A two-way identity authentication system and method for an internet of things terminal

CN122226301BActive Publication Date: 2026-09-11CHENGDU QINCHUAN IOT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202610702590.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-05-21
Publication Date
2026-09-11
Estimated Expiration
2046-05-21

AI Technical Summary

Technical Problem

[0007]本发明旨在解决现有物联网身份验证方案中存在的终端计算资源受限与防御强度需求失衡、缺乏完备双向认证逻辑以及在复杂信道环境下鲁棒性不足等技术问题,从而提供一种用于物联网终端的双向身份验证系统及方法

Benefits of technology

[0023]其一,本发明通过在终端侧引入物理不可克隆函数(PUF)单元,将身份验证的信任根从传统的软件层面软件密钥锚定到了硬件物理层面的器件差异性上。由于PUF产生的硬件指纹具有不可预测、不可克隆及易失性特点,即便终端设备被攻击者获取并进行物理拆解,也无法通过常规手段读取出其核心身份信息,极大增强了终端在无人值守环境下的物理抗克隆能力,解决了现有技术中PSK方案易被暴力破解的技术痛点。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122226301B_ABST
    Figure CN122226301B_ABST
Patent Text Reader

Abstract

The application discloses a kind of two-way identity authentication system and method for Internet of Things terminal, solve terminal resource limited and defense intensity imbalance, lack of two-way authentication logic and so on.The system includes integrated with SRAM-PUF unit terminal node, edge side auxiliary module and centralization server.The method includes: using PUF to generate hardware fingerprint as key entropy source, combined with improved elliptic curve implicit certificate and three-stage challenge-response logic.The above scheme is used, the trust root is anchored to the physical layer device difference, reduces the authentication communication overhead and computing load, while realizing high-strength two-way security guarantee, effectively improve the ability of terminal anti-physical cloning and resist man-in-the-middle attack.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security, and in particular to a two-way authentication system and method for Internet of Things (IoT) terminals. Background Technology

[0002] With the widespread adoption of 5G and the deep integration of the Internet of Things (IoT) into vertical sectors such as industrial control, smart homes, smart cities, and telemedicine, the IoT has evolved from a simple sensor network into the infrastructure supporting the digital economy. In this process, IoT terminals, as the final link in the physical world's data collection and command execution, have their access security directly impacting the overall system's stable operation. To ensure the authenticity of data and the legitimacy of commands, authentication mechanisms, as the first line of defense for network security, remain a core research topic in this field.

[0003] In existing technological systems, mainstream authentication schemes are typically based on pre-shared keys (PSK) or lightweight asymmetric encryption algorithms. In early application scenarios, these schemes could meet the basic requirements for device access to a certain extent. Specifically, the system pre-implants the same key between the terminal and the central server, or uses Public Key Infrastructure (PKI) to distribute digital certificates to the terminal. When making an access request, the terminal sends a specific encrypted sequence or digital signature to the server, which then performs a consistency verification based on the credentials stored in its database. This one-way authentication logic has high execution efficiency in relatively closed, simple topology static network environments, effectively solving the problem of unauthorized devices blindly accessing the network and reducing the initial construction cost of the system.

[0004] However, as IoT applications become increasingly complex, dynamic, and decentralized, the demands on authentication in these environments far exceed previous requirements, highlighting the inherent limitations of existing technologies. A deeper analysis of their technical principles reveals a profound and irreconcilable technical contradiction in addressing modern network threats: a severe imbalance between limited terminal computing resources and ever-growing demands for robust defenses. IoT terminals, especially large-scale low-power nodes distributed at the edge, often face strict limitations in computing power, storage space, and energy supply, making it difficult to support complex certificate chain verification or lengthy modular exponentiation operations. In this context, introducing heavy encryption protocols to balance security leads to severe authentication delays and may even rapidly deplete terminal power due to excessive computational overhead, causing frequent network node outages. Conversely, simplifying authentication logic to pursue energy efficiency exposes the system to extremely high security risks.

