Identity authentication methods, target devices, verification terminals, systems, equipment, media, and products

By using a mapping algorithm to generate and parse authentication feature data during the identity authentication process, the security issue of data transmission between the verification end and the target device is solved, data encryption and randomness are achieved, and the security of identity authentication is improved.

CN121125127BActive Publication Date: 2026-04-07YONGJIANG LAB
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-11-17
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

During the identity authentication process, the data transmission between the verification end and the target device is easily intercepted by third-party observers, leading to the leakage of PUF response values ​​and identity authentication results, resulting in insufficient data security.

Method used

The target device generates authentication feature data through the first mapping algorithm and sends it to the verification end. The verification end parses the authentication response data through the second mapping algorithm to determine the identity authentication result, instead of directly transmitting the PUF response value and authentication result. The encryption and randomness of the mapping algorithm are used to improve data security.

Benefits of technology

It effectively prevents third parties from obtaining PUF response values ​​and identity authentication results, thus improving the data security of the verification end during the target device identity authentication process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125127B_ABST
    Figure CN121125127B_ABST
Patent Text Reader

Abstract

This application provides an identity authentication method, target device, verification terminal, system, device, medium, and product. When the verification terminal performs identity authentication on the target device, the target device can generate authentication feature data to characterize the PUF response value generated by at least one PUF module according to a first mapping algorithm, and send the authentication feature data to the verification terminal, so that the verification terminal performs identity authentication on the target device according to the authentication feature data. Finally, the target device parses the authentication response data sent by the verification terminal according to a second mapping algorithm to determine whether the identity authentication is successful. This application can effectively improve the security of the identity authentication process of the verification terminal on the target device.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of identity authentication technology, and in particular to an identity authentication method, target device, verification terminal, system, device, medium and product. Background Technology

[0002] Physically Unclonable Function (PUF)-based authentication is a security technology that utilizes the random physical characteristics of chip manufacturing to generate unique hardware features, thereby enabling device authentication and key management.

[0003] During the identity authentication process, third-party observers can easily intercept the data transmitted between the verification end and the target device. How to improve the security of data transmitted by the verification end during the identity authentication process of the target device is a technical problem that needs to be solved in this field. Summary of the Invention

[0004] This application provides an identity authentication method, target device, verification terminal, system, device, medium, and product to improve the security of data during the identity authentication process of the verification terminal on the target device.

[0005] A first aspect of this application provides an authentication method applied to a target device, the target device including at least one PUF module, the method comprising: sending an authentication request to a verification terminal; upon receiving an authentication instruction sent by the verification terminal based on the authentication request, obtaining a PUF response value generated by the at least one PUF module, and generating authentication feature data characterizing the PUF response value according to a first mapping algorithm; sending the authentication feature data to the verification terminal, causing the verification terminal to perform authentication on the target device based on the authentication feature data; receiving authentication response data sent by the verification terminal, and parsing the authentication response data according to a second mapping algorithm to determine whether the authentication was successful, the authentication response data being used to characterize the authentication result of the target device.

[0006] A second aspect of this application provides an identity authentication method applied at a verification end. The method includes: upon receiving an authentication request from a target device, sending an authentication instruction to the target device, the target device including at least one PUF module; receiving authentication feature data sent by the target device, parsing the authentication feature data according to a first mapping algorithm to obtain a PUF response value generated by the at least one PUF module, and determining the identity authentication result of the target device based on a comparison result between the PUF response value and reference data; generating authentication response data to characterize the identity authentication result according to a second mapping algorithm; and sending the authentication response data to the target device, so that the target device determines whether the identity authentication is successful based on the authentication response data.

[0007] A third aspect of this application provides a target device that can be used to perform the authentication method as described in the first aspect of this application.

[0008] The fourth aspect of this application provides a verification terminal that can be used to perform the identity authentication method as described in any of the second aspects of this application.

[0009] The fifth aspect of this application provides a network system comprising: a plurality of target devices for identity verification using the method described in any one of the first aspects of this application; and an authentication terminal for authenticating the plurality of target devices using the method described in any one of the second aspects of this application.

[0010] A sixth aspect of this application provides an electronic device, comprising: a processor, and a memory communicatively connected to the processor; the memory storing computer-executable instructions; the processor executing the computer-executable instructions stored in the memory to implement the method as described in any one of the first or second aspects of this application.

[0011] A seventh aspect of this application provides a computer-readable storage medium, comprising: computer-executable instructions stored in the computer-readable storage medium, wherein the computer-executable instructions, when executed by a processor, are used to implement the method as described in any one of the first or second aspects of this application.

[0012] The eighth aspect of this application provides a computer program product comprising: a computer program that, when executed by a processor, implements the method as described in any one of the first or second aspects of this application.

[0013] In summary, the identity authentication method, target device, verification terminal, system, device, medium, and product provided in this application, when the verification terminal authenticates the target device, the target device can generate authentication feature data to characterize the PUF response value generated by at least one PUF module according to the first mapping algorithm, and send the authentication feature data to the verification terminal, so that the verification terminal can authenticate the target device according to the authentication feature data. Finally, the target device parses the authentication response data sent by the verification terminal according to the second mapping algorithm to determine whether the identity authentication is successful. In this process, no private data such as PUF response value and authentication result is transmitted between the verification terminal and the target device. Even if a third-party observer intercepts the data between the verification terminal and the target device, since the first mapping algorithm and the second mapping algorithm cannot be determined, it is also impossible to parse and obtain important information such as PUF response value and identity authentication result, which effectively improves the security of the identity authentication process of the verification terminal on the target device. Attached Figure Description

[0014] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0015] Figure 1 A schematic diagram illustrating the application scenario of the verification terminal and target device provided in this application;

[0016] Figure 2 A flowchart illustrating the method by which the verification terminal provided in this application performs identity authentication on the target device;

[0017] Figure 3 A flowchart illustrating an embodiment of the identity authentication method provided in this application;

[0018] Figure 4 A schematic diagram of an embodiment of the mapping algorithm model provided in this application;

[0019] Figure 5 A schematic diagram of the structure of an embodiment of the identity authentication device provided in this application;

[0020] Figure 6 This is a schematic diagram of the structure of an electronic device provided in this application. Detailed Implementation

[0021] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0022] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a particular order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented, for example, in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0023] Figure 1 This is a schematic diagram illustrating the application scenario of the verification terminal and target device provided in this application, such as... Figure 1 The network system provided in the target device network scenario shown includes a verification terminal 20 and multiple target devices 10, with the verification terminal 20 communicating with each of the multiple target devices 10. Figure 1 In this example, X target devices 10 are used, denoted as target device 10-1, target device 10-2, ..., target device 10-X, where X can be any positive integer.

[0024] Specifically, the target device 10 can be a wireless target device, which can transmit data to other devices or networks for processing via wireless communication technology. It is a core component in communication networks, the Internet of Things (IoT), and other technologies, and can be widely used in data communication, environmental monitoring, industrial control, smart homes, agricultural management, and healthcare.

[0025] More specifically, the target device 10 can be the PUF module itself, or it can be an electronic device containing one or more PUF modules. The PUF module includes at least one of a sensor, an integrated circuit module, a storage module, an optical PUF module, SRAM, and a wireless PUF module. Taking the PUF module as a sensor as an example, the target device 10 can be a single sensor, or it can be an electronic device containing one or more sensors.

[0026] In one embodiment, the target device 10 includes at least one PUF module, which can be at least one of physical modules capable of generating PUF data, such as a sensor, integrated circuit module, storage module, optical module, SRAM, etc.

