PUF-based distributed IoT device authentication method
By introducing PUF hardware modules and distributed authentication methods into IoT devices, the problems of imperfect IoT device authentication processes and insufficient security are solved, achieving efficient and secure device authentication and meeting the needs of large-scale deployment and real-time authentication.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- GUANGZHOU JIXIANG TECH CO LTD
- Filing Date
- 2025-05-30
- Publication Date
- 2026-07-17
AI Technical Summary
Existing IoT device authentication methods suffer from imperfect authentication processes and insufficient security, making it difficult to meet the needs of large-scale deployment and real-time authentication. In particular, when facing complex network environments and attack methods, the complexity of key management and certificate storage in traditional cryptographic authentication methods is difficult to solve.
A distributed IoT device authentication method based on PUF is adopted. By setting up a PUF hardware module in the terminal device, the unique and non-clonable response characteristics of PUF are used to generate an authentication request by combining the device identifier and PUF identifier. The authentication request is then verified by the interaction between the authentication service device and the security management center to realize the identity authentication of the terminal device. This avoids the complex problems of key management and certificate storage, and enhances security and efficiency.
It improves the security and efficiency of IoT device authentication, reduces the computational and storage burden, provides traceability and manageability, and meets the special needs of IoT application scenarios.
Smart Images

Figure CN120729527B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of Internet of Things (IoT) communication technology, and in particular to a distributed IoT device authentication method based on PUF. Background Technology
[0002] As a crucial component of the next generation of information technology, the Internet of Things (IoT) is profoundly changing people's lives and production methods. Security authentication of IoT devices is a key link in ensuring the stable operation of IoT systems, secure data transmission, and the protection of user privacy. However, the widespread distribution, massive number, and resource constraints of IoT devices present significant challenges to their security authentication.
[0003] Traditional IoT device authentication methods primarily rely on cryptography, such as pre-shared keys and digital certificates. Pre-shared keys require sharing keys between the device and the authentication authority before deployment; however, key management and distribution are complex, and key leakage severely compromises the security of the entire system. While digital certificates offer high security, their generation, storage, and verification processes consume significant computing and storage resources. This undoubtedly increases the burden on resource-constrained IoT devices, leading to low authentication efficiency and failing to meet the demands of large-scale IoT deployments and real-time authentication.
[0004] In recent years, Physically Unclonable Functions (PUFs), as an emerging hardware security technology, have provided a new approach to IoT device authentication due to their unique physical characteristics and unclonability. PUFs can generate unique responses based on the physical characteristics of a device, providing a reliable hardware foundation for device authentication. However, existing PUF-based IoT device authentication methods still have many shortcomings. For example, the authentication process is not perfect, lacking strict control over each step, making it vulnerable to various attacks; security is insufficient, and it is difficult to effectively guarantee the security of device authentication when facing complex network environments and attack methods. Therefore, developing a more secure and efficient distributed IoT device authentication method is urgently needed. Summary of the Invention
[0005] Therefore, the purpose of this application is to provide a PUF-based distributed IoT device authentication method to improve the security and efficiency of IoT device authentication.
[0006] The distributed IoT device authentication method based on PUF described in this application includes the following steps:
[0007] The terminal device obtains a device identifier and a PUF identifier, generates an authentication request based on the device identifier and the PUF identifier, and sends the authentication request to the authentication service device; wherein, the terminal device is equipped with a PUF hardware module; the device identifier is used to uniquely identify the terminal device, and the PUF identifier is used to uniquely identify the PUF hardware module;
[0008] The authentication service device obtains PUF fingerprint information sent from the security management center according to the authentication request; the PUF fingerprint information includes PUF challenge information and a first hash value, the first hash value being obtained based on the first PUF response information; first verification information is obtained based on the first hash value; and the PUF challenge information is sent to the terminal device.
[0009] The terminal device inputs the PUF challenge information into the PUF hardware module to obtain PUF response information; it then obtains second verification information based on the PUF response information and sends the second verification information to the authentication service device.
[0010] The authentication service device receives the second verification information and determines whether the second verification information matches the first verification information. If they match, the terminal device is determined to be authenticated successfully, and an authentication success result is sent to the security management center. The security management center sets the binding status in the binding record corresponding to the device identifier and the PUF identifier to the authentication success status. If they do not match, the terminal device is determined to be authenticated unsuccessfully, and an authentication failure result is sent to the security management center. The security management center clears the binding record corresponding to the device identifier and the PUF identifier.
[0011] In this embodiment, a PUF hardware module is installed within the terminal device. Utilizing the unique and unclonable response characteristics generated by the PUF hardware module based on physical properties, a robust security foundation is provided for device authentication. During the authentication process, the terminal device generates an authentication request using both the device identifier and the PUF identifier. This innovative approach ensures the uniqueness of the device identity while enhancing authentication security through the uniqueness of the PUF. The authentication service device obtains PUF fingerprint information from the security management center, including PUF challenge information and a first hash value obtained based on the first PUF response information, and then interacts with the terminal device for verification. The terminal device inputs the challenge information into the PUF hardware module, receives a response, and generates second verification information, which is returned to the authentication service device. The authentication result is determined by comparing the first and second verification information. This PUF hardware module-based authentication mechanism effectively avoids the complexities of key management and certificate storage in traditional cryptographic authentication methods, as well as the resulting security risks. It also reduces the computational and storage burden on the device caused by complex authentication processes. Furthermore, the security management center's management of the binding records between the device identifier and the PUF identifier ensures the traceability and manageability of the authentication results, facilitating unified control of IoT devices. Overall, this solution ensures the security of IoT device authentication while taking into account device resource limitations, improving authentication efficiency, and meeting the specific needs of device authentication in IoT application scenarios.
[0012] To better understand and implement this application, the following detailed description is provided in conjunction with the accompanying drawings. Attached Figure Description
[0013] Figure 1 This is a flowchart illustrating the PUF-based distributed IoT device authentication method according to an embodiment of this application.
[0014] Figure 2 This is a schematic diagram illustrating the steps of the PUF registry verification request in an embodiment of this application;
[0015] Figure 3 This is a schematic diagram illustrating the steps of verifying the device binding relationship table in an embodiment of this application;
[0016] Figure 4 This is a schematic diagram illustrating the steps of the authentication service device in determining the local cache in an embodiment of this application. Detailed Implementation
[0017] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings. Wherein, when the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements.