[0005] The most serious issue is that existing technologies largely focus on "one-way monitoring" of terminals by servers, neglecting the terminal's authentication of the server or gateway. In actual deployments, attackers often exploit the openness of wireless channels to induce terminals to connect to unauthorized control nodes by spoofing base stations, malicious gateways, or launching man-in-the-middle attacks. Due to the lack of a robust two-way authentication mechanism, terminals cannot effectively verify the authenticity of higher-level entities, making them highly susceptible to data leakage or malicious hijacking to execute incorrect commands. Such security risks are unacceptable in scenarios involving life safety or major industrial production. Furthermore, existing authentication protocols often lack robust synchronization mechanisms and fault tolerance in weak network environments or with fluctuating channels. Once the handshake process is blocked, the terminal becomes trapped in a loop of reconnection attempts, which not only exacerbates channel congestion but also exposes more communication characteristics, providing opportunities for side-channel attacks.

[0006] In summary, existing IoT authentication solutions generally face a dilemma in balancing security, real-time performance, and low power consumption when handling massive numbers of heterogeneous terminals. How to build a robust, resilient, and peer-to-peer authentication system that can defend against man-in-the-middle attacks and supports end-to-end authentication without significantly increasing terminal hardware costs and computational burden has become a deep-seated technical challenge in the field of IoT security. Therefore, developing a highly robust two-way authentication system and method that can adapt to resource-constrained environments, addressing the core pain points of existing technologies such as the lack of two-way authentication logic and the mismatch between protocol overhead and security strength, has become a key challenge for those skilled in the art. Summary of the Invention

[0007] This invention aims to address the technical problems existing in current IoT authentication schemes, such as the imbalance between limited terminal computing resources and defense strength requirements, the lack of complete two-way authentication logic, and insufficient robustness in complex channel environments, thereby providing a two-way authentication system and method for IoT terminals.

[0008] To achieve the above objectives, this invention provides a two-way authentication system for IoT terminals. The system comprises an IoT terminal node, an edge-side authentication auxiliary module, and a centralized identity management server. The IoT terminal node integrates a hardware secure execution environment, which includes a physically unclonable function unit, a lightweight cryptographic operator accelerator, and a non-volatile secure storage area. The physically unclonable function unit employs an SRAM-PUF architecture based on the initial state differences of static random access memory at power-on, used to generate a unique device hardware fingerprint and serve as the entropy source for subsequent key derivation. The lightweight cryptographic operator accelerator is configured to execute an Edwards curve-based digital signature algorithm and a hash function-based message authentication code operation. The selected elliptic curve parameters ensure that the number of iterations for dot product operations does not exceed 256 at 128-bit security strength. The non-volatile secure storage area is used to store the global root public key distributed by the centralized identity management server and the terminal's own implicit certificate identifier.

[0009] The centralized identity management server, acting as the holder of the root of trust, incorporates a high-performance cryptographic coprocessing matrix at its hardware level to handle large-scale concurrent certificate issuance and revocation requests. Internally, the server houses an attribute-based access control database that records the hardware feature hash values ​​of all legitimate terminal nodes and their corresponding business permission levels. The centralized identity management server establishes a long-lived connection with the edge-side authentication assistance module via a pre-defined transport layer security protocol, enabling real-time issuance and synchronization of authentication tokens.

[0010] The edge-side authentication assistance module is deployed at the access gateway close to the terminal. Its main function is to alleviate the communication pressure on the centralized identity management server and utilize its stronger computing power compared to the terminal for preliminary identity filtering. The edge-side authentication assistance module maintains a dynamically updated temporary challenge sequence pool. Each challenge value in this pool is associated with a strict timestamp threshold to prevent replay attacks.