[0027] A PUF module is a physical hardware structure integrated into a chip, hardware system, or sensor. Its core function is to, upon receiving an input (called a "challenge"), utilize the random and unique physical differences generated during the manufacturing process to output a corresponding, repeatable, and verifiable signal (called a "response"). A brief introduction to different types of PUF modules follows:

[0028] When the PUF module is an integrated circuit module, it amplifies process variations through specially designed circuit structures (such as oscillators, flip-flops, and amplifiers) to generate unique characteristics. For example, a circuit-structure-based PUF module may include: a ring oscillator PUF, an arbitrator PUF, or a flip-flop PUF.

[0029] The ring oscillator (PUF) is a module composed of multiple identical ring oscillators. Due to manufacturing variations (such as inverter delay and differences in wire resistance), the oscillation frequencies of different oscillators exhibit slight but stable differences. By comparing the frequencies of any two oscillators, a large number of unique response bits can be generated, which can serve as PUF response data.

[0030] The core of the PUF arbitrator consists of a symmetrical delay path and an arbitrator. When an excitation signal is input, it propagates along two parallel, symmetrical paths. Due to manufacturing variations in transistors and wires along these paths, the signal propagation delays differ between the two paths. The arbitrator determines which path's signal arrives first (first arrives as 1, second as 0), and outputs a response accordingly. By changing the bit width of the excitation signal or the path structure, a vast number of responses can be generated as PUF response data.

[0031] The PUF (Programmable Initial Flip-Flop) generates PUF data using the "random state" of the flip-flop during power-on initialization. Due to manufacturing variations in the two inverter circuits of the flip-flop, one of the inverters will reach a stable state faster at the moment of power-on, causing the flip-flop to eventually lock into either a "1" or "0" state. This initial state distribution is unique, and therefore can be used as PUF response data.

[0032] When a PUF module is a storage module (excluding SRAM), it utilizes the "inherent state deviation" of the memory cell during initialization to generate a unique response, similar to the principle of an SRAM PUF module. This is one of the most widely used types. Memory-based PUF modules can include: Dynamic Random Access Memory, Flash Memory, and EEPROM (Electrically Erasable Programmable Read-Only Memory) PUF.

[0033] In DRAM, the storage cells are composed of capacitors and transistors, and charge leaks out when power is off. However, due to differences in manufacturing processes, the leakage rate varies slightly between different cells. After power is turned off and then on again, without actively writing data, some cells will retain a weak charge (presenting a "1" state) due to slow leakage, while others will present a "0" state due to fast leakage. This initial random state distribution is unique and can be used as PUF response data.

[0034] Flash memory (PUF Flash) stores data by storing charge in its cells through floating gates. During manufacturing, variations in the oxide layer thickness and tunnel junction area of ​​the floating gates can lead to differences in the "programming / erasing voltage threshold" or "data retention capability" of different cells. By detecting these threshold differences, stable PUF response data can be generated.

[0035] EEPROM PUF is similar in principle to Flash. The cell characteristic deviations of EEPROM (such as write current and erase time) can also serve as the physical basis for generating PUF response data. It is often used in low-power devices (such as smart cards and sensor nodes) that need to frequently rewrite small amounts of data.

[0036] Optical PUF modules are PUF modules based on optical properties. These PUF modules utilize the microscopic randomness of optical materials or structures to generate responses through differences in the reflection and scattering of light signals. They are extremely secure and difficult to physically replicate. Optical property-based PUF modules can include: scattering medium PUF modules and fiber optic PUF modules.

[0037] A wireless PUF module is a PUF module based on the physical characteristics of the transmission link and channel during communication. It can utilize the different characteristics of the communication signal reflected on the signal wave due to the environmental characteristics between the transmitter and receiver. For example, different signals may have slight differences in phase, intensity, polarization state, and timing, which are difficult to physically replicate. Wireless PUF modules can be radio frequency PUF modules or spatial optical PUF modules.

[0038] The core of the Scattering Media PUF (PUF) module is a scattering medium (such as frosted glass, frosted plastic, or nanoparticle thin film) with a microscopic random structure. When a laser beam shines on the medium, the random structure inside the medium causes complex scattering of the light, forming a unique "speckle pattern" (similar to an "optical fingerprint") at the receiving end. The speckle patterns of different media are completely different, and the medium structure cannot be deduced from a known pattern. Therefore, it can be used as PUF response data.

[0039] Fiber Optic PUF modules utilize the microscopic inhomogeneities (such as refractive index fluctuations and core diameter deviations) formed during the manufacturing process of optical fibers. When optical signals propagate in the fiber, light of different frequencies will produce unique "mode dispersion" or "polarization state changes" due to these inhomogeneities. By detecting these changes, PUF response data of the target device can be generated.

[0040] A resistive resistive resistive element (PUF) module generates PUF response data by utilizing the microscopic random resistance differences of resistive elements (such as thin-film resistors and carbon nanotube resistors). Due to variations in material density and thickness during manufacturing, resistors of the same design will exhibit minute differences in resistance values. These differences can be detected using high-precision circuitry and used as PUF response data.

[0041] When the PUF module is a sensor module, it generates PUF response data by utilizing the mechanical characteristic deviations of sensors (such as microcantilever beams and microresonators). For example, multiple microcantilever beams with the same structure may have different inherent vibration frequencies due to manufacturing deviations (differences in length, thickness, and elastic modulus). PUF response data can be generated by detecting these frequency differences.

[0042] Sensors can be, for example, MEMS sensors or Nano-Electro-Mechanical System (NEMS) sensors. MEMS / NEMS sensors can be, for example, resistive sensors, capacitive sensors, or resonant sensors.

[0043] MEMS / NEMS resistive sensors can be categorized into resistive pressure sensors, resistive strain sensors, resistive temperature sensors, resistive force sensors, resistive acceleration sensors, resistive displacement sensors, resistive torque sensors, resistive humidity sensors, resistive gas sensors, resistive biosensors, and resistive magnetic sensors, among others.

[0044] MEMS / NEMS capacitive sensors can be capacitive pressure sensors, capacitive acceleration sensors, capacitive displacement sensors, capacitive humidity sensors, capacitive liquid level sensors, capacitive gyroscopes, capacitive gas sensors, capacitive temperature sensors, or capacitive biosensors, etc.

[0045] MEMS / NEMS resonant sensors can be categorized into resonant pressure sensors, resonant force sensors, resonant displacement sensors, resonant mass sensors, resonant strain sensors, resonant flow sensors, resonant torque sensors, resonant vibration sensors, resonant level sensors, resonant gyroscopes, resonant gas sensors, resonant magnetic sensors, resonant biosensors, resonant humidity sensors, resonant temperature sensors, resonant chemical sensors, resonant accelerometers, and resonant inertial sensors, among others.

[0046] When the target device is an electronic device that includes one or more PUF modules, the target device can be a PLC device, an electronic device motherboard, an IoT terminal, or other electronic devices that require identity verification.

[0047] The verification terminal 20 can be an electronic device with relevant functions, such as a computer, gateway, or workstation. It is the core data processing and control center in the target device network, responsible for receiving, storing, and analyzing data collected by the target device nodes and providing services to users or application systems. It is usually located at the back end of the target device network and can be used to communicate with the front-end target device 10 to achieve bidirectional data interaction.

[0048] Specifically, the role of the verification terminal 20 is to receive authentication requests and determine the legitimacy of the target device's identity. Its form can be flexibly changed according to specific application scenarios (such as communication architecture, security requirements, and device hierarchy). This application does not limit the form of the verification terminal 20. For example, the verification terminal 20 can be a server, gateway, optical modem, etc.