[0018] It should be understood that the embodiments described below do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without inventive effort are within the scope of protection of this application.
[0019] The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The singular forms “a,” “the,” and “the” used in this application are also intended to include the plural forms unless the context clearly indicates otherwise. Furthermore, in the description of this application, unless otherwise stated, “a plurality” means two or more. It should also be understood that the term “and / or” as used herein refers to and includes any or all possible combinations of one or more associated listed items, for example, A and / or B, which can represent: A alone, A and B together, and B alone; the character “ / ” generally indicates that the preceding and following objects are in an “or” relationship.
[0020] It should be understood that although the terms first, second, third, etc., may be used in this application to describe various information, this information should not be limited to these terms, and these terms are only used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence, nor should they be construed as indicating or implying relative importance. Those skilled in the art can understand the specific meaning of the above terms in this application according to the specific circumstances. Depending on the context, the word "if" as used in this application can be interpreted as "when," "when," or "in response to determination."
[0021] As a crucial component of the next generation of information technology, the Internet of Things (IoT) is profoundly changing people's lives and production methods. Security authentication of IoT devices is a key link in ensuring the stable operation of IoT systems, secure data transmission, and the protection of user privacy. However, the widespread distribution, massive number, and resource constraints of IoT devices present significant challenges to their security authentication.
[0022] Traditional IoT device authentication methods primarily rely on cryptography, such as pre-shared keys and digital certificates. Pre-shared keys require sharing keys between the device and the authentication authority before deployment; however, key management and distribution are complex, and key leakage severely compromises the security of the entire system. While digital certificates offer high security, their generation, storage, and verification processes consume significant computing and storage resources. This undoubtedly increases the burden on resource-constrained IoT devices, leading to low authentication efficiency and failing to meet the demands of large-scale IoT deployments and real-time authentication.
[0023] In recent years, Physically Unclonable Functions (PUFs), as an emerging hardware security technology, have provided a new approach to IoT device authentication due to their unique physical characteristics and unclonability. PUFs can generate unique responses based on the physical characteristics of a device, providing a reliable hardware foundation for device authentication. However, existing PUF-based IoT device authentication methods still have many shortcomings. For example, the authentication process is not perfect, lacking strict control over each step, making it vulnerable to various attacks; security is insufficient, and it is difficult to effectively guarantee the security of device authentication when facing complex network environments and attack methods. Therefore, developing a more secure and efficient distributed IoT device authentication method is urgently needed.
[0024] In response, this application proposes a distributed IoT device authentication method based on PUF to improve the security and efficiency of IoT device authentication.
[0025] Please refer to Figure 1 The distributed IoT device authentication method based on PUF described in this application includes the following steps:
[0026] S101: The terminal device obtains a device identifier and a PUF identifier, generates an authentication request based on the device identifier and the PUF identifier, and sends the authentication request to the authentication service device; wherein, the terminal device is equipped with a PUF hardware module; the device identifier is used to uniquely identify the terminal device, and the PUF identifier is used to uniquely identify the PUF hardware module;
[0027] S102: The authentication service device obtains PUF fingerprint information sent from the security management center according to the authentication request; the PUF fingerprint information includes PUF challenge information and a first hash value, the first hash value is obtained according to the first PUF response information; the first verification information is obtained according to the first hash value; and the PUF challenge information is sent to the terminal device.
[0028] S103: The terminal device inputs the PUF challenge information into the PUF hardware module to obtain PUF response information; it obtains second verification information based on the PUF response information and sends the second verification information to the authentication service device;
[0029] S104: The authentication service device receives the second verification information and determines whether the second verification information matches the first verification information; if they match, it determines that the terminal device has passed authentication and sends the authentication success result to the security management center, and the security management center sets the binding status in the binding record corresponding to the device identifier and the PUF identifier to the authentication success status; if they do not match, it determines that the terminal device has failed authentication and sends the authentication failure result to the security management center, and the security management center clears the binding record corresponding to the device identifier and the PUF identifier.
[0030] In this embodiment, a PUF hardware module is installed within the terminal device. Utilizing the unique and unclonable response characteristics generated by the PUF hardware module based on physical properties, a robust security foundation is provided for device authentication. During the authentication process, the terminal device generates an authentication request using both the device identifier and the PUF identifier. This innovative approach ensures the uniqueness of the device identity while enhancing authentication security through the uniqueness of the PUF. The authentication service device obtains PUF fingerprint information from the security management center, including PUF challenge information and a first hash value obtained based on the first PUF response information, and then interacts with the terminal device for verification. The terminal device inputs the challenge information into the PUF hardware module, receives a response, and generates second verification information, which is returned to the authentication service device. The authentication result is determined by comparing the first and second verification information. This PUF hardware module-based authentication mechanism effectively avoids the complexities of key management and certificate storage in traditional cryptographic authentication methods, as well as the resulting security risks. It also reduces the computational and storage burden on the device caused by complex authentication processes. Furthermore, the security management center's management of the binding records between the device identifier and the PUF identifier ensures the traceability and manageability of the authentication results, facilitating unified control of IoT devices. Overall, this solution ensures the security of IoT device authentication while taking into account device resource limitations, improving authentication efficiency, and meeting the specific needs of device authentication in IoT application scenarios.
[0031] In step S101, the terminal device obtains a device identifier and a PUF identifier, generates an authentication request based on the device identifier and the PUF identifier, and sends the authentication request to the authentication service device; wherein, the terminal device is equipped with a PUF hardware module; the device identifier is used to uniquely identify the terminal device, and the PUF identifier is used to uniquely identify the PUF hardware module.
[0032] Device identifiers are a set of specific information used to uniquely identify terminal devices. They can be a string of numbers, letters, or a combination thereof, similar to a device's "ID number." In an Internet of Things (IoT) system, each terminal device has a unique device identifier so that authentication service devices and other relevant components can accurately identify the device.
[0033] A PUF identifier is used to uniquely identify the PUF hardware module installed within a terminal device. The PUF hardware module generates responses based on the device's physical characteristics. Different PUF hardware modules have different physical characteristics, therefore a PUF identifier is needed to distinguish them and ensure that the corresponding PUF hardware module can be correctly associated during the authentication process.