[0011] In a preferred embodiment of the present invention, the two-way authentication process between the IoT terminal node and the centralized identity management server is implemented based on an improved elliptic curve implicit certificate mechanism. Specifically, during the device registration phase, the IoT terminal node generates an original stimulus-response pair through its internal physically non-clonable function unit and extracts a 256-bit device private key seed. The terminal uses the private key seed to calculate the corresponding public key component in a lightweight cryptographic operator accelerator and sends it along with the device's unique physical identifier to the centralized identity management server. Upon receiving the registration request, the centralized identity management server first verifies the legitimacy of the device's unique physical identifier, and then uses its own server private key and the received public key component to perform algebraic synthesis to generate an implicit certificate containing the terminal's identity information and public key information. The implicit certificate does not contain an explicit digital signature, but rather embeds the public key through a specific mathematical relationship, and its mathematical expression is: Terminal Valid Public Key ,in This is the content of the implicit certificate. For collision-resistant hash functions, This is the server's public key.

[0012] Furthermore, the system described in this invention employs a three-stage dynamic challenge-response logic when performing two-way authentication. The first stage is the access request stage initiated by the terminal, where the IoT terminal node generates a 128-bit random number. And combined with the current system timestamp and implicit certificate identifier Construct access request vector Then Send to the edge-side authentication assistance module. The edge-side authentication assistance module receives the data. After that, first check Check if the deviation from the current gateway time is within a preset 500 milliseconds range. If it exceeds this range, the request is considered invalid and immediately blocked; if it is within the range, then... Forwarded to the centralized identity management server.

[0013] The second stage is the server-to-terminal one-way authentication stage, in which the centralized identity management server retrieves data from the database. The corresponding terminal public key parameter generates a random challenge value. And use elliptic curve dot product to calculate the verification value. ,in This serves as the base point for the curve. Subsequently, the server calculates the message authentication code. ,in Based on Derived temporary session key. The server will contain... , and the server's own digital signature The response message is sent to the terminal. After receiving the response message, the terminal first verifies the information using the pre-stored global root public key. The legitimacy of the terminal is verified to confirm the server's identity, completing the first dimension of identity verification; then, the terminal uses its private key to... calculate ,like With received If they are completely identical, it is determined that the server possesses valid session negotiation parameters.

[0014] The third stage is the reverse identity verification stage between the terminal and the server. The IoT terminal node uses the hardware mask generated by its physical non-cloning function unit to verify the identity of the server. Perform a nonlinear transformation to generate the terminal response value. And reconstruct containing The centralized identity management server receives the confirmation message and then uses the stored hash value of the terminal's hardware characteristics to perform a reverse reconstruction. If the reconstruction result matches the sent message... If the preset homomorphic mapping relationship is satisfied, the authenticity of the terminal's identity will be confirmed.

[0015] The present invention also provides a two-way authentication method for IoT terminals, the method being executed based on the aforementioned two-way authentication system, specifically including the following steps:

[0016] Step 1: Initialization and Offline Registration. The centralized identity management server generates the system's root key pair and elliptic curve domain parameters. Before leaving the factory, each IoT terminal node generates a set of baseline response values ​​through a physically non-cloning function unit. These response values ​​are then processed using a fuzzy extraction algorithm and stored as the terminal's root secret in a secure isolated area. The terminal sends the extracted public parameters to the server to complete registration.

[0017] Step Two: Access Request and Environmental Awareness. When an IoT terminal node attempts to access the network, it first senses the quality parameters of the current physical channel, including signal-to-noise ratio and multipath latency. If the channel quality is lower than a preset threshold, the terminal automatically switches to low-entropy authentication mode, reducing the random number length to shorten the message length. The terminal constructs a request message containing a temporary identifier and a current high-precision timestamp, and scrambles the message using a pre-shared initial protection key before sending it to the edge-side authentication assistance module. The edge-side authentication assistance module performs traffic feature analysis on the received request message, eliminating potential denial-of-service attack packets by detecting the message's transmission frequency and the consistency of the data packet sequence. Messages that pass verification are appended with the edge node's geographical location tag and latency compensation factor, and then uploaded to the centralized identity management server.

[0018] Step 3: Server-side Identity Reconstruction and Challenge Distribution. The centralized identity management server extracts the corresponding terminal static feature vector from the encrypted database based on the temporary identifier in the request message. The server activates a true random number generator to produce multiple sets of challenge vectors and constructs an authentication operator with quantum attack resistance potential using the error learning problem (LWE) under lattice cryptography. The server merges the constructed challenge payload with its own implicit certificate, encapsulates it into a response frame, and sends it out.