[0049] Verification terminal 20 needs to authenticate the target device 10 it connects to, to prevent unauthorized devices from attacking verification terminal 20 through target device 10. Among these methods, authentication methods based on device physical characteristics are widely used, especially those utilizing Physically Unclonable Functions (PUFs). PUF technology is a technique that uses the inherent physical characteristics of a device to generate a unique identifier, possessing characteristics that are difficult to copy and clone. The basic principle of PUF technology is to utilize the unavoidable minute process differences during manufacturing, which are unique to each device. By measuring and processing these differences, a unique response can be generated based on PUF technology for device authentication. This makes PUF technology a powerful tool for device authentication because it can provide a highly secure authentication mechanism that resists physical attacks and cloning attacks.

[0050] For example, Figure 2 This is a flowchart illustrating the method for the verification terminal provided in this application to authenticate the target device, which can be applied to, for example... Figure 1 In the network system shown, the process is performed by the authentication terminal 20 and any target device 10. The authentication terminal 20 can be used to authenticate the identities of X connected target devices 10 based on PUF technology. For any one of the X target devices 10, when communication with the authentication terminal 20 is required or in other scenarios, the target device 10 sends an authentication request to the authentication terminal 20 via S10. After receiving the authentication request, the authentication terminal 20 sends an authentication instruction to the target device 10 via S20. The authentication instruction may include incentive conditions, causing the target device 10 to incentivize its PUF module to generate a PUF response value upon receiving the incentive conditions. Subsequently, the target device 10 sends the PUF response value to the authentication terminal 20 via S30, allowing the authentication terminal 20 to verify the PUF response value, thereby authenticating the target device 10. Finally, the authentication terminal 20 sends the authentication result to the target device 10 via S40. After the target device 10 confirms the authentication result, subsequent communication and other operations can be performed between the target device 10 and the authentication terminal 20.

[0051] However, in the above Figure 2 During the identity authentication process shown, since the target device 10 and the verification terminal 20 need to transmit private data such as PUF response value and authentication result, a third-party observer can easily obtain information such as PUF response value and identity authentication result by intercepting the data transmitted between the verification terminal 20 and the target device 10.

[0052] Therefore, how to improve the security of the data transmitted between the verification terminal 20 and the target device 10 during the identity authentication process is a technical problem that needs to be solved in this field.

[0053] Based on this, this application provides an identity authentication method, target device, verification terminal, system, device, medium, and product to improve data security during the identity authentication process of the verification terminal on the target device. The technical solution of this application will be described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments.

[0054] Figure 3 A flowchart illustrating an embodiment of the identity authentication method provided in this application is shown below. Figure 3 The authentication method shown can be applied to, for example, Figure 1 In the scenario shown, this is executed by the verification terminal 20 and any target device 10. Specifically, as... Figure 3 The authentication methods shown include:

[0055] S101: Target device 10 sends an authentication request to verification terminal 20.

[0056] In one embodiment, the request sent by the target device 10 to the verification terminal 20 carries the identity identifier (ID) of the target device 10, which is used to inform the verification terminal 20 of its identity and request verification.

[0057] In one embodiment, the verification terminal 20 further determines the response data range corresponding to the target device 10 based on the verification request. The response data range is determined by the verification terminal based on the maximum and minimum allowed PUF values ​​corresponding to the target device 10. Therefore, the range of allowed PUF values ​​can be determined based on the maximum and minimum allowed PUF values ​​corresponding to the target device 10. For example, if the maximum allowed PUF value is m and the minimum allowed PUF value is n, then the range of allowed PUF values ​​is [n, m]. Based on the range of allowed PUF values ​​and the first mapping algorithm, the response data range can be determined because each allowed PUF value within the range has corresponding data to be verified. Therefore, determining the range of allowed PUF values ​​also determines the response data range.

[0058] In one embodiment, when the first mapping algorithm is a bounded function, the response data range is determined by the verification end 20 using the first mapping algorithm to perform encryption calculations on the maximum and minimum allowed PUF values ​​corresponding to the target device 10, respectively. Taking the first mapping algorithm as a bounded function as an example, the response data range is determined as follows: the maximum allowed PUF value is encrypted using the first mapping algorithm to obtain a first encryption result a; the minimum allowed PUF value is encrypted using the first mapping algorithm to obtain a second encryption result b. Because the first mapping algorithm is a bounded function and the minimum allowed PUF value is less than the maximum allowed PUF value, and because the first encryption result a is greater than the second encryption result b, the verification end determines the response data range corresponding to the target device 10 to be [b, a].

[0059] In one optional implementation, the first mapping algorithm performs the encryption calculation of the maximum allowed value of PUF as follows: Substituting the maximum allowed value of PUF into the first mapping algorithm yields the first encryption result. The method for calculating the second encryption result is similar to that for the first encryption result, and will not be repeated here. Thus, by utilizing the bounded property of the target mapping algorithm, only two endpoints need to be calculated to determine the range of response data, improving the efficiency of determining the range of response data.

[0060] In an optional implementation, the authentication method provided in this application further includes a registration process before S101. Specifically, the registration process includes sending the identification information, maximum allowable PUF value, and minimum allowable PUF value corresponding to each target device 10 to the verification terminal 20 through a secure channel, so that the verification terminal 20 stores the identification information, maximum allowable PUF value, and minimum allowable PUF value. The maximum allowable PUF value can be the sum of the average PUF response and the allowable error; the minimum allowable PUF value can be the difference between the average PUF response and the allowable error. The average PUF response is the average of multiple PUF response values ​​corresponding to the PUF module when the same stimulus is input multiple times to the PUF module.

[0061] The registration process in several typical application scenarios is described below. In the following three scenarios, the target device 10 includes a PUF module, and the PUF module is a sensor.

[0062] Scenario 1: The user corresponding to the verification terminal 20 and the target device 10 is the same, both belonging to supplier A. The average PUF response and allowable error can be obtained by the target device 10 manufacturer before it leaves the factory. The target device 10 manufacturer determines the PUF source data based on the average PUF response and allowable error. The PUF source data includes the maximum allowable value and the minimum allowable value of PUF. The PUF source data and the identification information of the target device 10 are written into the product data manual, or given to supplier A as a database file. Supplier A's technical personnel then store the database file in the verification terminal 20.

[0063] Scenario 2: The users corresponding to the verification terminal 20 and the target device 10 are not the same. For example, the verification terminal 20 is a commercial verification terminal shared by multiple enterprises, while the target device 10 is used internally by a specific user. Therefore, unlike in Scenario 1, the PUF source data and identification information of the target device 10 cannot be directly stored in the verification terminal 20. After networking, when the PUF module contained in the target device 10 is powered on for the first time, the target device 10 needs to register on the verification terminal. During registration, when the same stimulus is input to its own PUF module multiple times in real time, the target device 10 generates the average of multiple PUF response values. Then, based on the average PUF response and the allowable error pre-stored in the target device 10, the maximum allowable value and the minimum allowable value of PUF are determined, and the identification information, the maximum allowable value of PUF, and the minimum allowable value of PUF are directly sent to the verification terminal 20. Direct plaintext data transmission has low security. To improve security, a secure channel can be established through existing IT software registration methods. Identification information, the maximum allowed value of PUF, and the minimum allowed value of PUF can be sent through the secure channel. To further enhance security, the identification information, the maximum allowed value of PUF, and the minimum allowed value of PUF can be encrypted first, and then the encrypted information can be sent to the verification end 20 through the secure channel.

[0064] Scenario 3: The user corresponding to the verification terminal 20 and the target device 10 is the same. Registration can also be performed during the first network setup, and the registration method is the same as that in Scenario 2.

[0065] In an optional implementation, the registration process further includes: the target device 10 sending the target mapping algorithm to the verification terminal 20 through a secure channel.