[0034] The PUF hardware module is a hardware component based on physically unclonable function technology. It leverages unavoidable physical differences in device manufacturing processes, such as differences in transistor threshold voltages and circuit resistance, to generate a unique response when specific challenge information is input. This response information is unclonable, providing a reliable security foundation for device authentication. In this embodiment, the PUF hardware module registers the PUF challenge information and the corresponding generated response information (i.e., the first PUF response information) to the security management center during the production registration phase.
[0035] In this step, when authentication is required, the terminal device first obtains the device identifier and PUF identifier from its own storage or related configuration. Then, the terminal device combines these two identifiers according to a specific format and rules to generate an authentication request. After generating the authentication request, the terminal device sends the authentication request to the authentication service device via network communication or other means, so that the authentication service device can proceed with the subsequent authentication process based on the request.
[0036] For step S102, the authentication service device obtains PUF fingerprint information sent from the security management center according to the authentication request; the PUF fingerprint information includes PUF challenge information and a first hash value, the first hash value is obtained according to the first PUF response information; the first verification information is obtained according to the first hash value; and the PUF challenge information is sent to the terminal device.
[0037] Among them, PUF fingerprint information is a collection of key information related to a specific PUF hardware module stored in the security management center. It includes PUF challenge information and the first hash value.
[0038] PUF challenge information is the input data used to trigger the PUF hardware module to generate a response.
[0039] The first hash value is calculated using a hash algorithm based on the first PUF response information generated during the production registration phase of the PUF hardware module. A hash algorithm can map data of arbitrary length to a fixed-length hash value, possessing irreversibility and collision resistance, and is commonly used for data integrity verification and identity authentication. In one embodiment, the first hash value is obtained by calculating the combined value of the first PUF response information and the PUF challenge information using the SM3 cryptographic hash algorithm.
[0040] The first verification information is obtained by the authentication service device through further processing of the first hash value in the PUF fingerprint information obtained from the security management center using a specific algorithm or rule. This first verification information is used to compare with the verification information subsequently generated by the terminal device to verify the terminal device's identity.
[0041] In this step, after receiving the authentication request from the terminal device, the authentication service device requests the corresponding PUF fingerprint information from the security management center based on the relevant information in the request. The security management center sends the PUF fingerprint information, including PUF challenge information and a first hash value, to the authentication service device. Upon receiving the PUF fingerprint information, the authentication service device uses the first hash value to generate first verification information according to a pre-set algorithm or rule. Then, the authentication service device sends the PUF challenge information to the terminal device, providing the necessary input for the terminal device to generate response information.
[0042] In one embodiment, step S102, where the authentication service device obtains the PUF fingerprint information sent from the security management center according to the authentication request, includes:
[0043] Step S1021: The authentication service device generates a PUF fingerprint information acquisition request based on the device identifier and the PUF identifier, and sends the PUF fingerprint information acquisition request to the security management center.
[0044] The authentication service device generates a structured PUF fingerprint information retrieval request based on the device identifier and PUF identifier submitted by the terminal device. This request contains these two identifiers to ensure that the security management center can accurately match the terminal device with the corresponding PUF fingerprint information. Subsequently, the authentication service device sends this request to the security management center through a secure channel (such as TLS encrypted communication).
[0045] In step S1022, the security management center parses the PUF fingerprint information acquisition request to obtain the device identifier and the PUF identifier; obtains the corresponding PUF fingerprint information according to the PUF identifier, and sends the PUF fingerprint information to the authentication service device.
[0046] Upon receiving a PUF fingerprint information retrieval request, the security management center parses the request content to obtain the device identifier and the PUF identifier. Then, the security management center searches the target database for the corresponding PUF fingerprint information based on the PUF identifier and sends this information to the authentication service device. In one embodiment, the security management center includes an information management module and an authentication processing module. The authentication processing module parses the PUF fingerprint information retrieval request to obtain the device identifier and the PUF identifier; it retrieves the PUF fingerprint information corresponding to the PUF identifier from the information management module; and the authentication processing module sends the PUF fingerprint information to the authentication service device. In this embodiment, the information management module is responsible for storing and managing the PUF fingerprint information, while the authentication processing module is responsible for receiving and processing requests from the authentication service device, including performing relevant verifications and providing feedback on the request results, such as the PUF fingerprint information, to the authentication service device. In one embodiment, the security management center sends the PUF fingerprint information and the device identifier to the authentication service device. Thus, when a large number of terminal devices are used for identity authentication, the device identifier sent along with the PUF fingerprint information enables the authentication service device to determine the target terminal device to be verified corresponding to the PUF fingerprint information, and then initiate subsequent authentication steps to the target terminal device based on the PUF fingerprint information.
[0047] This embodiment achieves secure and accurate acquisition of PUF fingerprint information through a clearly defined interaction process between the authentication service device and the security management center. This not only improves the security of the authentication system and prevents unauthorized access or impersonation, but also enhances the system's reliability and stability, ensuring the smooth operation of the authentication process.
[0048] Please refer to Figure 2 In one embodiment, step S1022, where the security management center obtains the corresponding PUF fingerprint information based on the PUF identifier and sends the PUF fingerprint information to the authentication service device, includes:
[0049] Step S10221: The security management center verifies the validity of the PUF identifier based on a preset PUF registry; the PUF registry records the PUF identifiers of registered PUF hardware modules.
[0050] The PUF registry is a database table maintained by the security management center. It records the PUF identifiers and associated information of all registered PUF hardware modules, and is used to verify the legitimacy of the PUF identifiers. The associated information may include the device to which it belongs, the registration time, etc.
[0051] In this step, after receiving the PUF fingerprint information acquisition request, the security management center parses the PUF identifier and checks if the identifier exists in the PUF registry. If it exists, it is considered valid; if it does not exist, for example, if it is not registered or the identifier has been tampered with, it is considered invalid. The purpose of this step is to prevent unauthorized devices or forged PUF identifiers from accessing system resources.
[0052] In step S10222, if the verification is invalid, the security management center generates an error message and sends it to the authentication service device; the authentication service device responds to the error message and determines that the terminal device authentication has failed.
