUF fingerprint information based on the device identifier and the PUF identifier.

[0074] If the second communication verification information matches the first communication verification information, it means that the first lightweight message has not been tampered with during transmission. The authentication service device requests the security management center to obtain the corresponding PUF fingerprint information based on the device identifier and PUF identifier in the message payload.

[0075] Step S10203: If there is no match, the authentication service device generates a verification error message; uses the preset error identifier as the message type part and the verification error information as the message payload part, and splices a fourth lightweight message to send to the terminal device; after parsing the error identifier and the verification error information, the terminal device regenerates the first lightweight message and sends it to the authentication service device.

[0076] The error identifier is an identifier used to identify the message type. In this embodiment, it is used to identify the verification error information generated by the authentication service device so that the terminal device can quickly identify that the message is about a verification error.

[0077] In this step, if the second communication verification information does not match the first communication verification information, it indicates that the first lightweight message may have been tampered with during transmission. The authentication service device generates a verification error message. The authentication service device then concatenates the message using a preset error identifier as the message type and the verification error information as the message payload to generate a fourth lightweight message and sends it to the terminal device. After parsing the error identifier and verification error information, the terminal device regenerates the first lightweight message and sends it to the authentication service device.

[0078] In summary, this embodiment verifies message integrity by introducing a message verification unit into the message and using a communication encryption algorithm to calculate communication verification information. By comparing the second communication verification information calculated by itself with the first communication verification information sent by the terminal device, the authentication service device can accurately determine whether the message has been tampered with during transmission. If the verification passes, the authentication service device continues with the subsequent authentication process. If the verification fails, the authentication service device generates a verification error message and notifies the terminal device, which then regenerates and sends the message. This solution effectively ensures the security and integrity of message transmission and avoids authentication errors or security risks caused by message tampering.

[0079] It should be noted that in the embodiments of the present application, lightweight messages are used for communication between the terminal device and the authentication service device, following the same message format, message splicing rules, and message parsing rules. A lightweight message includes at least a message type section and a message payload section, and other sections can be flexibly expanded as needed. For example, in the above embodiment, a message length section and a message check section are also expanded.

[0080] Please refer to Figure 3 In one embodiment, after the authentication service device parses the first lightweight message in step S102, the following steps are included:

[0081] In step S102a, if the authentication service device parses and obtains the authentication request identifier, it determines whether the device identifier and the PUF fingerprint information corresponding to the PUF identifier exist in the local cache; if so, it determines whether the cached PUF fingerprint information is within the validity period; if so, the authentication service device obtains the device identifier and the PUF fingerprint information corresponding to the PUF identifier from the local cache.

[0082] Among them, the local cache is a memory area or database in the authentication service device used to temporarily store PUF fingerprint information, aiming to reduce the number of interactions with the security management center and improve authentication efficiency.

[0083] The validity period is a time range set for the PUF fingerprint information. After the time range is exceeded, the PUF fingerprint information is considered invalid and needs to be obtained again.

[0084] In this step, after parsing the first lightweight message and obtaining the authentication request identifier, the authentication service device checks its local cache for PUF fingerprint information corresponding to the device identifier and PUF identifier in the request. If so, it further determines whether the PUF fingerprint information is within its validity period. If so, the authentication service device retrieves the PUF fingerprint information directly from its local cache, avoiding communication overhead with the security management center and improving authentication efficiency. This step aims to optimize the authentication process by utilizing the caching mechanism and reducing unnecessary network interactions.

[0085] Step S102b: If the PUF fingerprint information corresponding to the device identifier and the PUF identifier does not exist, or exists but is not within the validity period, the authentication service device generates a PUF fingerprint information acquisition request based on the device identifier and the PUF identifier, and sends the PUF fingerprint information acquisition request to the security management center.

[0086] If the PUF fingerprint information corresponding to the device ID and PUF ID in the request does not exist in the local cache, or if it exists but has expired, the authentication service device generates a PUF fingerprint information acquisition request based on the device ID and PUF ID and sends the request to the security management center. The purpose of this step is to obtain the latest PUF fingerprint information through interaction with the security management center in the event of a cache miss or expired information, thereby ensuring the accuracy and security of authentication.