[0066] In this way, the registration process receives and stores the target device's identification information and the maximum and minimum allowed values ​​of PUF through a secure channel, ensuring that this sensitive information is not intercepted or tampered with during transmission.

[0067] In one optional implementation, both the target device 10 and the verification terminal 20 store the same candidate first mapping algorithm, the number of candidate first mapping algorithms is greater than or equal to 1, and at least one candidate first mapping algorithm includes the first mapping algorithm.

[0068] In one optional implementation, both the target device 10 and the verification terminal 20 store the same candidate second mapping algorithm, the number of candidate second mapping algorithms is greater than or equal to 1, and at least one candidate second mapping algorithm includes the second mapping algorithm.

[0069] Under the premise of scenario 1 above, the candidate preset algorithms in the target device 10 and the verification terminal 20 are all pre-stored by the staff of supplier A, which has the highest security.

[0070] In scenario 2 or scenario 3, there are two possibilities:

[0071] One scenario is that the target device 10 pre-stores the candidate first mapping algorithm and / or candidate second mapping algorithm at the factory, but the verification terminal 20 does not. After networking, when the PUF module included in the target device 10 is powered on for the first time, the target device 10 needs to register with the verification terminal 20. During registration, the target device 10 sends the candidate first mapping algorithm and / or candidate second mapping algorithm directly to the verification terminal in plaintext, or establishes a secure channel and sends it to the verification terminal 20 through the secure channel, or encrypts the candidate first mapping algorithm and / or candidate second mapping algorithm and sends it to the verification terminal 20 after encryption.

[0072] Another scenario is that the verification terminal 20 has pre-stored the candidate first mapping algorithm and / or the candidate second mapping algorithm, but the target device 10 does not. In this case, after the network is established, when the PUF module included in the target device 10 is powered on for the first time, the target device 10 needs to register with the verification terminal 20. During registration, the verification terminal 20 can send the candidate first mapping algorithm and / or the candidate second mapping algorithm directly to the target device 10 in plaintext, or establish a secure channel and send them to the target device 10 through the secure channel, or encrypt the candidate first mapping algorithm and / or the candidate second mapping algorithm and send them to the target device 10 after encryption.

[0073] In one optional implementation, both the candidate first mapping algorithm and / or the candidate second mapping algorithm are bounded functions. The response data range is determined by the encryption result obtained by the verification end 20 after performing encryption calculations on the maximum and minimum allowed values ​​of the PUF using the candidate first mapping algorithm and / or the candidate second mapping algorithm, respectively.

[0074] S102: After receiving the authentication request, the verification terminal 20 sends an authentication instruction to the target device 10.

[0075] It should be noted that, for the same target device, both the verification terminal 20 and the target device 10 store a first mapping algorithm or multiple candidate first mapping algorithms. Furthermore, the verification terminal stores at least one stimulus corresponding to each legitimate target device and PUF response data corresponding to the at least one stimulus.

[0076] In one embodiment, for a target device, the verification terminal 20 stores multiple stimuli and corresponding PUF response data for each stimuli. After receiving an authentication request from the target device, the verification terminal 20 can randomly select or generate stimuli information and send it to the target device. In other embodiments, for a target device, the verification terminal 20 stores one stimuli and its PUF response data. That is, during the authentication process, if the stimuli are preset values ​​for one or more target devices, and the target device also stores the preset stimuli value, then the verification terminal 20 may not send stimuli information to the target device after receiving its authentication request.

[0077] Furthermore, when a first mapping algorithm is assigned to the same target device and the coefficients of the first mapping algorithm are variable, the verification terminal 20 also needs to randomly generate multiple random numbers as parameters of the first mapping algorithm and send these parameters to the target device. Alternatively, when multiple candidate first mapping algorithms are assigned to the same target device, the verification terminal 20 can randomly obtain a random number as the sequence number of the candidate first mapping algorithm and send the sequence number to the target device so that the target device can determine the first mapping algorithm from the multiple pre-stored candidate first mapping algorithms.

[0078] The excitation signal randomly determined at the verification end, the parameters of the randomly generated first mapping algorithm, and the randomly determined sequence number are all used to ensure the uniqueness and security of each verification and to prevent replay attacks.

[0079] S103: The target device 10 acquires the PUF response value generated by at least one PUF module, and generates authentication feature data to characterize the PUF response value according to the first mapping algorithm.

[0080] In one embodiment, after receiving an authentication request, the target device 10 obtains the PUF response value of at least one PUF module according to the incentive information, and inputs the PUF response value into the first mapping algorithm model to obtain the authentication feature data output by the first algorithm mapping model.

[0081] For example, Figure 4 A schematic diagram of an embodiment of the mapping algorithm model provided in this application is shown below. Figure 4 As shown, assuming the PUF response value is simulated PUF data, specifically the currently measured output voltage v, the target device 10 inputs the PUF response value v into the first mapping algorithm f1(x) to obtain the authentication feature data f(v) output by the first mapping algorithm f1(x).

[0082] Specifically, the first mapping algorithm f1(x) can be used to authenticate the target device 10 while ensuring the security performance of the PUF source data. The obtained authentication feature data f(v) is not numerically equal to the PUF source data v, but the authentication feature data f(v) can be used to characterize the PUF source data v.

[0083] This application does not limit the specific implementation of the first mapping algorithm f1(x). In the first mapping algorithm f1(x), the input independent variable is kept within a reasonable fluctuation range, and the output dependent variable is also kept within a reasonable range. Preferably, the independent variable and the dependent variable have a one-to-one correspondence.

[0084] For example, the first mapping algorithm f1(x) can be a bounded function, such as an exponential function, logarithmic function, trigonometric function, inverse trigonometric function, monotonic function, polynomial function, bidirectional tangent function, etc. For instance, the general form of the polynomial function of the first mapping algorithm f1(x) can be f(x) = anx n +an-1x n-1 +……a2x 2 +a1x 1 +a0, where a1, a2...an are n coefficients to be determined corresponding to the general form, and a0 is a fixed constant.

[0085] In one embodiment, the first mapping algorithm f1(x) is shared by the target device 10 and the verification terminal 20. Both the target device 10 and the verification terminal 20 store the first mapping algorithm f1(x). It can be that the target device 10 determines the first mapping algorithm f1(x) and sends it to the verification terminal 20 during the registration stage before S101, or the verification terminal 20 determines the first mapping algorithm f1(x) and sends it to the target device 10.

[0086] In one embodiment, the authentication instruction sent by the verification terminal 20 to the target device 10 includes first indication information, which is used to indicate the first mapping algorithm f1(x).

[0087] Then, for target device 10, after receiving the authentication instruction and before generating the authentication feature data for representing the PUF response value according to the first mapping algorithm, a first mapping algorithm f1(x) is also generated according to the first instruction information. When the first mapping algorithm f1(x) is a polynomial function, specifically, the coefficients to be determined in the polynomial function are randomly generated.

[0088] Alternatively, the target device 10 may store multiple candidate first mapping algorithms, including a first mapping algorithm f1(x). Then, after receiving the authentication instruction and before generating authentication feature data for representing the PUF response value according to the first mapping algorithm, the first mapping algorithm f1(x) corresponding to the first instruction information is determined from the stored multiple candidate first mapping algorithms based on the first instruction information.

[0089] In one embodiment, when the target device 10 generates a first mapping algorithm, the first indication information may be a random number that serves as each parameter in the first mapping algorithm; when the target device 10 stores multiple candidate first mapping algorithms, the first indication information may be identification information such as the sequence number of the first mapping algorithm.

