Intelligent safety control and hierarchical fusing system and method based on PUF fingerprint identification

By using a PUF fingerprint recognition-based intelligent security control system, which generates a unique fingerprint for each device using a PUF chip and combines it with a tiered circuit breaker strategy, the system solves the problems of vulnerability to hacking and network dependence in device security control. It achieves unique device authentication, remote controllability, and multi-level security protection, ensuring the security and controllability of devices under different threat scenarios.

CN121530583APending Publication Date: 2026-02-13WEAPON EQUIP RES INST OF CHINA NAT WEAPON EQUIP GRP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511529870.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-24
Publication Date
2026-02-13

AI Technical Summary

Technical Problem

Existing equipment security control technologies are vulnerable to unauthorized operations, illegal disassembly, and cyberattacks, and are highly predictable due to their susceptibility to network restrictions. They also lack effective remote security control mechanisms, which threaten equipment security.

Method used

The system employs a PUF fingerprint recognition-based intelligent security control system, which combines a challenge-response mechanism and a tiered circuit breaker strategy. It generates a unique fingerprint for each device through a PUF chip, monitors the device status in real time, performs remote authentication, and executes tiered circuit breaker measures such as logical locking, function degradation, communication blocking, and physical self-destruction when a threat occurs.

Benefits of technology

It achieves unique device authentication, remote controllability, and anti-reverse engineering capabilities, providing multi-level security protection to ensure the security and controllability of the device under different threat scenarios and avoid losses caused by direct self-destruction.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121530583A_ABST
    Figure CN121530583A_ABST
Patent Text Reader

Abstract

The invention provides an intelligent security control and hierarchical fusing system and method based on PUF fingerprint identification, and belongs to the field of equipment security management, the system comprises a PUF chip, a challenge-response calculation module, a security management module, a remote server and a communication channel used for performing security data exchange between equipment and the remote server; when the equipment is started for the first time, the PUF chip generates a unique equipment fingerprint and sends the equipment fingerprint to the remote server, and the remote server stores the equipment fingerprint in a challenge-response pair database of the remote server; the safety management module monitors the equipment state, periodically sends the equipment state to the remote server, and executes an equipment safety strategy according to a control instruction of the remote server; when the device triggers a specific event, the device establishes communication with the remote server, the remote server sends a challenge signal to the device, and the challenge-response calculation module generates a response signal based on the physical characteristics of the device and returns the response signal to the remote server for comparison authentication.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of device security management, and particularly relates to an intelligent security control and hierarchical fuse system and method based on PUF fingerprint identification. BACKGROUND

[0002] When a device encounters unauthorized operation permission acquisition, illegal disassembly of device components, or unauthorized technical analysis, it may cause technical achievement leakage, interest damage, or user privacy risk. Therefore, it is urgent to establish a full-life-cycle device security management mechanism to achieve permission management or data protection mechanisms through technical innovation.

[0003] Currently, device security control technology mainly relies on cryptography, encryption chips, and remote management methods, but these methods still have many limitations. Traditional cryptography schemes (such as symmetric encryption and asymmetric encryption) can provide some security protection, but if the key is cracked or leaked, the security of the device will be severely threatened. Although encryption chips can improve the anti-tamper ability of the device, they can still be threatened by side-channel attacks, physical attacks, and other means. In addition, remote management schemes usually rely on servers and network connections, which may not work when the network is unstable or under network attack, resulting in the failure of the security mechanism.

[0004] To address the above problems, physical unclonable function (PUF) technology, as a new type of hardware security mechanism, provides a high-security device identity recognition and authentication method. PUF is based on the tiny process differences in the chip manufacturing process to generate unique fingerprint information, thus having the advantages of unclonability, unpredictability, and tamper resistance. This technology has been applied to identity verification, encryption key generation, chip anti-counterfeiting, and other fields, but there is still a lack of systematic solutions for remote security control of products.