[0087] In summary, this embodiment improves the efficiency of the authentication process by introducing a local caching mechanism in the authentication service device to cache and manage PUF fingerprint information. When valid and corresponding PUF fingerprint information exists in the local cache, the authentication service device can obtain it directly from the local cache, avoiding frequent interactions with the security management center and reducing network communication overhead and response time. At the same time, setting an expiration date for the cached PUF fingerprint information ensures the accuracy and security of the fingerprint information used, avoiding authentication errors or security risks caused by the use of expired information. When there is no valid information in the local cache, the authentication service device can promptly request new PUF fingerprint information from the security management center, ensuring the smooth progress of the authentication process.

[0088] Please refer to Figure 4 In one embodiment, before the step S102a in which the authentication service device determines whether the cached PUF fingerprint information is within the validity period, the following steps are further included:

[0089] Step S102a1: The authentication service device counts the access frequency of the terminal device and determines a frequency range corresponding to the access frequency; the frequency range includes a high frequency range, a medium frequency range, and a low frequency range;

[0090] Among them, access frequency refers to the number of times a terminal device initiates authentication requests to the authentication service device within a unit of time, which is used to measure the activity level of the terminal device.

[0091] Frequency ranges are divided into different intervals based on access frequency, including high frequency range, medium frequency range, and low frequency range, and are used to distinguish the access activity of terminal devices.

[0092] In this step, the authentication service device counts the number of accesses by the terminal device over a period of time, thereby calculating the access frequency of the terminal device. It then determines the frequency range to which the access frequency belongs, based on a preset classification standard, i.e., whether it is in the high frequency range, the medium frequency range, or the low frequency range.

[0093] Step S102a2: determining the cache priority and cache validity period of the PUF fingerprint information corresponding to the terminal device according to the frequency range; wherein the priorities corresponding to the high frequency range, the medium frequency range, and the low frequency range are from high to low, and the corresponding cache validity periods are from long to short.

[0094] The cache priority is a parameter used to determine the storage order and retention time of the PUF fingerprint information in the local cache. The higher the priority, the longer the cache retention time or the higher the priority of the storage location.

[0095] The cache validity period refers to the maximum length of time that the PUF fingerprint information can be used in the local cache. After this time, the cached information is considered invalid.

[0096] In this step, the authentication service device assigns a corresponding cache priority and cache validity period to the PUF fingerprint information corresponding to the terminal device based on the frequency range determined in step S102a1. Specifically, the PUF fingerprint information corresponding to the terminal device in the high-frequency range has the highest cache priority and the longest cache validity period; the PUF fingerprint information corresponding to the terminal device in the medium-frequency range has the next highest cache priority and a correspondingly shorter cache validity period; and the PUF fingerprint information corresponding to the terminal device in the low-frequency range has the lowest cache priority and the shortest cache validity period.

[0097] Step S102a3: Encrypt and cache the PUF fingerprint information corresponding to the terminal device locally according to the cache priority, and determine the validity period of the PUF fingerprint information as the cache validity period.

[0098] Among them, encrypted caching refers to encrypting the PUF fingerprint information before caching it locally to prevent information leakage or tampering.

[0099] In this step, the authentication service device encrypts the PUF fingerprint information corresponding to the terminal device and caches it in local storage according to the cache priority determined in step S102a2. At the same time, the cache validity period determined in step S102a2 is used as the validity period of the PUF fingerprint information. That is, within this validity period, the PUF fingerprint information is considered valid and can be used for authentication.

[0100] In summary, this embodiment achieves reasonable allocation and management of local cache resources by counting the access frequency of terminal devices and dividing the frequency range, and determining the cache priority and cache validity period of the PUF fingerprint information corresponding to the terminal devices according to the frequency range. For terminal devices with high access frequency, a higher cache priority and a longer cache validity period are given, so that these devices can quickly obtain PUF fingerprint information from the local cache during the subsequent authentication process, thereby improving authentication efficiency, reducing the number of interactions with the security management center, and reducing network communication overhead. For terminal devices with low access frequency, a lower cache priority and a shorter cache validity period are given, which avoids the local cache being occupied by long-term inactive device information and improves the utilization rate of cache space. At the same time, the use of encrypted cache ensures the security of PUF fingerprint information in the local cache and prevents information leakage. This solution comprehensively considers multiple factors such as authentication efficiency, cache resource utilization, and data security, and realizes an efficient and secure authentication process.