[0090] This embodiment can select and determine the first mapping algorithm f1(x), so that the authentication feature data transmitted between the target device 10 and the verification terminal 20 in each authentication process can be generated by different mapping algorithms. This further enhances the randomness of the data transmitted between the target device 10 and the verification terminal 20, increases the difficulty for third parties to intercept and parse the authentication feature data, and more effectively improves the security of the verification terminal in the process of authenticating the target device.

[0091] In one embodiment, taking the first mapping algorithm f1(x) as an example, which is a pre-stored general function form with a certain coefficient to be determined, the verification terminal 20 can randomly generate n coefficients using a random number generator or similar method, and then substitute the generated n coefficients into the general form of the function to obtain the first mapping algorithm f1(x). For example, n=4, and the general form of the function is: f(x)=a4x 4 +a3x 3 +a2x 2 +a1x 1 +2, the four coefficients generated by the verification end 20 are a4=1, a3=2, a2=3, a1=4 respectively. Substituting these four coefficients into the general form of the function, we obtain the first mapping algorithm f1(x) = x 4 +2x 3 +3x 2 +4x 1 +2. Verification terminal 20 determines the first mapping algorithm f1(x) by randomly generating n coefficients. These randomly generated n coefficients can be sent to target device 10, so that target device 10 can also determine the same first mapping algorithm f1(x) based on the n coefficients and the general form of the function.

[0092] In one embodiment, the candidate first mapping algorithm includes n coefficients to be determined, and the first mapping algorithm f1(x) includes m coefficient values, where n ≥ m. The number of coefficients in the first mapping algorithm f1(x) can refer to the number of coefficient values ​​included in any candidate coefficient group corresponding to the general form of the function, or it can refer to the number of coefficient values ​​in the coefficient information of the general form of the function sent by the verification terminal 20 to the target device 10. The number of coefficient values ​​included in each candidate coefficient group corresponding to the general form of any function can be the same or different, and this application does not limit this. For example, the general form of the candidate first mapping algorithm function is: f(x) = a4x 4 +a3x 3 +a2x 2 +a1x 1 +a0, where a1, a2...a4 are the four coefficients to be determined corresponding to the general form, and a0 is a fixed constant. The general form of this function corresponds to two candidate coefficient groups: candidate coefficient group 1 and candidate coefficient group 2. Candidate coefficient group 1 includes three coefficient values: a4=3, a3=2, and a2=1. Candidate coefficient group 2 includes two coefficient values: a4=3 and a3=2. Any value corresponding to a coefficient to be determined can be specified in the candidate coefficient groups. Unspecified coefficients can be fixed values, for example, 0. Assuming that unspecified coefficients can be defined as 0, substituting the coefficient values ​​from candidate coefficient group 1 into the general form of the function yields the first mapping algorithm f1(x) = 3x. 4 +2x 3 +x 2 +a0; Substituting the coefficient values ​​in candidate coefficient group 2 into the general form of the function, the first mapping algorithm f1(x) = 3x is obtained. 4 +2x 3 +a0.

[0093] In one embodiment, in S103, the target device 10 may specifically receive a random number sent by the verification terminal 20, wherein the random number is generated by the verification terminal 20 using noise data. Subsequently, the target device 10 uses the first mapping algorithm f1(x) and the random number to perform encrypted calculations on the PUF value to be verified to obtain authentication feature data. As described above, the random number here represents coefficients in functional form, or the index of a candidate coefficient group, or the index of a candidate first mapping algorithm, depending on the different first mapping algorithms stored by the target device and the verification terminal.

[0094] S104: The target device 10 sends authentication feature data to the verification terminal 20, and correspondingly, the verification terminal 20 receives the authentication feature data sent by the target device 10.

[0095] Specifically, in this embodiment of the application, the target device 10 does not directly send the PUF response value to the verification terminal 20, but instead sends the authentication feature data encrypted by the first mapping algorithm to the verification terminal 20.

[0096] S105: The verification end 20 parses the authentication feature data received in S104 according to the first mapping algorithm f1(x) to obtain the PUF response value generated by at least one PUF module of the target device 10.

[0097] S106: The verification terminal 20 performs identity authentication on the target device 10 based on the PUF response value generated by at least one PUF module of the target device 10 obtained from the parsing in S105.

[0098] In one embodiment, the verification terminal 20 compares the PUF response value with pre-stored reference data, thereby authenticating the target device based on the comparison result. The reference data may be PUF reference values ​​used to characterize at least one PUF module of the target device 10.

[0099] In one embodiment, the verification terminal 20 can store reference data v-0, and then compare it with the PUF response value v obtained in S105 based on the stored reference data v-0. In reality, the response value of the target device under the same stimulus will fluctuate within a certain range when the external environment is different, but the fluctuation range vT is limited. The reference data v-0 can be the average response value of the target device calculated through multiple stimuli and responses under the same stimulus.

[0100] When the absolute value of the difference between the PUF response value and the reference data v-0 is less than or equal to the preset value vT, the verification terminal 20 determines that the identity authentication of the target device 10 is successful.

[0101] When the absolute value of the difference between the PUF response value and the reference data v-0 is greater than the preset value vT, the verification terminal 20 determines that the identity authentication of the target device 10 is unsuccessful.

[0102] S107: Verification terminal 20 generates authentication response data to characterize the identity authentication result according to the second mapping algorithm.

[0103] The device's authentication result is generally either "valid" or "invalid." When generating authentication response data, different authentication results can be mapped to different analog parameters, digital parameters, or representational data. These are then encrypted using a second mapping algorithm to obtain the authentication response data. To clearly distinguish authentication results, the representational data mapped to different authentication results can be significantly different, ensuring that the authentication response data encrypted using the second mapping algorithm is also significantly different.

[0104] This application does not limit the specific implementation of the second mapping algorithm f2(x). Similar to the first mapping algorithm, in the second mapping algorithm f2(x), the input independent variable is kept within a reasonable fluctuation range, and the output dependent variable is also kept within a reasonable range. Preferably, the independent variable and the dependent variable have a one-to-one correspondence.

[0105] For example, the second mapping algorithm f2(x) can be a bounded function, such as an exponential function, logarithmic function, trigonometric function, inverse trigonometric function, monotonic function, polynomial function, bidirectional tangent function, etc. For instance, the general form of the polynomial function of the second mapping algorithm f2(x) can be f(x) = anx. n +an-1x n-1 +……a2x 2 +a1x 1 +a0, where a1, a2...an are n coefficients to be determined corresponding to the general form, and a0 is a fixed constant.

[0106] In one embodiment, the second mapping algorithm f2(x) is shared by the target device 10 and the verification terminal 20. Both the target device 10 and the verification terminal 20 store the second mapping algorithm f2(x). It can be that the target device 10 determines the second mapping algorithm f2(x) and sends it to the verification terminal 20 during the registration stage before S101, or the verification terminal 20 determines the second mapping algorithm f2(x) and sends it to the target device 10.

[0107] In one embodiment, the authentication instruction sent by the verification terminal 20 to the target device 10 includes second indication information, which is used to indicate the second mapping algorithm f2(x).

[0108] Then, for target device 10, after receiving the authentication instruction and before parsing the authentication response data according to the second mapping algorithm, a second mapping algorithm f2(x) is generated based on the second instruction information. When the second mapping algorithm f2(x) is a polynomial function, specifically, the coefficients to be determined in the polynomial function are randomly generated.

[0109] Alternatively, the target device 10 stores multiple candidate second mapping algorithms, including a second mapping algorithm f2(x). After receiving the authentication indication but before parsing the authentication response data according to the second mapping algorithm, the second mapping algorithm f2(x) corresponding to the second indication information is determined from the multiple candidate second mapping algorithms stored based on the second indication information.