[0005] Existing export products often lack effective remote security control mechanisms after leaving the factory, resulting in devices being illegally used, disassembled, tampered with, or reverse-engineered by non-authorized users, thus threatening the confidentiality of enterprise core technology. Current security methods mainly rely on traditional encryption algorithms, physical anti-disassembly structures, or remote management schemes, but these methods have problems such as being easily cracked, being limited by network conditions, or having high predictability, making it difficult to achieve true unclonability, tamper resistance, and high-security-level remote control. Therefore, there is an urgent need for a technical solution that can uniquely identify, remotely manage, and execute security fusing (including function restriction, disablement, or even physical self-destruction) of export products when necessary. SUMMARY

[0006] In view of this, the present application provides a kind of based on PUF fingerprint identification intelligent security control and grading fuse system, comprising: the PUF chip of being arranged in a device, challenge-response calculation module, security management module, communication interface, remote server and for the communication channel of safe data exchange between device and remote server; When the device is first enabled, the PUF chip generates a unique device fingerprint, and the generated device fingerprint is sent to the remote server via the communication interface through the communication channel for safe data exchange, and the remote server stores the received device fingerprint in the challenge-response pair database of the remote server; The security management module monitors the device state in real time, and sends the device state to the remote server via the communication interface through the communication channel for safe data exchange at regular intervals or when the device triggers a specific event; When the device triggers a specific event, the device and the remote server establish communication, and the remote server sends a challenge signal to the device;The challenge-response calculation module of the device generates a response signal based on its own physical characteristics, and returns the generated response signal to the remote server via the communication interface through the communication channel for safe data exchange;The remote server compares and authenticates the received response signal returned by the device with the challenge-response pair data in the database; When the comparison authentication fails, the remote server issues a control instruction to the security management module to execute the grading fuse safety policy of the device.

[0007] Further, the specific event is device startup or running a specific function.

[0008] Further, the security management module uses an AI anomaly detection algorithm to monitor the device state in real time, and identifies abnormal operation or illegal disassembly behavior.

[0009] Further, the comparison authentication specifically includes: the remote server judges whether the device is in a safe running state based on the device state, geographic location and network environment.

[0010] Further, the device security policy is a grading fuse policy based on the degree of device anomaly.

[0011] Further, the fuse policy includes: logical lock, function degradation, communication block and physical self-destruction.

[0012] Further, when the device completely loses the control of the remote server or enters an enemy environment, the physical self-destruction policy is triggered, which includes: Data erasure: erase all sensitive information stored in the device, which cannot be recovered; Circuit fuse: cause irreversible damage to the key circuits of the device by triggering the internal current overload protection mechanism of the device; Physical destruction: using embedded hot melt mechanism, destroy the PUF storage structure, make the device lose effect.

[0013] The application also provides an intelligent security control and hierarchical fuse method based on PUF fingerprint identification, which is realized by the system as described above, and the method comprises the following steps: Step 1, when the device triggers a specific event, the device establishes communication with the remote server, and the remote server sends a challenge signal to the device; Step 2, the challenge-response calculation module of the device generates a response signal based on its own physical characteristics, and returns the generated response signal to the remote server through the communication channel for secure data exchange via the communication interface; Step 3, the remote server compares and authenticates the received response signal returned by the device with the challenge-response pair data in the database; Step 4, when the comparison authentication fails, the remote server issues a control instruction to the security management module to execute the hierarchical fuse safety strategy of the device.

[0014] Further, before step 1, it also includes: when the device is first enabled, the PUF chip generates a unique device fingerprint, and sends the generated device fingerprint to the remote server through the communication channel for secure data exchange via the communication interface, and the remote server stores the received device fingerprint in the challenge-response pair database of the remote server.

[0015] Further, it also includes the step of: the security management module monitors the device state in real time, and sends the device state to the remote server through the communication channel for secure data exchange via the communication interface periodically or when the device triggers a specific event.