[0101] In one embodiment, after the authentication service device encrypts and caches the PUF fingerprint information corresponding to the terminal device locally according to the cache priority in step S102a3, the method includes:

[0102] In step S102a4, the authentication service device monitors the network status between the authentication service device and the security management center. If the network status is abnormal, the validity period of the cached PUF fingerprint information is extended according to the duration of the abnormal network status; if the network status is normal, the validity period of the cached PUF fingerprint information is not extended.

[0103] The network status describes the network connection between the authentication service device and the security management center, including indicators such as network connectivity, stability, and bandwidth. In this embodiment, the focus is on whether the network is connected normally and whether there are any anomalies, such as network interruptions, excessive latency, and severe packet loss.

[0104] The duration of network status anomaly refers to the length of time from the detection of network anomaly to the end of the anomaly (restoration to normal).

[0105] During this step, the authentication service device continuously monitors the network status between itself and the security management center. If a network anomaly is detected, the authentication service device records the duration of the anomaly and extends the validity period of the cached PUF fingerprint information accordingly. This ensures that if a network anomaly prevents timely access to new PUF fingerprint information from the security management center, authentication can still be performed using the locally cached, extended PUF fingerprint information, ensuring continuity of the authentication process. Conversely, if the network status is normal, the authentication service device does not extend the validity period of the cached PUF fingerprint information, but instead manages it according to pre-set rules.

[0106] In summary, this embodiment enhances the adaptability and reliability of the authentication system in unstable network environments by monitoring the network status between the authentication service device and the security management center and dynamically adjusting the validity period of cached PUF fingerprint information based on the duration of the network anomaly. In the event of a network anomaly, extending the validity period of the PUF fingerprint information prevents authentication interruptions caused by the inability to obtain new information in a timely manner, ensuring that the authentication process can continue and improving the system's fault tolerance. In normal network conditions, maintaining the existing cache validity period management policy ensures the optimal use of cache resources. This solution ensures the stable operation of the authentication system despite network fluctuations, ensuring the efficiency and security of the authentication service.

[0107] For step S103, the terminal device parses the second lightweight message. If the challenge information identifier is obtained, the PUF challenge information is input into the PUF hardware module to obtain second PUF response information; the second verification information corresponding to the second PUF response information is calculated; and the preset response information identifier is used as the message type part and the second verification information is used as the message payload part. The three messages are spliced ​​into a third lightweight message and sent to the authentication service device.

[0108] The second PUF response information is response information generated by the PUF hardware module according to its unique physical characteristics after the terminal device inputs the received PUF challenge information into the PUF hardware module.

[0109] The second verification information is information used for authentication verification and is calculated based on the second PUF response information. The calculation method of the second verification information corresponds to the calculation method of the first verification information to ensure accurate matching verification in the subsequent authentication process.

[0110] The response information identifier is a pre-set specific identifier used to indicate during message transmission that the message carries the response information of the terminal device to the PUF challenge information.

[0111] In this step, after receiving the second lightweight message, the terminal device parses it. By checking the message type portion and determining that a challenge information identifier is obtained, the PUF challenge information in the message payload portion is input into the built-in PUF hardware module. The PUF hardware module generates a second PUF response message based on the challenge information. The terminal device calculates the second verification information corresponding to the second PUF response information. Then, according to a predetermined message format, the response information identifier is used as the message type portion and the second verification information is used as the message payload portion to form a third lightweight message. This message is then sent to the authentication service device so that the authentication service device can determine the authentication result.

[0112] In one embodiment, after the authentication service device parses the lightweight message sent by the terminal device, the authentication service device includes:

[0113] If any preset request identifier is not obtained through parsing, the lightweight message of the terminal device is not responded to; the preset request identifier includes an authentication request identifier and a response information identifier;

[0114] After the terminal device parses the lightweight message sent by the authentication service device, the method includes:

[0115] If any preset authentication identifier is not obtained through parsing, the lightweight message of the authentication service device is not responded to; the preset authentication identifier includes a challenge information identifier and an error identifier.