[0110] In one embodiment, when the target device 10 generates a second mapping algorithm, the second indication information may be a random number used as each parameter in the second mapping algorithm; when the target device 10 stores multiple candidate second mapping algorithms, the second indication information may be identification information such as the sequence number of the second mapping algorithm.

[0111] This embodiment can select and determine the second mapping algorithm f2(x) so that the authentication response data transmitted between the target device 10 and the verification terminal 20 in each authentication process can be generated by different mapping algorithms. This further enhances the randomness of the data transmitted between the target device 10 and the verification terminal 20, increases the difficulty for third parties to intercept and parse the authentication response data, and more effectively improves the security of the verification terminal in the process of authenticating the target device.

[0112] In one embodiment, taking the second mapping algorithm f2(x) as an example with a pre-stored general function form of a coefficient to be determined, the verification terminal 20 can randomly generate n coefficients using a random number generator or similar method, and then substitute the generated n coefficients into the general form of the function to obtain the second mapping algorithm f2(x). For example, n=4, and the general form of the function is: f(x)=a4x 4 +a3x 3 +a2x 2 +a1x 1 +2, the four coefficients generated by the verification end 20 are a4=1, a3=2, a2=3, a1=4 respectively. Substituting these four coefficients into the general form of the function, we obtain the second mapping algorithm f2(x) = x 4 +2x 3 +3x 2 +4x 1 +2. Verification terminal 20 determines the second mapping algorithm f2(x) by randomly generating n coefficients. These randomly generated n coefficients can be sent to target device 10, so that target device 10 can also determine the same second mapping algorithm f2(x) based on the n coefficients and the general form of the function.

[0113] In one embodiment, the candidate second mapping algorithm includes n coefficients to be determined, and the second mapping algorithm f2(x) includes m coefficient values, where n ≥ m. The number of coefficients in the second mapping algorithm f2(x) can refer to the number of coefficient values ​​included in any candidate coefficient group corresponding to the general form of the function, or it can refer to the number of coefficient values ​​in the coefficient information of the general form of the function sent by the verification terminal 20 to the target device 10. The number of coefficient values ​​included in each candidate coefficient group corresponding to the general form of any function can be the same or different, and this application does not limit this. For example, the general form of the candidate second mapping algorithm function is: f(x) = a4x 4+a3x 3 +a2x 2 +a1x 1 +a0, where a1, a2...a4 are the four coefficients to be determined corresponding to the general form, and a0 is a fixed constant. The general form of this function corresponds to two candidate coefficient groups: candidate coefficient group 1 and candidate coefficient group 2. Candidate coefficient group 1 includes three coefficient values: a4=3, a3=2, and a2=1. Candidate coefficient group 2 includes two coefficient values: a4=3 and a3=2. Any value corresponding to a coefficient to be determined can be specified in the candidate coefficient groups. Unspecified coefficients can be fixed values, for example, 0. Assuming that unspecified coefficients can be defined as 0, substituting the coefficient values ​​from candidate coefficient group 1 into the general form of the function yields the second mapping algorithm f2(x) = 3x. 4 +2x 3 +x 2 +a0; Substituting the coefficient values ​​in candidate coefficient group 2 into the general form of the function, we obtain the second mapping algorithm f2(x) = 3x 4 +2x 3 +a0.

[0114] In one embodiment, the second mapping algorithm f2(x) and the first mapping algorithm f1(x) can be the same mapping algorithm, thereby reducing the number of mapping algorithms stored in the target device 10 and reducing the computational load during the authentication process. The authentication indication may then include either the first indication information or the second indication information.

[0115] In another embodiment, the second mapping algorithm f2(x) and the first mapping algorithm f1(x) can be different mapping algorithms, which can further improve the randomness of the data transmitted between the target device 10 and the verification terminal 20, and increase the difficulty for third parties to intercept and parse the authentication feature data and authentication response data at the same time.

[0116] S108: Subsequently, the verification terminal 20 sends authentication response data to the target device 10, and the target device 10 receives the authentication response data sent by the verification terminal 20 accordingly.

[0117] Specifically, in this embodiment, the verification terminal 20 does not directly send its authentication result to the target device 10, but indirectly sends the authentication result by sending authentication response data encrypted by the second mapping algorithm to the target device 10, so that the target device 10 can determine whether the authentication is successful based on the authentication response data.

[0118] S109: The target device 10 parses the authentication response data received in S108 according to the second mapping algorithm f2(x) to obtain the PUF reference value v-0 or random data v'.

[0119] S110: The target device 10 determines whether the authentication of the target device 10 by the verification terminal 20 is successful based on the PUF reference value v-0 or random data v' obtained from the parsing in S109.

[0120] In this embodiment, when the verification terminal 20 successfully authenticates the target device 10, the authentication response data sent by the verification terminal 20 to the target device 10 is generated based on the reference data v-0. Specifically, in S106, the verification terminal 20 inputs the reference data v-0 into the second mapping algorithm f2(x) and obtains the authentication response data f(v-0). (Refer to...) Figure 4 In the example shown, the verification terminal 20 can obtain the factory reference value of the PUF response value v of the target device 10, denoted as the PUF reference value v-0. Then the verification terminal 20 can input the PUF reference value v-0 into the second mapping algorithm f2(x) and obtain the reference feature data f(v-0) output by the second mapping algorithm f2(x).

[0121] In S109, the target device 10 parses the received authentication response data f(v-0) to obtain the PUF reference value v-0, and in S110, based on the fact that the absolute value of the difference between the PUF response value v and the reference data v-0 is less than a preset value, it determines that the verification end 20 has successfully authenticated the identity of the target device 10.

[0122] When the authentication terminal 20 fails to authenticate the target device 10, the authentication response data sent by the authentication terminal 20 to the target device 10 is generated based on random data v'. Specifically, in S107, the authentication terminal 20 inputs the random data v' into the second mapping algorithm f2(x) and obtains the authentication response data f(v').

[0123] In S109, the target device 10 parses the received authentication response data f(v') to obtain random data v', and in S110, based on the absolute value of the difference between the PUF response value v and the random data v' being greater than a preset value, it is determined that the authentication of the target device 10 is unsuccessful.

[0124] The random feature data is obtained by inputting the PUF reference value of at least one PUF module of the target device 10 into the mapping algorithm model. For example, referring to... Figure 4 In the example shown, the verification terminal 20 can generate a random number v', where the difference between the random number v' and the PUF reference value v-0 is much greater than the preset value vT, and input the random number v' into the second mapping algorithm f2(x) to obtain the authentication response data f(v') output by the second mapping algorithm f2(x).

[0125] In one embodiment, the feature data parsed by the target device 10 based on the received authentication response data can be either reference data v-0 or random data v'. Based on the comparison between the feature data and the PUF response value v, the verification end 20 determines whether the authentication of the target device 10 is successful. Specifically, if the absolute value of the difference between the PUF response value v and the feature data is less than a preset value, the authentication is successful; if the absolute value of the difference between the PUF response value v and the feature data is greater than the preset value, the authentication is unsuccessful; if the absolute value of the difference between the PUF response value v and the feature data is equal to the preset value, the authentication is successful; or, if the absolute value of the difference between the PUF response value v and the feature data is equal to the preset value, the authentication is successful.

[0126] In one embodiment, when the target device 10 determines that the identity authentication is successful, it also completes the verification performed by the target device 10 on the verification terminal 20, that is, it determines that the server terminal 20 has the first mapping algorithm f1(x), the second mapping algorithm f2(x) and the PUF reference value v-0.

[0127] In other embodiments, other types of representation data can be set at the verification end to distinguish the identity authentication results, not limited to reference data v-0 and random data v'.