[0053] The error message can be a standardized message containing the reason for the failure, and the standardized message can be in JSON format. In this embodiment, the error message can include an error code, such as INVALID_PUF_ID, and can also include descriptive text, such as "PUF identifier not registered".
[0054] If the PUF identifier verification fails in this step, the security management center generates an error message and returns it to the authentication service device. After parsing the error message, the authentication service device terminates the current authentication process and finally returns an authentication failure response to the terminal device.
[0055] Step S10223: If the verification is valid, the security management center obtains the corresponding PUF fingerprint information based on the PUF identifier and sends the PUF fingerprint information to the authentication service device.
[0056] If the PUF identifier verification is valid, the security management center retrieves the PUF fingerprint information associated with that identifier and sends it to the authentication service device via an encrypted channel. This step ensures the confidentiality and integrity of the PUF fingerprint information during transmission.
[0057] In summary, the security management center in this embodiment maintains the PUF registry and verifies the validity of PUF identifiers in real time, effectively blocking access from unauthorized devices or forged identifiers and preventing potential attacks. After verification, the security management center accurately retrieves and encrypts the PUF fingerprint information from secure storage, ensuring the confidentiality of the PUF fingerprint information and avoiding the risk of tampering during transmission. This significantly enhances the system's ability to resist security threats such as identity forgery and data leakage, providing reliable protection for secure access of terminal devices.
[0058] Please refer to Figure 3 In one embodiment, step S1022, where the security management center obtains the corresponding PUF fingerprint information based on the PUF identifier and sends the PUF fingerprint information to the authentication service device, further includes:
[0059] Step S10224: The security management center determines whether there is a binding record related to the device identifier or the PUF identifier in the preset device binding relationship table;
[0060] The device binding relationship table is a database table maintained by the security management center. It records the binding relationship between device identifiers and PUF identifiers, as well as the authentication status of each authentication, such as authenticating, authentication successful, authentication failed, etc.
[0061] The security management center queries the device binding relationship table to check for any binding records related to the device identifier or PUF identifier in the request. The purpose of this step is to confirm whether the binding relationship between the device and the PUF has been established, and whether the current authentication request is a duplicate or abnormal request.
[0062] Step S10225: If no relevant binding record exists, the security management center obtains the corresponding PUF fingerprint information based on the PUF identifier, sends the PUF fingerprint information to the authentication service device, adds a binding record between the device identifier and the PUF identifier to the device binding relationship table, and sets the authentication status in the binding record to the authenticating status.
[0063] If no binding record related to the device identifier or PUF identifier in the request exists in the device binding relationship table, the security management center considers this a new authentication request. In this case, the security management center obtains the corresponding PUF fingerprint information based on the PUF identifier, sends the PUF fingerprint information to the authentication service device, adds a new binding record to the device binding relationship table, binds the device identifier to the PUF identifier, and sets the authentication status of this binding record to "authentication in progress." The purpose of this step is to establish the binding relationship between the device and the PUF and to record the current authentication process status.
[0064] Step S10226: If a relevant binding record exists, the security management center determines whether the device identifier and the PUF identifier match the binding record; if they match, the security management center obtains the corresponding PUF fingerprint information based on the PUF identifier; and sets the authentication status in the binding record corresponding to the device identifier and the PUF identifier to an authentication in progress state; if they do not match, the security management center generates an error message and sends it to the authentication service device; the authentication service device responds to the error message and determines that the terminal device authentication has failed.
[0065] If a binding record related to the device identifier or PUF identifier in the request exists in the device binding relationship table, the security management center further determines whether the device identifier and PUF identifier match the information in any related binding record. If they match, the security management center considers this a legitimate authentication request, obtains the corresponding PUF fingerprint information based on the PUF identifier, and updates the authentication status in the corresponding binding record to "authentication in progress." If they do not match, the security management center generates an error message and sends it to the authentication service device, notifying it of authentication failure. Upon receiving the error message, the authentication service device terminates the current authentication process.
[0066] This embodiment achieves security and reliability in the terminal device authentication process through a dual verification mechanism using both device identifier and PUF identifier, combined with the management of a device binding relationship table. The security management center dynamically manages the binding relationships between devices and PUFs by maintaining the device binding relationship table, effectively preventing unauthorized device access and the processing of duplicate authentication requests. Simultaneously, by setting authentication status, the progress of the authentication process can be tracked in real time, providing strong support for subsequent authentication result processing.
[0067] It should be noted that, in one embodiment, the PUF fingerprint information acquisition request can be verified together with the PUF registry and the device binding relationship table. Specifically, firstly, the PUF identifier is verified based on the PUF registry. If the PUF identifier is verified as valid, the binding record between the device identifier and the PUF identifier is further verified based on the device binding relationship table. That is, after the security management center verifies the validity of the PUF identifier based on the preset PUF registry in step S10223, it further executes steps S10224 to S10226 to determine whether the final verification is successful.
[0068] Please refer to Figure 4 In one embodiment, step S1021, where the authentication service device generates a PUF fingerprint information acquisition request based on the device identifier and the PUF identifier, and sends the PUF fingerprint information acquisition request to the security management center, includes:
[0069] Step S10211: The authentication service device determines whether the device identifier and the PUF fingerprint information corresponding to the PUF identifier exist in the local cache; if they exist, it determines whether the cached PUF fingerprint information is within the validity period; if it is within the validity period, the authentication service device obtains the device identifier and the PUF fingerprint information corresponding to the PUF identifier from the local cache.
[0070] Local cache is a memory area or database in the authentication service device used to temporarily store PUF fingerprint information, aiming to reduce the number of interactions with the security management center and improve authentication efficiency.
[0071] The validity period is a time range set for PUF fingerprint information. After the time range is exceeded, the PUF fingerprint information is considered invalid and needs to be obtained again.
[0072] Upon receiving an authentication request from a terminal device, the authentication service device first checks its local cache to see if it already stores the PUF fingerprint information corresponding to the device identifier and PUF identifier in the request. If it exists, it further determines whether the PUF fingerprint information is valid. If it is valid, the authentication service device directly retrieves the PUF fingerprint information from its local cache, avoiding communication overhead with the security management center and improving authentication efficiency. The purpose of this step is to optimize the authentication process using a caching mechanism and reduce unnecessary network interactions.