[0116] Based on any embodiment of the present application, it can be known that when the authentication service device or terminal device parses the received lightweight message, it will focus on parsing the message type part. By judging whether the message type part contains a valid preset identifier, such as an authentication request identifier, a response information identifier, a challenge information identifier, and an error identifier, the stage of authentication is determined, and then the corresponding processing operation is performed. If the authentication service device or terminal device parses the message type part in the lightweight message, the parsing result is empty or other data that is not a preset identifier, that is, no valid identifier is obtained through parsing, then no response is made. The purpose of this design is to ensure that both parties only perform subsequent operations when they receive messages that comply with the authentication process specifications through accurate identification of preset identifiers, effectively avoiding the processing of invalid messages, reducing system resource consumption, improving authentication efficiency, and enhancing the security of the system.

[0117] In summary of the above embodiments, in the technical solution of the present application, lightweight messages are the core component. The lightweight message adopts a layered design, which at least includes a message type part and a message payload, and can further expand the message verification part, etc., and the message structure is clear and concise. Among them, the message type part is a key field used to identify the specific type and function of the message, and is the basis for message parsing and response. Through the preset identifier in the message type part, the authentication service device and the terminal device can quickly and accurately identify the message type, thereby determining the stage of authentication and performing corresponding processing operations. This efficient identification mechanism greatly improves the authentication efficiency and reduces unnecessary communication overhead. Furthermore, the lightweight message can also be combined with a variety of security mechanisms according to the situation, such as message integrity protection, timestamp mechanism, etc., to ensure the security and integrity of the message during transmission.

[0118] This application reduces the complexity and overhead of the authentication process by optimizing the message format and interaction process. The design of lightweight messages fully considers the characteristics and needs of the Internet of Things environment, enabling this solution to run efficiently on resource-constrained devices. Specifically, compared with asymmetric encryption communication, this application avoids the complex process of public key distribution, storage and verification, does not require additional information such as signatures to be attached to the message, and does not require processing multiple rounds of handshake protocol overhead, thereby reducing the complexity of the message structure. Compared with symmetric encryption communication, this application utilizes PUF characteristics for identity authentication, without the need for explicit transmission and management of keys, thus avoiding the additional overhead brought by key distribution. At the same time, the layered message format and optimized interaction process designed by this application, while ensuring the integrity of the message and the validity of the authentication, reduce the redundant information in the message and improve the efficiency of message processing.

[0119] In one embodiment, the first hash value is a hash value obtained by calculating a combined value of the first PUF response information and the PUF challenge information using an SM3 cryptographic hash algorithm;

[0120] In step S102, the authentication service device uses a preset challenge information identifier as a message type part and the PUF challenge information as a message payload part, splicing them into a second lightweight message and sending it to the terminal device, further comprising:

[0121] The authentication service device obtains a random number, uses a preset challenge information identifier as a message type portion, and the random number and the PUF challenge information as a message payload portion, splices them into a second lightweight message, and then sends it to the terminal device;

[0122] The step of calculating the first verification information corresponding to the first hash value by the authentication service device in step S102 includes:

[0123] The authentication service device intercepts the first N bits of the first hash value to obtain a first response hash value; uses the SM3 cryptographic hash algorithm to calculate a first hash value of the exclusive OR value of the first response hash value and the random number, and intercepts the first N bits of the first hash value to obtain first verification information; wherein N is a positive integer;

[0124] The step of calculating the second verification information corresponding to the second PUF response information by the terminal device in step S103 includes:

[0125] The terminal device uses the SM3 cryptographic hash algorithm to calculate a second hash value of the combination value of the PUF response information and the PUF challenge information, and intercepts the first N bits of the second hash value to obtain a second response hash value; uses the SM3 cryptographic hash algorithm to calculate a second hash value of the XOR value of the second response hash value and the random number, and intercepts the first N bits of the second hash value to obtain second verification information.

[0126] Among them, the SM3 cryptographic hash algorithm is a cryptographic hash algorithm standard issued by the China National Cryptography Administration. It is used to convert input data of arbitrary length into a hash value of fixed length. It has security features such as anti-collision and anti-second preimage.

[0127] A random number is a random or pseudo-random data generated by an authentication service device to enhance the security of the authentication process.

[0128] The XOR value refers to the result of a bitwise XOR operation on two binary data.