[0128] In summary, in the authentication method provided in this application, when the verification end authenticates the target device, the target device can generate authentication feature data to characterize the PUF response value generated by at least one PUF module according to the first mapping algorithm, and send the authentication feature data to the verification end, so that the verification end can authenticate the target device according to the authentication feature data. Finally, the target device parses the authentication response data sent by the verification end according to the second mapping algorithm to determine whether the authentication is successful. In this process, no privacy data such as PUF response value and authentication result is transmitted between the verification end and the target device. Even if a third-party observer intercepts the data between the verification end and the target device, since there is no key information such as the first mapping algorithm f1(x) and the second mapping algorithm f2(x), it is impossible to parse and obtain important information such as PUF response value and authentication result. This effectively protects the privacy of the data and improves the security of the verification end in the process of authenticating the target device.

[0129] In particular, this application, when used in the two-way authentication process between the verification end and the target device, simulates the physical non-cloning property of PUF, enabling mutual authentication between devices without the need for pre-allocated keys, and protects the privacy of the authentication results. This prevents third parties from inferring whether the authentication was successful through communication data packets, effectively defending against network eavesdropping and AI model attacks.

[0130] In the foregoing embodiments of this application, the identity authentication method provided by the embodiments of this application has been described. In order to implement the functions of the methods provided by the embodiments of this application, the verification terminal and the target device, as the executing entities, can be implemented through hardware structures and / or software modules, for example, in the form of hardware structures, software modules, or hardware structures plus software modules. Whether a certain function is implemented in the form of hardware structures, software modules, or hardware structures plus software modules depends on the specific application and design constraints of the technical solution.

[0131] For example, this application provides a target device that can be applied to, for example... Figure 1 In the network system shown, and specifically used to perform, such as Figure 3 The authentication method performed by the target device 10 shown.

[0132] For example, this application provides a verification terminal that can be applied to, for example... Figure 1 In the network system shown, and specifically used to perform, such as Figure 3 The authentication method performed by the verification terminal 20 shown.

[0133] This application also provides a network system, which includes a verification terminal 20 and multiple target devices 10, and a specific implementation thereof can be referred to. Figure 1 The verification terminal 20 can be used to perform actions such as... Figure 3 The authentication method shown performs authentication on multiple connected target devices 10. Taking any one of the target devices 10 as an example, when the verification terminal 20 authenticates the target device 10, the target device 10 can generate authentication feature data to characterize the PUF response value generated by at least one PUF module according to a first mapping algorithm, and send the generated authentication feature data to the verification terminal 20, so that the verification terminal 20 can authenticate the target device 10 based on the received authentication feature data. Finally, the target device 10 parses the authentication response data sent by the verification terminal 20 according to a second mapping algorithm to determine whether the authentication was successful.

[0134] In one embodiment, the target device 10 may store a plurality of candidate first mapping algorithms and determine a first mapping algorithm from the plurality of candidate first mapping algorithms. Combined with Figure 1 In the example of the network system shown, when the verification terminal 20 connects to multiple target devices 10, to maximize security, the multiple candidate first mapping algorithms stored by the multiple target devices 10 connected to the verification terminal 20 are different. Each target device 10 may store one or more candidate first mapping algorithms. Alternatively, in other embodiments, to reduce data storage, the multiple target devices 10 connected to the verification terminal 20 may share multiple candidate first mapping algorithms.

[0135] In one embodiment, the target device 10 may store a plurality of candidate second mapping algorithms and determine a second mapping algorithm from the plurality of candidate second mapping algorithms. Combined with Figure 1 In the example of the network system shown, when the verification terminal 20 connects to multiple target devices 10, to maximize security, the multiple candidate second mapping algorithms stored by the multiple target devices 10 connected to the verification terminal 20 are different. Each target device 10 may store one or more candidate second mapping algorithms. Alternatively, in other embodiments, to reduce data storage, the multiple target devices 10 connected to the verification terminal 20 may also share multiple candidate second mapping algorithms.

[0136] More specifically, when the network system provided in this application is applied in an industrial IoT networking scenario, the target device 10 and the verification terminal 20 form a closed loop through data acquisition, transmission, analysis, and verification. This can be used to improve industrial production efficiency, optimize management decisions, and ensure the reliability of the network system. In an industrial IoT scenario, the target device 10 can be a physical entity that directly participates in production or operation within the industrial IoT. The target device 10 can acquire and control industrial data through built-in sensors, actuators, or communication modules. The verification terminal 20 can be used to clean, analyze, and verify the data acquired by the target device 10, and generate decision commands to control the target device 10.

[0137] In specific implementations, the target device 10 can be an industrial sensor, actuator, or controller, such as a temperature sensor, pressure sensor, industrial programmable logic controller (PLC), or smart meter. Since industrial IoT devices often need to operate for extended periods in harsh industrial environments, they typically have limited computing power and storage resources. Furthermore, the target device 10 involves critical information such as production processes and equipment control; if attacked or tampered with, it could lead to serious consequences. Therefore, the verification terminal 20 can be used in industrial IoT networking scenarios to perform authentication and security checks on the target device 10.

[0138] In one embodiment, such as Figure 1When the network system shown is an Industrial Internet of Things (IIoT) network system, it may also include gateway devices, data storage devices, and management and control devices. The gateway device can be used to forward data and perform protocol conversion between different devices. In a PUF-based authentication network system, the gateway device can assist communication between the target device 10 and the authentication terminal 20, ensuring the smooth progress of the authentication process. The data storage device is used to store data and authentication results from the target device 10 and / or the authentication terminal 20 for subsequent analysis and processing. The management and control device can be used for automated control of the target device 10 and / or the authentication terminal 20, or, alternatively, administrators can control the target device 10 and / or the authentication terminal 20 through the management and control device.

[0139] For example, Figure 5 This is a schematic diagram of the structure of an embodiment of the identity authentication device provided in this application, as shown below. Figure 5 The identity authentication device 100 shown includes a transceiver module 101 and a processing module 102.

[0140] When the identity authentication device 100 is used as the target device 10 to perform an identity authentication method, the processing module 102 sends an authentication request to the verification end through the transceiver module 101. Upon receiving an authentication instruction from the verification end through the transceiver module 101, the processing module 102 obtains the PUF response value generated by the at least one PUF module and generates authentication feature data characterizing the PUF response value according to a first mapping algorithm. The processing module 102 sends the authentication feature data to the verification end through the transceiver module 101, enabling the verification end to perform identity authentication on the target device based on the authentication feature data. The processing module 102 receives the authentication response data sent by the verification end through the transceiver module 101 and parses the authentication response data according to a second mapping algorithm to determine whether the identity authentication is successful.

[0141] When the identity authentication device 100 is used as the verification terminal 20 to perform the identity authentication method, the processing module 102 receives the authentication request sent by the target device 10 through the transceiver module 101, and sends the authentication instruction to the target device through the transceiver module 101; the processing module 102 receives the authentication feature data sent by the verification terminal through the transceiver module 101, and parses the authentication feature data according to the first mapping algorithm to obtain the PUF response value generated by the at least one PUF module, and determines the identity authentication result of the target device based on the comparison result of the PUF response value and the reference data; the processing module 102 sends the authentication response data to the target device through the transceiver module 101.

[0142] like Figure 5 The method performed by the identity authentication device is the same as the identity authentication method provided in the foregoing embodiments in terms of technical features and effects, and will not be described again.

[0143] It should be understood that the division of the various modules in the above device is merely a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, these modules can be implemented entirely in software via processing element calls; they can be fully implemented in hardware; or some modules can be implemented by processing element calls to software, while others are implemented in hardware. For example, a module can be a separately established processing element, or it can be integrated into a chip within the above device. Alternatively, it can be stored as program code in the memory of the above device, and its functions can be called and executed by a processing element of the device. The implementation of other modules is similar. Moreover, these modules can be fully or partially integrated together, or they can be implemented independently. The processing element mentioned here can be an integrated circuit with signal processing capabilities. In the implementation process, each step of the above method or each of the above modules can be completed through integrated logic circuits in the hardware of the processor element or through software instructions.