[0073] Step S10212: If the device identifier and the PUF fingerprint information corresponding to the PUF identifier do not exist, or exist but are not within the validity period, the authentication service device generates a PUF fingerprint information acquisition request based on the device identifier and the PUF identifier, and sends the PUF fingerprint information acquisition request to the security management center.
[0074] If the PUF fingerprint information corresponding to the device identifier and PUF identifier in the request does not exist in the local cache, or if it exists but has expired, the authentication service device generates a PUF fingerprint information retrieval request based on the device identifier and PUF identifier, and sends the request to the security management center. The purpose of this step is to obtain the latest PUF fingerprint information through interaction with the security management center in the event of a cache miss or information expiration, thereby ensuring the accuracy and security of authentication.
[0075] In summary, this embodiment achieves effective management and rapid retrieval of PUF fingerprint information by introducing a local caching mechanism and combining it with an expiration check. Upon receiving an authentication request, the authentication service device first attempts to retrieve the PUF fingerprint information from the local cache. If the cache hits and the information is within its validity period, the cached information is used directly, avoiding communication overhead with the security management center and improving authentication efficiency. If the cache misses or the information expires, the latest PUF fingerprint information is obtained through interaction with the security management center, ensuring the accuracy and security of authentication. The overall technical solution, through the synergistic effect of the caching mechanism and the expiration check, optimizes the authentication process and ensures authentication security, providing strong support for rapid and secure authentication of terminal devices.
[0076] In one embodiment, before step S10211 where the authentication service device determines whether the cached PUF fingerprint information is within its validity period, the method further includes the following step:
[0077] Step S102101: The authentication service device counts the access frequency of the terminal device and determines the frequency range corresponding to the access frequency; the frequency range includes a high frequency range, a medium frequency range, and a low frequency range.
[0078] Among them, access frequency refers to the number of times a terminal device sends an authentication request to the authentication service device per unit of time, which is used to measure the activity level of the terminal device.
[0079] Frequency range is a series of intervals divided according to access frequency, including high frequency range, medium frequency range and low frequency range, used to distinguish the access activity of terminal devices.
[0080] Before processing authentication requests, the authentication service device first counts the access frequency of terminal devices, that is, the number of times a terminal device initiates an authentication request per unit of time. Then, based on preset thresholds, the access frequency is divided into different frequency ranges, such as high-frequency, medium-frequency, and low-frequency ranges. The purpose of this step is to provide a basis for subsequent caching strategy formulation, ensuring that highly active terminal devices can obtain more efficient authentication services.
[0081] Step S102102: Determine the cache priority and cache validity period of the PUF fingerprint information corresponding to the terminal device according to the frequency range; wherein, the priority of the high frequency range, the mid frequency range and the low frequency range are from high to low, and the corresponding cache validity period is from long to short.
[0082] Among them, cache priority is a parameter used to determine the storage order and retention time of PUF fingerprint information in the local cache. The higher the priority, the longer the cache retention time or the more priority the storage location.
[0083] The cache validity period refers to the maximum time that PUF fingerprint information can be used in the local cache. After this time, the cached information is considered invalid.
[0084] The authentication service equipment determines the corresponding cache priority and cache validity period based on the frequency range of the terminal devices. Generally, terminal devices with higher access frequency (i.e., in the high-frequency range) have higher cache priority and longer cache validity periods; conversely, terminal devices with lower access frequency (i.e., in the low-frequency range) have lower cache priority and shorter cache validity periods. The purpose of this step is to dynamically adjust the caching strategy based on the activity level of the terminal devices, thereby improving the utilization of cache resources and authentication efficiency.
[0085] Step S102103: encrypt and cache the PUF fingerprint information corresponding to the terminal device locally according to the cache priority, and determine the validity period of the PUF fingerprint information as the cache validity period.
[0086] Encrypted caching refers to encrypting PUF fingerprint information before caching it locally to prevent information leakage or tampering.
[0087] The authentication service device encrypts the PUF fingerprint information corresponding to the terminal device according to the determined cache priority and caches it in local storage. Simultaneously, the validity period of the cached PUF fingerprint information is set to the previously determined cache validity period. This step aims to ensure the security and validity of the PUF fingerprint information in the local cache, while dynamically adjusting the caching strategy based on the terminal device's access activity to optimize system resource allocation.
[0088] In summary, this embodiment achieves intelligent management and optimized utilization of PUF fingerprint information by introducing access frequency statistics and dynamic caching strategies. The authentication service device statistically analyzes the access frequency of terminal devices and determines cache priority and validity period based on the frequency range. This allows highly active terminal devices to obtain longer cache validity periods and higher cache priorities, thereby improving the authentication efficiency of these devices. Simultaneously, encrypted caching technology ensures the security of PUF fingerprint information in local storage, preventing the risk of information leakage and tampering. The overall technical solution, through the synergistic effect of access frequency statistics, cache priority allocation, and encrypted caching, forms an efficient and secure PUF fingerprint information management mechanism, providing strong support for rapid and secure authentication of terminal devices.
[0089] In one embodiment, after step S102103, where the authentication service device encrypts and caches the PUF fingerprint information corresponding to the terminal device locally according to the cache priority, the following steps are included:
[0090] Step S102104: The authentication service device monitors the network status between itself and the security management center. If the network status is abnormal, the validity period of the cached PUF fingerprint information is extended according to the duration of the abnormal network status. If the network status is normal, the validity period of the cached PUF fingerprint information is not extended.
[0091] Network status refers to the communication connection status between the authentication service equipment and the security management center, including normal and abnormal states. Abnormal network status may be caused by network congestion, link failure, or service interruption of the security management center.
[0092] The duration of network status anomaly refers to the length of time from when the network status becomes abnormal until the network status returns to normal.
[0093] After encrypting and caching the PUF fingerprint information corresponding to the terminal device locally, the authentication service device continuously monitors the network status between itself and the security management center. If an abnormal network status is detected, such as the inability to establish a connection with the security management center or communication latency exceeding a threshold, the authentication service device dynamically adjusts the validity period of the locally cached PUF fingerprint information based on the duration of the network status abnormality. Specifically, if the network status abnormality lasts for a long time, the authentication service device will extend the validity period of the cached PUF fingerprint information to ensure that the cached information can continue to be used for authentication until the network recovers, avoiding authentication failures caused by network problems. Conversely, if the network status is normal, the authentication service device will not extend the validity period of the cached PUF fingerprint information, but will manage it according to the originally set validity period.