[0019] Step Four: Terminal-Side Hardware Fingerprint Extraction and Bidirectional Comparison. After receiving the response frame from the server, the IoT terminal node wakes up the physically unclonable function unit in the hardware secure execution environment (HMI). It then maps the challenge vector issued by the server to the current environmental entropy value, generating a unique real-time hardware fingerprint. The terminal first verifies the integrity and non-repudiation of the content sent by the server by calculating the public key corresponding to the server's implicit certificate. Subsequently, the terminal compares the generated real-time hardware fingerprint bit by bit with a pre-stored reference value. The comparison process uses a constant-time algorithm to avoid timing attacks.

[0020] Step 5: Session Key Derivation and Connection Establishment. After successful bidirectional verification, the IoT terminal node and the centralized identity management server synchronously initiate the Key Derivation Function (KDF). The derivation process incorporates the random numbers exchanged in the preceding steps. Server challenge value And the internal variables generated by physically unclonable functions. The final generated session key serves as the symmetric key for subsequent application-layer data encryption.

[0021] Step Six: Authentication Status Maintenance and Dynamic Re-authentication. During communication after the connection is established, the system initiates a heartbeat monitoring mechanism. The centralized identity management server periodically sends short random challenges to the terminal, requiring the terminal to respond with a counter value encrypted based on the current session key within a specified calculation period. If the terminal responds with an error or times out, the system immediately revokes the terminal's access authorization and triggers an alarm process.

[0022] The beneficial effects of this invention are:

[0023] Firstly, this invention introduces a Physically Unclonable Function (PUF) unit on the terminal side, anchoring the root of trust for authentication from the traditional software-level software key to the device differences at the hardware physical level. Because the hardware fingerprint generated by the PUF is unpredictable, unclonable, and volatile, even if an attacker obtains and physically disassembles the terminal device, its core identity information cannot be read through conventional means. This greatly enhances the terminal's physical anti-cloning capability in unattended environments and solves the technical pain point of existing PSK schemes being easily cracked by brute force.

[0024] Secondly, the Elliptic Curve Implicit Certificate (ECQV) mechanism employed in this invention significantly reduces communication overhead and computational load during the authentication process. Compared to the traditional X.509 certificate system, implicit certificates do not require lengthy CA digital signatures, reducing certificate length to less than 40 bytes. Furthermore, it eliminates complex hash comparisons and recursive certificate chain verification in public key recovery and verification rings. This improvement enables resource-constrained IoT nodes to complete high-strength asymmetric encryption operations within milliseconds, effectively balancing the conflict between security strength and processing latency, and avoiding abnormal fluctuations in terminal power consumption caused by excessively long authentication processes.

[0025] Third, the three-stage bidirectional authentication logic constructed in this invention completely overcomes the shortcomings of existing one-way authentication schemes in defending against man-in-the-middle attacks. By having the server and terminal act as challengers and responders to each other, it ensures that both parties can verify each other's legitimacy in real time. In particular, after introducing the pre-verification mechanism of the edge-side authentication auxiliary module, the system can effectively intercept illegal attack traffic at the network edge, reducing the load pressure on the central server. At the same time, the joint verification mechanism based on timestamps and random numbers provides the system with absolute immunity to replay attacks.

[0026] Fourth, the solution of this invention possesses extremely high environmental adaptability and robustness. By incorporating channel quality awareness and adaptive adjustment algorithms into the authentication process, the system can dynamically optimize the message structure in weak network environments, reducing the probability of handshake failure. Furthermore, the dynamic key derivation mechanism based on hardware PUF generation ensures that each session's key has an independent entropy source, achieving physical-level "one key, one password." Even if individual session keys are leaked, it will not threaten the security of the terminal's root key or the confidentiality of subsequent communications.