[0144] For example, these modules can be one or more integrated circuits configured to implement the above methods, such as one or more application-specific integrated circuits (ASICs), one or more digital signal processors (DSPs), or one or more field-programmable gate arrays (FPGAs). As another example, when a module is implemented using processing element scheduler code, the processing element can be a general-purpose processor, such as a central processing unit (CPU) or other processor capable of calling program code. Furthermore, these modules can be integrated together to implement a system-on-a-chip (SOC).

[0145] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, authentication terminal, or data center to another website, computer, authentication terminal, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as an authentication terminal or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk (SSD)).

[0146] For example, Figure 6 A schematic diagram of the structure of an electronic device provided in this application, such as... Figure 6 The device shown can be used to perform any of the authentication methods described in this application. In one embodiment, such as... Figure 6 The illustrated electronic device 1000 includes one or more processors 1001 and a memory 1002. The memory 1002 stores computer-executable instructions, and the processor 1001 can execute the computer-executable instructions stored in the memory 1002. When the computer-executable instructions are executed by the processor 1001, the processor 1001 implements any of the authentication methods described in the foregoing embodiments of this application.

[0147] In one embodiment, such as Figure 6 The electronic device 1000 shown also includes a communication interface 1003, through which the processor 1001 can communicate with other devices, such as sending and receiving data through the communication interface 1003.

[0148] In the above embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.

[0149] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.

[0150] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.

[0151] This application also provides a chip for executing instructions, the chip being used to execute any of the authentication methods described above in this application.

[0152] This application also provides a computer program product, including a computer program that, when executed, implements any of the authentication methods described above.

[0153] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed, can be used to implement any of the authentication methods described above in this application.

[0154] The aforementioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.

[0155] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in the device.

[0156] The division of units is merely a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.

[0157] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0158] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0159] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, a verification terminal, or a network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0160] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.

[0161] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.

Claims

1. An authentication method applied to a target device, the target device comprising at least one PUF module, characterized in that, The method includes: Send an authentication request to the verification end; Upon receiving an authentication instruction sent by the verification end based on the authentication request, the PUF response value generated by the at least one PUF module is obtained, and authentication feature data for characterizing the PUF response value is generated according to the first mapping algorithm; The authentication feature data is sent to the verification terminal, enabling the verification terminal to authenticate the target device based on the authentication feature data. The system receives authentication response data sent by the verification terminal and parses the authentication response data according to the second mapping algorithm to determine whether the identity authentication is successful. The authentication response data is used to characterize the identity authentication result of the target device and to prevent third parties from inferring whether the target device has been successfully authenticated, thus defending against network eavesdropping and AI model attacks. The step of parsing the authentication response data according to the second mapping algorithm to determine whether the identity authentication was successful includes: The authentication response data is parsed according to the second mapping algorithm to obtain feature data; the feature data includes reference data or random data. When the absolute value of the difference between the PUF response value and the feature data is less than a preset value, the identity authentication is determined to be successful. If the absolute value of the difference between the PUF response value and the feature data is greater than the preset value, the identity authentication is determined to be unsuccessful. The authentication is determined to be successful if the absolute value of the difference between the PUF response value and the feature data is equal to the preset value; or the authentication is determined to be unsuccessful if the absolute value of the difference between the PUF response value and the feature data is equal to the preset value.

2. The method according to claim 1, characterized in that, The target device stores the first mapping algorithm, or the target device stores multiple candidate first mapping algorithms, which are used to determine the first mapping algorithm; and / or, the target device stores the second mapping algorithm, or the target device stores multiple candidate second mapping algorithms, which are used to determine the second mapping algorithm; And / or, the second mapping algorithm is different from the first mapping algorithm, or the second mapping algorithm is the same as the first mapping algorithm; And / or, the first mapping algorithm includes a bounded function, and / or, the second mapping algorithm includes a bounded function.

3. The method according to claim 2, characterized in that, When the authentication indication includes first indication information of the first mapping algorithm, before generating authentication feature data for representing the PUF response value according to the first mapping algorithm, the method further includes: generating the first mapping algorithm according to the first indication information; or, determining the first mapping algorithm corresponding to the first indication information from at least one mapping algorithm stored in the target device. When the authentication indication includes second indication information of the second mapping algorithm, before parsing the authentication response data according to the second mapping algorithm, the method further includes: The second mapping algorithm is generated based on the second indication information; or, the second mapping algorithm corresponding to the second indication information is determined from at least one mapping algorithm stored in the target device.

4. An identity authentication method, applied at a verification end, characterized in that, The method includes: Upon receiving an authentication request from a target device, an authentication instruction is sent to the target device, wherein the target device includes at least one PUF module; The system receives authentication feature data sent by the target device, parses the authentication feature data according to the first mapping algorithm to obtain the PUF response value generated by the at least one PUF module, and determines the identity authentication result of the target device based on the comparison result of the PUF response value and the reference data. The second mapping algorithm generates authentication response data to characterize the authentication result, and prevents third parties from inferring whether the target device has been successfully authenticated. The authentication response data is sent to the target device, enabling the target device to determine whether the identity authentication was successful based on the authentication response data. The step of generating authentication response data to characterize the identity authentication result according to the second mapping algorithm includes: When the target device is successfully authenticated, the authentication response data is generated based on the reference data and the second mapping algorithm; When the target device authentication fails, the authentication response data is generated based on random data and the second mapping algorithm; wherein the absolute value of the difference between the random data and the reference data is greater than a preset value.

5. The method according to claim 4, characterized in that, The verification terminal stores the first mapping algorithm, or the verification terminal stores multiple candidate first mapping algorithms, wherein the multiple candidate first mapping algorithms are used to determine the first mapping algorithm; and / or, the verification terminal stores the second mapping algorithm, or the verification terminal stores multiple candidate second mapping algorithms, wherein the multiple candidate second mapping algorithms are used to determine the second mapping algorithm. And / or, the second mapping algorithm is different from the first mapping algorithm, or the second mapping algorithm is the same as the first mapping algorithm; And / or, the first mapping algorithm includes a bounded function, and / or, the second mapping algorithm includes a bounded function.

6. The method according to claim 4 or 5, characterized in that, The determination of the target device's authentication result based on the comparison result between the PUF response value and the reference data includes: When the absolute value of the difference between the PUF response value and the reference data is less than or equal to a preset value, the target device is determined to have successfully authenticated. If the absolute value of the difference between the PUF response value and the reference data is greater than the preset value, it is determined that the target device authentication is unsuccessful.

7. A target device, characterized in that, It can be used to perform the identity authentication method as described in any one of claims 1-3.

8. A verification terminal, characterized in that, It can be used to perform the authentication method as described in any one of claims 4-6.

9. A network system, characterized in that, include: Multiple target devices are used for authentication by the method described in any one of claims 1-3; The verification end is used to authenticate the plurality of target devices by means of the method described in any one of claims 4-6.

10. The network system according to claim 9, characterized in that, The multiple candidate first mapping algorithms stored in each of the target devices are different or the same, and / or the multiple candidate second mapping algorithms stored in each of the target devices are different or the same; Alternatively, the multiple target devices may share the multiple candidate first mapping algorithms, and / or the multiple candidate second mapping algorithms may be shared.

11. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1-6.

12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-6.

13. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method as described in any one of claims 1-6.

Citation Information

Patent Citations

  • Radio frequency device, authentication server and authentication method

    CN107493171A