[0129] This embodiment implements secure verification and dynamic authentication of PUF response information by introducing the SM3 cryptographic hash algorithm, random numbers, and XOR operations. The authentication service device and the terminal device generate verification information through the same processing flow, namely SM3 hash calculation, random number XOR, and interception of the first N bits, ensuring the uniqueness and consistency of the verification information. The application of the SM3 algorithm ensures the security and collision resistance of the hash value. The introduction of random numbers enhances the dynamic nature and anti-replay attack capability of the authentication process. The XOR operation further obfuscates the data, increasing the difficulty of cracking. The overall technical solution forms a secure and reliable PUF authentication mechanism through the synergy of cryptographic algorithms and dynamic factors, providing a solid guarantee for the identity authentication of terminal devices.

[0130] For step S104, the authentication service device parses the third lightweight message, and if the response information identifier is obtained, determines whether the second verification information matches the first verification information; if they match, determines that the terminal device authentication is successful, and sends the authentication pass result to the security management center, and the security management center sets the binding status in the binding record corresponding to the device identifier and the PUF identifier to the authentication success status; if they do not match, determines that the terminal device authentication has failed, and sends the authentication failure result to the security management center, and the security management center clears the binding record corresponding to the device identifier and the PUF identifier.

[0131] The Security Management Center maintains a record of the binding between device IDs and PUF identifiers. This record records the correspondence between each terminal device's device ID and the PUF identifier of its internal PUF hardware module, as well as information such as authentication status. This binding record enables the Security Management Center to centrally manage and monitor IoT devices.

[0132] The binding status in the binding record indicates the current authentication status of the device identifier and the PUF identifier, typically including "authentication successful," "unauthenticated," or "authentication failed." If authentication succeeds, the binding status is set to "authentication successful," indicating that the terminal device and its PUF hardware module have been authenticated and are legitimate and trustworthy. If authentication fails, the Security Management Center clears the binding record, effectively removing the binding relationship between the device identifier and the PUF identifier from the system. This indicates that the device failed authentication and may pose a security risk.

[0133] In this step, after receiving the third lightweight message, the authentication service device parses it. By checking the message type portion, if it determines that a response information identifier is obtained, the second verification information in the message payload portion is obtained and matched with the first verification information previously calculated. If the second verification information matches the first verification information, it indicates that the response information generated by the terminal device's PUF hardware module meets expectations, and the authentication service device determines that the terminal device has passed authentication. Subsequently, the authentication service device sends the authentication result to the security management center. After receiving the authentication result, the security management center sets the binding status in the binding record corresponding to the device identifier and the PUF identifier to the authentication success status, allowing the terminal device to access and communicate normally in the IoT system. If the second verification information does not match the first verification information, it indicates that the terminal device's authentication has failed. The authentication service device determines that the terminal device has failed authentication and sends the authentication failure result to the security management center. After receiving the authentication failure result, the security management center clears the binding record corresponding to the device identifier and the PUF identifier to prevent the terminal device from accessing the system in an illegal state.

[0134] The above embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art may make various modifications and improvements without departing from the spirit of the present application, and the present application is intended to encompass such modifications and variations.

Claims

1. A distributed IoT device authentication method based on lightweight messages, characterized in that: The following steps are involved: The terminal device responds to the authentication request instruction by obtaining a device identifier, a PUF identifier, and a preset authentication request identifier; uses the authentication request identifier as a message type portion, and the device identifier and the PUF identifier as a message payload portion, and splices them into a first lightweight message, which is then sent to the authentication service device; wherein the terminal device has a built-in PUF hardware module; the device identifier and the PUF identifier uniquely identify the terminal device and the PUF hardware module, respectively; The authentication service device parses the first lightweight message, and if the authentication request identifier is obtained, requests the security management center to obtain PUF fingerprint information based on the device identifier and the PUF identifier, wherein the PUF fingerprint information includes PUF challenge information and a first hash value, and the first hash value is obtained based on the first PUF response information; calculates first verification information corresponding to the first hash value; uses the preset challenge information identifier as the message type part and the PUF challenge information as the message payload part, splices them into a second lightweight message, and then sends it to the terminal device; The terminal device parses the second lightweight message, and if the challenge information identifier is obtained, inputs the PUF challenge information into the PUF hardware module to obtain second PUF response information; calculates second verification information corresponding to the second PUF response information; and uses the preset response information identifier as the message type part and the second verification information as the message payload part to splice them into a third lightweight message and send it to the authentication service device; The authentication service device parses the third lightweight message, and if the response information identifier is obtained, determines whether the second verification information matches the first verification information; if they match, determines that the terminal device authentication is successful, and sends the authentication pass result to the security management center, and the security management center sets the binding status in the binding record corresponding to the device identifier and the PUF identifier to the authentication success status; if they do not match, determines that the terminal device authentication has failed, and sends the authentication failure result to the security management center, and the security management center clears the binding record corresponding to the device identifier and the PUF identifier.