[0094] In summary, this embodiment significantly enhances the fault tolerance and robustness of the authentication service device by introducing network status monitoring and dynamic validity period adjustment mechanisms. In the event of abnormal network conditions, the authentication service device can intelligently extend the validity period of cached PUF fingerprint information based on the duration of the abnormality, ensuring the continuity and stability of the authentication process and avoiding authentication interruptions or failures caused by network problems. Simultaneously, when the network condition is normal, the authentication service device maintains its original validity period management strategy, avoiding unnecessary extensions of cached information, thereby optimizing the utilization of system resources. The overall technical solution, by combining network status monitoring and dynamic validity period adjustment, forms a flexible and efficient authentication service mechanism, providing strong protection for the secure authentication of terminal devices in complex network environments.
[0095] For step S103, the terminal device inputs the PUF challenge information into the PUF hardware module to obtain PUF response information; obtains second verification information based on the PUF response information, and sends the second verification information to the authentication service device.
[0096] In this step, after receiving the PUF challenge information sent by the authentication service device, the terminal device immediately inputs it into its built-in PUF hardware module. The PUF hardware module processes the challenge information based on its own physical characteristics, generating a unique response, namely the PUF response information. After obtaining the PUF response information, the terminal device calculates the second verification information using the same algorithm or rules as the authentication service device in generating the first verification information. Then, the terminal device sends the second verification information to the authentication service device via network communication or other means, so that the authentication service device can perform subsequent verification.
[0097] In one embodiment, the first hash value is a hash value obtained by calculating the combination value of the first PUF response information and the PUF challenge information using the SM3 cryptographic hash algorithm;
[0098] Step S102, whereby the authentication service device sends the PUF challenge information to the terminal device, further includes:
[0099] The authentication service device generates a random number and sends the random number and the PUF challenge information to the terminal device;
[0100] Step S102, where the authentication service device obtains the first verification information based on the first hash value, includes:
[0101] The authentication service device extracts the first N bits of the first hash value to obtain the first response hash value; it uses the SM3 cryptographic hash algorithm to calculate the first hash value of the XOR value of the first response hash value and the random number, and extracts the first N bits of the first hash value to obtain the first verification information; where N is a positive integer;
[0102] Step S103, whereby the terminal device obtains the second verification information based on the PUF response information, includes:
[0103] The terminal device uses the SM3 cryptographic hash algorithm to calculate the second hash value of the combination of the PUF response information and the PUF challenge information, and extracts the first N bits of the second hash value to obtain the second response hash value; it also uses the SM3 cryptographic hash algorithm to calculate the second hash value of the XOR value of the second response hash value and the random number, and extracts the first N bits of the second hash value to obtain the second verification information.
[0104] Among them, the SM3 cryptographic hash algorithm is a cryptographic hash algorithm standard released by the State Cryptography Administration of China. It is used to convert input data of arbitrary length into hash values of fixed length and has security characteristics such as collision resistance and second preimage resistance.
[0105] Random numbers are random or pseudo-random data generated by authentication service equipment to enhance the security of the authentication process.
[0106] The XOR value refers to the result of performing a bitwise XOR operation on two binary data.
[0107] This embodiment achieves secure verification and dynamic authentication of PUF response information by introducing the SM3 cryptographic hash algorithm, random numbers, and XOR operations. The authentication service device and the terminal device use the same processing flow: SM3 hash calculation, random number XOR, and truncating the first N bits to generate verification information, ensuring the uniqueness and consistency of the verification information. The application of the SM3 algorithm guarantees the security and collision resistance of the hash value, the introduction of random numbers enhances the dynamism of the authentication process and its resistance to replay attacks, and the XOR operation further obfuscates the data, increasing the difficulty of cracking. The overall technical solution, through the synergistic effect of cryptographic algorithms and dynamic factors, forms a secure and reliable PUF authentication mechanism, providing a solid guarantee for the identity verification of terminal devices.
[0108] In step S104, the authentication service device receives the second verification information and determines whether the second verification information matches the first verification information. If they match, the terminal device is determined to have passed authentication, and an authentication success result is sent to the security management center. The security management center sets the binding status in the binding record corresponding to the device identifier and the PUF identifier to the authentication success status. If they do not match, the terminal device is determined to have failed authentication, and an authentication failure result is sent to the security management center. The security management center clears the binding record corresponding to the device identifier and the PUF identifier.
[0109] The security management center maintains a binding record between device identifiers and PUF identifiers. This record records the correspondence between the device identifier of each terminal device and the PUF identifier of its internal PUF hardware module, as well as authentication status and other information. Through this binding record, the security management center can perform unified management and monitoring of IoT devices.
[0110] The binding status in the binding record indicates the current authentication status of the device identifier and the PUF identifier, typically showing "authentication successful," "unauthenticated," or "authentication failed." When authentication is successful, the binding status is set to "authentication successful," indicating that the terminal device and its PUF hardware module have been authenticated and are legitimate and trustworthy devices. When authentication fails, the security management center will clear the binding record, effectively removing the binding relationship between the device identifier and the PUF identifier from the system, indicating that the device cannot be authenticated and may pose a security risk.
[0111] In this step, after receiving the second verification information from the terminal device, the authentication service device compares it with the previously generated first verification information. If they match, it indicates that the response information provided by the terminal device is valid, and the authentication service device determines that the terminal device has passed authentication. Then, the authentication service device sends the authentication success result to the security management center. Upon receiving the authentication success result, the security management center sets the binding status in the binding record corresponding to the device identifier and PUF identifier to the authentication success status, indicating that the device has passed authentication and can be used normally in the IoT system. If the second verification information does not match the first verification information, the authentication service device determines that the terminal device authentication has failed and sends an authentication failure result to the security management center. Upon receiving the authentication failure result, the security management center clears the binding record corresponding to the device identifier and PUF identifier to prevent unauthorized devices from continuing to attempt to access the IoT system, ensuring system security.