[0016] The application has the following technical effects: 1. Uniqueness and unclonability. The PUF fingerprint technology ensures that the identity information of each device is unique and unforgeable, which is more secure than traditional cryptography solutions.

[0017] 2. Remote controllability. Through the challenge-response mechanism and the remote server interaction, the security monitoring and remote management of the device are realized.

[0018] 3. Hierarchical fuse mechanism. It provides multi-level security protection to ensure that the device takes appropriate control measures in different security threat scenarios and avoids the loss caused by direct self-destruction.

[0019] 4. Anti-reverse engineering capability. The randomness and unpredictability of PUF technology, combined with the security fuse strategy, make it difficult for the device to be reverse analyzed or cloned. BRIEF DESCRIPTION OF DRAWINGS

[0020] In order to more clearly illustrate the technical solutions in the specific embodiments of the present application, the drawings needed to be used in the description of the specific embodiments will be briefly introduced as follows. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can also be obtained by those skilled in the art without creative labor on the basis of these drawings.

[0021] Figure 1 The schematic diagram of the intelligent safety control and hierarchical fuse system architecture based on PUF fingerprint recognition of the embodiment of the present application is shown in the figure. Figure 2 The device safety fuse strategy schematic diagram of the embodiment of the present application is shown in the figure. Figure 3 The device self-destruction flowchart of the embodiment of the present application is shown in the figure. Figure 4 The flowchart of the intelligent safety control and hierarchical fuse method based on PUF fingerprint recognition of the embodiment of the present application is shown in the figure. Specific embodiments

[0022] In order to make the purpose, technical solutions and advantages of the embodiments of the present application more clear, the technical solutions in the embodiments of the present application will be described clearly and completely in the following with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0023] The present application provides an intelligent safety control and hierarchical fuse method based on physical unclonable function (PUF) fingerprint recognition. The unique identity of the device is generated by the PUF chip, and combined with the challenge-response mechanism (CRP), remote control and fuse strategy, the dynamic safety management of the export product is realized. The specific technical solutions are as follows: (1) PUF fingerprint generation and authentication. The PUF chip is integrated inside the device, and the unique PUF fingerprint is generated by the slight difference of the chip manufacturing process, and is used as the device identity. The challenge-response mechanism is used to authenticate the device, to ensure the unforgeability of its identity.

[0024] (2) Remote safety control mechanism. The device periodically or at a specific event trigger, sends the PUF fingerprint data to the remote server through the secure channel for identity verification. The remote server judges whether the device is in a safe running state based on the device state, geographical location, network environment and other factors.

[0025] (3) Hierarchical fuse strategy. Logical lock (first-level fuse): When detecting potential illegal use risks, lock part of the key functions such as communication and data transmission through remote command. Function degradation (second-level fuse): If the device state is further exacerbated, reduce the running ability of the device, such as reducing the processing speed, limiting part of the hardware function, etc. Communication blocking (third-level fuse): When the device may be maliciously disassembled or tampered with, completely cut off the communication ability, so that it cannot interact with the outside world. Physical self-destruction (fourth-level fuse): When the device falls into hostile forces or is under serious security threats, execute the final self-destruction measures such as erasing storage data, burning key circuits, etc., to ensure that technical secrets are not leaked.

[0026] (4) Security triggering mechanism. An AI-based anomaly detection algorithm is used to continuously monitor the device running state and identify abnormal operations or illegal disassembly behaviors. The device can still automatically execute the fuse measures according to the preset security strategy in the offline environment, avoiding dependence on network connection.

[0027] The application will be described in more detail by the following examples.

[0028] This embodiment provides a device security control system based on PUF (Physical Unclonable Function) technology, which can be used for the security management of foreign trade export products to prevent the device from being illegally tampered with or used for unintended purposes.

[0029] As shown in Figure 1 , the system mainly includes: 1) PUF device end (100): including PUF chip (not shown), challenge-response calculation module (not shown), security management unit and communication interface.