2. The distributed IoT device authentication method based on lightweight messages according to claim 1 is characterized in that: The step of the terminal device using the authentication request identifier as a message type portion, the device identifier, and the PUF identifier as a message payload portion, splicing a first lightweight message into the message, and then sending the message to the authentication service device includes: The terminal device obtains the first message total length information according to the sum of the first message length information of the message payload part, the second message length information of the message type part, and the third message length information of the preset message length part; the authentication request identifier is used as the message type part, the device identifier and the PUF identifier are used as the message payload part, and the first message total length information is used as the message length part, and the first lightweight message is obtained by splicing. The step of splicing, by the terminal device, a preset response information identifier as a message type portion and the second verification information as a message payload portion into a third lightweight message and then sending the message to the authentication service device includes: The terminal device obtains the second message total length information based on the sum of the fourth message length information of the message payload part, the fifth message length information of the message type part and the third message length information of the preset message length part; using the preset response information identifier as the message type part, the second verification information as the message payload part, and the second message total length information as the message length part, the message type part, the message length part and the message payload part are spliced ​​to obtain the third lightweight message.

3. The distributed IoT device authentication method based on lightweight messages according to claim 2 is characterized in that: The step of parsing the first lightweight message by the authentication service device includes: If the authentication service device obtains the total length information of the first message through parsing, the authentication service device determines a parsing termination bit of the first lightweight message according to the total length information of the first message; and determines that parsing of the first lightweight message is complete when the parsing termination bit is reached. The step of parsing the third lightweight message by the authentication service device includes: If the authentication service device parses and obtains the total length information of the second message, it determines the parsing termination bit of the third lightweight message based on the total length information of the second message; when the parsing termination bit is reached, it determines that the parsing of the third lightweight message is completed.

4. The distributed IoT device authentication method based on lightweight messages according to claim 1 is characterized in that: Before the step of splicing the authentication service device into a second lightweight message using a preset challenge information identifier as a message type portion and the PUF challenge information as a message payload portion and then sending the message to the terminal device, the step includes: The authentication service device obtains third message total length information based on the sum of the sixth message length information of the message payload part, the seventh message length information of the message type part, and the third message length information of the preset message length part; using the preset challenge information identifier as the message type part, the PUF challenge information as the message payload part, and the third message total length information as the message length part, the message type part, the message length part, and the message payload part are concatenated to obtain the second lightweight message; The step of, by the terminal device, parsing the second lightweight message, includes: If the terminal device parses and obtains the total length information of the third message, it determines the parsing end bit of the second lightweight message based on the total length information of the third message; when the parsing end bit is parsed, it is determined that the parsing of the second lightweight message is completed.

5. The distributed IoT device authentication method based on lightweight messages according to claim 1 is characterized in that: The step of the terminal device using the authentication request identifier as a message type portion, the device identifier, and the PUF identifier as a message payload portion, splicing a first lightweight message into the message, and then sending the message to the authentication service device includes: The terminal device calculates first communication verification information based on the message type part and the message payload part using a preset communication encryption algorithm; uses the first communication verification information as the message verification part; and concatenates the message type part, the message payload part, and the message verification part to obtain the first lightweight message; Before the step of requesting the authentication service device to obtain the PUF fingerprint information from the security management center according to the device identifier and the PUF identifier, the method includes: The authentication service device calculates second communication verification information based on the message type part and the message payload part using the communication encryption algorithm, and determines whether the second communication verification information matches the first communication verification information; If a match occurs, the PUF fingerprint information is requested from the security management center based on the device identifier and the PUF identifier. If there is no match, the authentication service device generates a verification error message; uses the preset error identifier as the message type part and the verification error information as the message payload part, splices together a fourth lightweight message and sends it to the terminal device; after parsing the error identifier and the verification error information, the terminal device regenerates the first lightweight message and sends it to the authentication service device.