[0112] In one embodiment, after step S104, where the security management center sets the binding status in the binding record corresponding to the device identifier and the PUF identifier to an authentication success status, the following steps are included:
[0113] Step S1041: The security management center obtains the authentication log information based on the device identifier, authentication pass result and current authentication time, and records the authentication log information into a preset authentication log table.
[0114] After step S104, where the security management center clears the binding record corresponding to the device identifier and the PUF identifier, the process includes:
[0115] In step S1042, the security management center obtains authentication log information based on the device identifier, authentication failure result, authentication failure type, and current authentication time, and records the authentication log information in the authentication log table; wherein, the authentication failure type is determined based on the reason for the authentication failure.
[0116] Among them, the authentication log information is an entry that records information related to the authentication process, which usually includes device identification, authentication result, authentication time, etc., and is used for auditing and tracing authentication behavior.
[0117] The authentication log table is a pre-defined database table or file used to store authentication log information, facilitating subsequent querying and analysis.
[0118] This embodiment achieves comprehensive auditing and traceability of the authentication process by introducing an authentication log recording mechanism. The security management center generates corresponding authentication log information and records it in a pre-defined authentication log table for both successful and failed authentication cases. This technique not only provides system administrators with detailed records of authentication behavior, facilitating subsequent auditing and traceability, but also provides strong data support for system optimization and troubleshooting. By recording detailed information on successful and failed authentication (including device identification, authentication result, authentication time, and failure type), the security management center can comprehensively grasp the operational status of the authentication system and promptly identify and address potential security vulnerabilities.
[0119] In one embodiment, after the authentication service device determines in step S104 that the terminal device authentication has failed, the method further includes the following steps:
[0120] The authentication service device generates authentication failure information and sends the authentication failure information to the terminal device;
[0121] After the authentication service device determines that the terminal device has passed authentication in step S104, the method further includes the following steps:
[0122] The authentication service device generates authentication pass information and sends the authentication pass information to the terminal device.
[0123] In this embodiment, when authentication fails, the authentication service device generates and sends authentication failure information, providing the terminal device with a clear reason or status code for the authentication failure, which helps the terminal device to troubleshoot errors or re-authenticate. When authentication succeeds, the authentication service device generates and sends authentication success information, providing the terminal device with confirmation of successful authentication, enabling the terminal device to continue performing subsequent operations or enter a secure access state.
[0124] In one embodiment, after step S104, where the security management center sets the binding status in the binding record corresponding to the device identifier to an authentication success status, the following steps are included:
[0125] When a device unbinding instruction is received from the terminal device through the authentication service device, the device identifier to be unbound and the corresponding PUF identifier are parsed; it is determined whether there is a binding record between the device identifier and the PUF identifier in the device binding relationship table; if so, the binding record is cleared; if not, an unbinding error message is sent to the authentication service device.
[0126] Among them, the device unbinding command is initiated by the terminal device to request the removal of its binding relationship with a specific PUF identifier.
[0127] This embodiment is executed by the authentication processing module of the security management center. After the authentication processing module sets the binding status in the binding record corresponding to the device identifier to the authentication successful status, if it receives a device unbinding command sent by the terminal device through the authentication service device, it first parses the command to obtain the device identifier to be unbound and the corresponding PUF identifier. Next, it queries the device binding relationship table to determine whether there is a binding record in the table that matches the parsed device identifier and PUF identifier. If it exists, the binding record is removed from the table, and the unbinding operation is completed. If it does not exist, an unbinding error message is generated and sent to the authentication service device to inform it that the unbinding operation failed. This embodiment achieves dynamic management of the binding relationship between devices and PUF identifiers by introducing a device unbinding command parsing and processing flow.
[0128] The above embodiments are merely illustrative of several implementation methods of this application, and their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the invention patent. It should be noted that those skilled in the art can make several modifications and improvements without departing from the concept of this application, and this application also intends to include these modifications and variations.
Claims
1. A distributed IoT device authentication method based on PUF, characterized in that, Includes the following steps: The terminal device obtains a device identifier and a PUF identifier, generates an authentication request based on the device identifier and the PUF identifier, and sends the authentication request to the authentication service device; wherein, the terminal device is equipped with a PUF hardware module; the device identifier is used to uniquely identify the terminal device, and the PUF identifier is used to uniquely identify the PUF hardware module; The authentication service device obtains PUF fingerprint information sent from the security management center according to the authentication request; the PUF fingerprint information includes PUF challenge information and a first hash value, the first hash value being obtained based on the first PUF response information; the first verification information is obtained based on the first hash value; the PUF challenge information is sent to the terminal device; the first PUF response information is registered to the security management center by the PUF hardware module during the production registration stage; The terminal device inputs the PUF challenge information into the PUF hardware module to obtain PUF response information; it then obtains second verification information based on the PUF response information and sends the second verification information to the authentication service device. The authentication service device receives the second verification information and determines whether the second verification information matches the first verification information. If they match, the terminal device is determined to be authenticated successfully, and an authentication success result is sent to the security management center. The security management center sets the binding status in the binding record corresponding to the device identifier and the PUF identifier to the authentication success status. If they do not match, the terminal device is determined to be authenticated unsuccessfully, and an authentication failure result is sent to the security management center. The security management center clears the binding record corresponding to the device identifier and the PUF identifier. The first hash value is obtained by using the SM3 cryptographic hash algorithm to calculate the combined value of the first PUF response information and the PUF challenge information; The step of the authentication service device sending the PUF challenge information to the terminal device further includes: The authentication service device generates a random number and sends the random number and the PUF challenge information to the terminal device; The step by which the authentication service device obtains the first verification information based on the first hash value includes: The authentication service device extracts the first N bits of the first hash value to obtain the first response hash value; it uses the SM3 cryptographic hash algorithm to calculate the first hash value of the XOR value of the first response hash value and the random number, and extracts the first N bits of the first hash value to obtain the first verification information; where N is a positive integer; The steps for the terminal device to obtain the second verification information based on the PUF response information include: The terminal device uses the SM3 cryptographic hash algorithm to calculate the second hash value of the combination of the PUF response information and the PUF challenge information, and extracts the first N bits of the second hash value to obtain the second response hash value; it also uses the SM3 cryptographic hash algorithm to calculate the second hash value of the XOR value of the second response hash value and the random number, and extracts the first N bits of the second hash value to obtain the second verification information.