[0027] In summary, the system and method described in this invention achieve telecom-grade two-way identity security while ensuring extremely low resource consumption, providing a solid security foundation for the interconnection of large-scale heterogeneous IoT terminals. It has significant promotional value and practical engineering significance in high-reliability application fields such as smart industrial control and critical infrastructure monitoring. Attached Figure Description

[0028] Figure 1 This is a schematic diagram of the structure of a two-way authentication system for an Internet of Things (IoT) terminal according to an embodiment of the present invention;

[0029] Figure 2 This is a schematic diagram of the internal structure of an IoT terminal node in an embodiment of the present invention;

[0030] Figure 3 This is a flowchart illustrating a two-way authentication method for an IoT terminal according to an embodiment of the present invention.

[0031] The attached diagram is labeled as follows: 1. IoT terminal node; 2. Edge-side authentication auxiliary module; 3. Centralized identity management server; 4. Hardware secure execution environment; 5. Physically unclonable function unit; 6. Lightweight cryptographic operator accelerator; 7. Non-volatile secure storage area; 8. High-performance cryptographic coprocessing matrix; 9. Attribute-based access control database; 10. Temporary challenge sequence pool. Detailed Implementation

[0032] The present invention will be further described below with reference to the accompanying drawings and specific embodiments. The illustrative embodiments and descriptions herein are used to explain the present invention, but are not intended to limit the present invention.

[0033] like Figure 1-3 As shown, the two-way authentication system for IoT terminals described in this invention consists of three core physical entities: an IoT terminal node 1, an edge-side authentication auxiliary module 2, and a centralized identity management server 3. The IoT terminal node 1 serves as the carrier of the perception and execution layers, and integrates a highly integrated hardware secure execution environment 4. This hardware secure execution environment 4 achieves physical isolation at the underlying hardware logic level, ensuring that the processing of sensitive data is not interfered with by the instruction set of insecure areas. Inside the hardware secure execution environment 4, a physically unclonable function unit 5 acts as the generator of the root identity, employing an SRAM-PUF architecture based on the initial state differences of static random access memory at power-on. Specifically, this physically unclonable function unit 5 utilizes the minute random fluctuations in the transistor threshold voltage during CMOS process technology, ensuring that each SRAM cell exhibits a definite zero-state or one-state distribution upon initial power-on. Experimental tests show that, under a standard 25-degree Celsius environment, the average inter-chip Hamming distance distribution of the 256-bit response value generated by this physically unclonable function unit 5 is 0.498, demonstrating extremely strong individual uniqueness.

[0034] Furthermore, the IoT terminal node 1 is configured with a lightweight cryptographic operator accelerator 6. This accelerator is optimized at the logic gate level for resource-constrained microcontrollers, and its core operators include an Edwards curve-based digital signature algorithm (EdDSA) and a message authentication code operation based on a hash function. In a specific embodiment of the present invention, the Ed25519 curve is selected as the encryption basis, and its curve equation is defined as... Operating in the prime number field Above. The lightweight cryptographic operator accelerator 6, when processing 256-point multiplication operations, significantly reduces peak power consumption by employing a combined base-point pre-computation and sliding window method, keeping the typical computation loop count below 256. The accompanying non-volatile secure storage area 7 uses physically masked flash memory to persistently store the global root public key distributed by the centralized identity management server 3 and the terminal's own implicit certificate identifier. This area has an anti-tamper self-destruct mechanism; sensitive data will be immediately erased upon detecting abnormal encapsulation voltage or clock glitches.

[0035] The centralized identity management server 3 acts as the trust anchor in the system. Its hardware layer is equipped with a high-performance cryptographic coprocessing matrix 8, composed of multiple FPGA chips connected in parallel, capable of supporting over 100,000 ECC public key recovery operations per second. The attribute-based access control database 9 built inside the server not only stores terminal identifiers but also stores, in encrypted form, the reference feature vectors reported by each terminal's physical non-cloning function unit 5 during the registration phase. The centralized identity management server 3 maintains a persistent connection with the edge-side authentication assistance module 2 via a 10 Gigabit Ethernet interface, employing the TLS 1.3 protocol at the transport layer and enforcing two-way authentication.