[0030] 2) Remote server (200): stores PUF device fingerprint data and challenge-response pair (CRP) database, and executes security strategy.

[0031] 3) Security management module (300): monitors the device state and sends the device state to the remote server regularly, and executes the fuse or self-destruction operation according to the instruction of the remote server.

[0032] 4) Communication channel (400): for secure data exchange between the device and the server.

[0033] When the device is first enabled, the PUF chip of the PUF device end generates a unique device fingerprint, which is stored in the CRP database of the server. After that, every time the device starts or runs a key function, the server sends a challenge signal (Cn) to the PUF device end, and the PUF device generates a response signal (Rn) based on its physical characteristics and returns it to the server for comparison and authentication.

[0034] As Figure 2 shown, to deal with abnormal behavior or illegal use of the device, the present application designs a set of hierarchical fuse strategy, including: 1) Normal operation (510): device authentication passes, in normal working state.

[0035] 2) First level fuse (520): the device detects slight abnormalities, such as short time unable to connect to the server or abnormal operation, limit some functions, such as shielding remote control or prohibiting data transmission.

[0036] 3) Second level fuse (530): the device detects high-risk behavior, such as abnormal communication mode or non-expected environment operation, further degrade the function, such as limit core computing module.

[0037] 4) Third level fuse (540): the device detects physical tampering attempt, such as disassembly, crack PUF chip, directly disable communication module, prevent the device continue to work.

[0038] 5) Fourth level fuse (550): the device detects serious security risks, such as completely lose remote server control or enter hostile environment, for example, the device detects illegal disassembly, tampering or long time out of touch, trigger the final self-destruction mechanism.

[0039] As Figure 3 shown, when the device enters the highest risk state (fourth level fuse), the following self-destruction measures will be executed: 1) Data erasure (710): erase all sensitive information stored in the device, so that it cannot be recovered.

[0040] 2) Circuit fuse (720): by triggering the internal current overload protection mechanism, the key circuit is damaged irreparably.

[0041] 3) Physical destruction (730): for example, using embedded hot melt mechanism, destroy PUF storage structure, so that the device loses its function.

[0042] In this way, the device completely loses its function, preventing information leakage or illegal use.

[0043] The embodiment of the present application is based on the secure communication between the PUF device end and the remote server, and realizes the remote management of the device, such as Figure 4 shown, the intelligent security control and hierarchical fuse method based on PUF fingerprint recognition of the embodiment of the present application includes: 1) The device end and the remote server establish a secure connection, and the remote server sends a challenge signal (Cn) to the PUF device; 2) The challenge-response calculation module of the PUF device generates a response signal (Rn) based on its internal process difference; 3) The PUF device returns Rn to the remote server for identity verification; 4) The remote server compares the CRP data in the database to confirm the legitimacy of the device identity; 5) If verified, the device identity is legitimate, the device operates normally; if verified, the device identity is not legitimate, the fuse mechanism is triggered.

[0044] As can be known from the above introduction, the intelligent safety control and hierarchical fuse method based on PUF fingerprint recognition proposed by the application provides unique authentication of the device through PUF technology, realizes remote monitoring and state evaluation of the device by combining challenge-response mechanism (CRP) and artificial intelligence analysis, and takes different levels of fuse measures such as logical locking, function degradation, communication blocking and physical self-destruction according to the safety level, so that when the device is illegally used, disassembled or faces a security threat, measures can be taken quickly to ensure the safety and controllability of the product. This scheme is particularly suitable for high-security export products such as unmanned aerial vehicles, communication base stations, military equipment and intelligent terminals, effectively preventing the product from being used by hostile forces or key technology being leaked, and providing a new technical solution for the safety management of export products.