2. The PUF-based distributed IoT device authentication method according to claim 1, characterized in that, The step of the authentication service device obtaining PUF fingerprint information sent from the security management center according to the authentication request includes: The authentication service device generates a PUF fingerprint information acquisition request based on the device identifier and the PUF identifier, and sends the PUF fingerprint information acquisition request to the security management center; The security management center determines whether a pre-defined device binding relationship table contains a binding record related to the device identifier or the PUF identifier; If no relevant binding record exists, the security management center obtains the corresponding PUF fingerprint information based on the PUF identifier, sends the PUF fingerprint information to the authentication service device, adds a binding record between the device identifier and the PUF identifier to the device binding relationship table, and sets the authentication status in the binding record to the authenticating status. If a relevant binding record exists, the security management center determines whether the device identifier and the PUF identifier match the binding record. If they match, the security management center obtains the corresponding PUF fingerprint information based on the PUF identifier and sets the authentication status in the binding record corresponding to the device identifier and the PUF identifier to an authentication in progress state. If they do not match, the security management center generates an error message and sends it to the authentication service device. The authentication service device responds to the error message and determines that the terminal device authentication has failed.
3. The PUF-based distributed IoT device authentication method according to claim 1, characterized in that, The step of the authentication service device obtaining PUF fingerprint information sent from the security management center according to the authentication request includes: The authentication service device generates a PUF fingerprint information acquisition request based on the device identifier and the PUF identifier, and sends the PUF fingerprint information acquisition request to the security management center; The security management center verifies the validity of the PUF identifier based on a preset PUF registry; the PUF registry records the PUF identifiers of registered PUF hardware modules; If the verification fails, the security management center generates an error message and sends it to the authentication service device; the authentication service device responds to the error message and determines that the terminal device authentication has failed. If the verification is valid, the security management center obtains the corresponding PUF fingerprint information based on the PUF identifier and sends the PUF fingerprint information to the authentication service device.
4. The PUF-based distributed IoT device authentication method according to claim 2 or 3, characterized in that, The step of the authentication service device generating a PUF fingerprint information acquisition request based on the device identifier and the PUF identifier, and sending the PUF fingerprint information acquisition request to the security management center includes: The authentication service device determines whether the device identifier and the PUF fingerprint information corresponding to the PUF identifier exist in the local cache; if they exist, it determines whether the cached PUF fingerprint information is within its validity period; if it is within its validity period, the authentication service device obtains the device identifier and the PUF fingerprint information corresponding to the PUF identifier from the local cache. If the device identifier and the PUF fingerprint information corresponding to the PUF identifier do not exist, or exist but are not within the validity period, the authentication service device generates a PUF fingerprint information acquisition request based on the device identifier and the PUF identifier, and sends the PUF fingerprint information acquisition request to the security management center.
5. The PUF-based distributed IoT device authentication method according to claim 4, characterized in that, Before the authentication service device determines whether the cached PUF fingerprint information is within its validity period, the following step is also included: The authentication service device counts the access frequency of terminal devices and determines the frequency range corresponding to the access frequency; the frequency range includes a high frequency range, a medium frequency range, and a low frequency range. The cache priority and cache validity period of the PUF fingerprint information corresponding to the terminal device are determined according to the frequency range; wherein, the priority of the high frequency range, the mid frequency range and the low frequency range are from high to low, and the corresponding cache validity period is from long to short. The PUF fingerprint information corresponding to the terminal device is encrypted and cached locally according to the cache priority, and the validity period of the PUF fingerprint information is determined as the cache validity period.
6. The PUF-based distributed IoT device authentication method according to claim 5, characterized in that, After the authentication service device encrypts and caches the PUF fingerprint information corresponding to the terminal device locally according to the cache priority, the following steps are included: The authentication service device monitors the network status between itself and the security management center. If the network status is abnormal, the validity period of the cached PUF fingerprint information is extended according to the duration of the abnormality. If the network status is normal, the validity period of the cached PUF fingerprint information is not extended.
7. The PUF-based distributed IoT device authentication method according to claim 1, characterized in that, After the security management center sets the binding status in the binding record corresponding to the device identifier and the PUF identifier to the authentication successful status, the following steps are included: The security management center obtains authentication log information based on the device identifier, authentication pass result, and current authentication time, and records the authentication log information into a preset authentication log table; After the security management center clears the binding record corresponding to the device identifier and the PUF identifier, the following steps are included: The security management center obtains authentication log information based on the device identifier, authentication failure result, authentication failure type, and current authentication time, and records the authentication log information in the authentication log table; wherein, the authentication failure type is determined based on the reason for the authentication failure.
8. The PUF-based distributed IoT device authentication method according to claim 2, characterized in that, The security management center includes an information management module and an authentication processing module; The step of the authentication service device obtaining PUF fingerprint information sent from the security management center according to the authentication request includes: The authentication service device generates a PUF fingerprint information acquisition request based on the device identifier and the PUF identifier, and sends the PUF fingerprint information acquisition request to the security management center; The authentication processing module parses the PUF fingerprint information acquisition request to obtain the device identifier and the PUF identifier; obtains the PUF fingerprint information corresponding to the PUF identifier from the information management module; and sends the PUF fingerprint information to the authentication service device.
9. The PUF-based distributed IoT device authentication method according to claim 8, characterized in that, After the security management center sets the binding status in the binding record corresponding to the device identifier to the authentication successful status, the following steps are included: When the authentication processing module receives a device unbinding instruction sent by the terminal device through the authentication service device, it parses the device identifier to be unbound and the corresponding PUF identifier; it determines whether there is a binding record between the device identifier and the PUF identifier in the device binding relationship table; if so, it clears the binding record; if not, it sends an unbinding error message to the authentication service device.
10. The PUF-based distributed IoT device authentication method according to claim 1, characterized in that, After the authentication service device determines that the terminal device has failed to authenticate, the process further includes the following steps: The authentication service device generates authentication failure information and sends the authentication failure information to the terminal device; After the authentication service device determines that the terminal device has passed authentication, the process further includes the following steps: The authentication service device generates authentication pass information and sends the authentication pass information to the terminal device.