6. The distributed IoT device authentication method based on lightweight messages according to claim 1 is characterized in that: After the step of parsing the first lightweight message by the authentication service device, the method includes: If the authentication service device parses and obtains the authentication request identifier, it determines whether the device identifier and the PUF fingerprint information corresponding to the PUF identifier exist in the local cache; if so, it determines whether the cached PUF fingerprint information is within the validity period; if so, the authentication service device obtains the device identifier and the PUF fingerprint information corresponding to the PUF identifier from the local cache; If the PUF fingerprint information corresponding to the device identifier and the PUF identifier does not exist, or exists but is not within the validity period, the authentication service device generates a PUF fingerprint information acquisition request based on the device identifier and the PUF identifier, and sends the PUF fingerprint information acquisition request to the security management center.

7. The distributed IoT device authentication method based on lightweight messages according to claim 6 is characterized in that: Before the step of determining whether the cached PUF fingerprint information is within the validity period, the authentication service device further includes the following steps: The authentication service device counts the access frequency of the terminal device and determines a frequency range corresponding to the access frequency; the frequency range includes a high frequency range, a medium frequency range and a low frequency range; Determine the cache priority and cache validity period of the PUF fingerprint information corresponding to the terminal device according to the frequency range; wherein the priorities corresponding to the high frequency range, the medium frequency range, and the low frequency range are from high to low, and the corresponding cache validity periods are from long to short; The PUF fingerprint information corresponding to the terminal device is encrypted and cached locally according to the cache priority, and the validity period of the PUF fingerprint information is determined to be the cache validity period.

8. The distributed IoT device authentication method based on lightweight messages according to claim 6 is characterized in that: After the step of encrypting and caching the PUF fingerprint information corresponding to the terminal device locally according to the cache priority, the method further includes: The authentication service device monitors the network status between the authentication service device and the security management center. If the network status is abnormal, the validity period of the cached PUF fingerprint information is extended according to the duration of the abnormal network status; if the network status is normal, the validity period of the cached PUF fingerprint information is not extended.

9. The distributed IoT device authentication method based on lightweight messages according to claim 1 is characterized in that: The first hash value is a hash value obtained by calculating a combined value of the first PUF response information and the PUF challenge information using an SM3 cryptographic hash algorithm; The authentication service device uses a preset challenge information identifier as a message type part and the PUF challenge information as a message payload part, splicing them into a second lightweight message and sending the message to the terminal device, further comprising: The authentication service device obtains a random number, uses a preset challenge information identifier as a message type portion, and the random number and the PUF challenge information as a message payload portion, splices them into a second lightweight message, and then sends it to the terminal device; The step of calculating, by the authentication service device, first verification information corresponding to the first Hash value includes: The authentication service device intercepts the first N bits of the first hash value to obtain a first response hash value; uses the SM3 cryptographic hash algorithm to calculate a first hash value of the exclusive OR value of the first response hash value and the random number, and intercepts the first N bits of the first hash value to obtain first verification information; wherein N is a positive integer; The step of calculating, by the terminal device, second verification information corresponding to the second PUF response information includes: The terminal device uses the SM3 cryptographic hash algorithm to calculate a second hash value of the combination value of the PUF response information and the PUF challenge information, and intercepts the first N bits of the second hash value to obtain a second response hash value; uses the SM3 cryptographic hash algorithm to calculate a second hash value of the XOR value of the second response hash value and the random number, and intercepts the first N bits of the second hash value to obtain second verification information.

10. The distributed IoT device authentication method based on lightweight messages according to claim 1, characterized in that: After the authentication service device parses the lightweight message sent by the terminal device, the method includes: If any preset request identifier is not obtained through parsing, the lightweight message of the terminal device is not responded to; the preset request identifier includes an authentication request identifier and a response information identifier; After the terminal device parses the lightweight message sent by the authentication service device, the method includes: If any preset authentication identifier is not obtained through parsing, the lightweight message of the authentication service device is not responded to; the preset authentication identifier includes a challenge information identifier and an error identifier.

Citation Information

Patent Citations

  • Metropolitan Internet of Things system, security authentication method and device thereof, and storage medium

    CN116669032A

  • Lightweight identity authentication method based on PUF

    CN117614626A

  • Lightweight unmanned aerial vehicle identity authentication method based on PUF

    CN120017281A

  • Device authentication apparatus and method using Physical Unclonable Function

    KR1020140059485A

  • Password management with addressable physical unclonable function generators

    US20190354672A1