[0045] Please note that the technical features of the above embodiments can be combined in any way. In order to make the description simple, all possible combinations of the technical features in the above embodiments are not described, however, as long as the combination of the technical features does not exist contradictory, it should be considered as the scope of the description. The above embodiments only express several embodiments of the application, and the description is more specific and detailed, but it should not be interpreted as a limitation on the scope of the patent. It should be noted that for those skilled in the art, without departing from the concept of the application, some modifications and improvements can be made, which are all within the scope of the application. Therefore, the scope of the patent of the application should be subject to the appended claims.

Claims

1. An intelligent security control and hierarchical fusing system based on PUF fingerprint recognition, characterized in that, The system comprises a PUF chip, a challenge-response calculation module, a security management module, a communication interface, a remote server and a communication channel for secure data exchange between the device and the remote server, which are arranged inside the device. When the device is first enabled, the PUF chip generates a unique device fingerprint, and sends the generated device fingerprint to the remote server through the communication channel for secure data exchange via the communication interface; the remote server stores the received device fingerprint in the challenge-response pair database of the remote server. The security management module monitors the device state in real time, and sends the device state to the remote server through the communication channel for secure data exchange via the communication interface at regular intervals or when the device triggers a specific event. When the device triggers a specific event, the device establishes communication with the remote server, and the remote server sends a challenge signal to the device; the challenge-response calculation module of the device generates a response signal based on its own physical characteristics, and returns the generated response signal to the remote server through the communication channel for secure data exchange via the communication interface; the remote server compares and authenticates the received response signal returned by the device with the challenge-response pair data in the database. When the comparison authentication fails, the remote server issues a control instruction to the security management module to execute the hierarchical fuse safety policy of the device.

2. The system of claim 1, wherein, The specific event is the start of the device or the running of a specific function.

3. The system of claim 1, wherein, The security management module uses an AI anomaly detection algorithm to monitor the device state in real time, and identifies abnormal operations or illegal disassembly behaviors.

4. The system of claim 1, wherein, The comparison authentication specifically comprises: the remote server judges whether the device is in a safe running state based on the device state, geographical location and network environment.

5. The system of claim 1, wherein, The device safety policy is a hierarchical fuse policy based on the degree of device abnormality.

6. The system of claim 5, wherein, The fuse policy includes: logical locking, function degradation, communication blocking and physical self-destruction.

7. The system of claim 6, wherein, The physical self-destruction policy is triggered when the device completely loses the control of the remote server or enters an enemy environment, and the physical self-destruction policy includes: Data erasure: erasing all sensitive information stored in the device, which cannot be recovered; Circuit fuse: causing irreversible damage to the key circuits of the device by triggering the current overload protection mechanism inside the device; Physical destruction: using embedded hot melting mechanism to destroy the PUF storage structure, so that the device loses its function.

8. A method for intelligent security control and hierarchical fusing based on PUF fingerprinting, implemented by the system of any one of claims 1-7, characterized in that, The method comprises: Step 1: when the device triggers a specific event, the device establishes communication with the remote server, and the remote server sends a challenge signal to the device; Step 2: the challenge-response calculation module of the device generates a response signal based on its own physical characteristics, and returns the generated response signal to the remote server through the communication channel for secure data exchange via the communication interface; Step 3: the remote server compares and authenticates the received response signal returned by the device with the challenge-response pair data in the database; Step 4: when the comparison authentication fails, the remote server issues a control instruction to the security management module to execute the hierarchical fuse safety policy of the device.

9. The method of claim 8, wherein, Further comprising before step 1 : When the device is first enabled, the PUF chip generates a unique device fingerprint and sends the generated device fingerprint via the communication interface over the communication channel for secure data exchange to a remote server, the remote server stores the received device fingerprint in a challenge-response pair database of the remote server.

10. The method of claim 8, wherein, Further comprising the step: The security management module monitors the device status in real time, sends the device status via the communication interface over the communication channel for secure data exchange to the remote server periodically or when the device triggers a specific event.