[0036] The edge-side authentication assistance module 2 is deployed at the access gateway layer close to the IoT terminal node 1. This module internally maintains a temporary challenge sequence pool 10 with a capacity of 1024 entries. Each challenge value... All are generated by a hardware random number generator and are associated with a strict 500-millisecond time-to-live (TTL). The edge-side authentication assistance module 2 can identify and filter illegal format identity request packets in real time by performing deep traffic fingerprint analysis on uplink packets, thereby intercepting potential denial-of-service attack risks at the edge and avoiding impacting the computing resources of the centralized identity management server 3.

[0037] The two-way authentication method for IoT terminals described in this invention begins its complete engineering implementation process with the initialization and offline registration phase. In this phase, the centralized identity management server 3 first generates global parameters for the system, including the selected elliptic curve base points. Subgroup order n and the server's own root private key With public key In the pre-shipment solidification process of IoT terminal node 1, the physically unclonable function unit 5 undergoes 20 consecutive power-on tests under controlled conditions to extract stable response bits as the golden sequence. Subsequently, the corresponding auxiliary data (Helper Data) is generated using the BCH error correction algorithm. This auxiliary data is stored in the non-volatile secure storage area 7 and is used to correct bit flips caused by temperature drift or power supply noise during subsequent operation. The terminal transmits the derived public key component through a secure channel. The certificate is sent to the centralized identity management server 3, which generates an implicit certificate based on the improved elliptic curve implicit certificate mechanism. The design of this implicit certificate follows... The algebraic relation, where the hash function The SHA-3 256 algorithm is selected to achieve tight coupling between the public key and identity information.

[0038] When IoT terminal node 1 requests network access, it enters the access request and environment awareness phase. The terminal's internal sensors collect current physical channel parameters in real time. If the signal-to-noise ratio of the current environment is detected to be below 12dB, the terminal will automatically trigger a low-entropy authentication mode. In this mode, a random number... The length of the access request vector was dynamically reduced from 128 bits to 80 bits to reduce the probability of radio frame fragmentation. middle, A synchronous clock stamp with microsecond-level precision is used. This vector is pre-verified by the edge-side authentication assistance module 2. The edge-side module performs window filtering with a tolerance of 500 milliseconds by comparing the current system timestamp. If the verification passes, the edge-side module appends a 16-bit geographic tag derived from its own geographic location coordinates to the message and forwards it along with the original request to the centralized identity management server 3.

[0039] During the server-side identity reconstruction and challenge distribution phase, the centralized identity management server 3 retrieves the identity from the attribute-based access control database 9. The static features of the matching. To address potential future threats from quantum computing, the server incorporates a lattice-based error learning problem (LWE) operator when generating challenge values. Specifically, the server constructs a matrix... and an error vector ,calculate .Should Combinations are distributed to the endpoint as part of the challenge load. This leverages the fact that lattice problems are difficult to solve in polynomial time, adding a quantum-resistant security dimension to the authentication process.

[0040] Subsequently, IoT terminal node 1 enters the hardware fingerprint extraction and two-way comparison stage. The hardware secure execution environment 4 wakes up the physically unclonable function unit 5, and, combined with auxiliary data read from the non-volatile secure storage area 7, reconstructs the high-entropy internal private key. The terminal uses this private key to perform public key recovery operations, calculates the server's current valid public key, and verifies the implicit certificate. The validity of the public key is verified. If public key recovery fails, the terminal will immediately suspend all external communications. After authentication with the server, the terminal uses the current environmental entropy value to verify the validity of the public key issued by the server. The vector is subjected to nonlinear perturbation to generate the terminal response value. The comparison process strictly follows a constant-time algorithm, meaning that regardless of changes in the input bitstream, the power consumption and time consumed by the computing unit remain consistent, thus eliminating the possibility of key-side channel attacks through power analysis at the physical layer.

[0041] After the two-way comparison confirms that there are no errors, the system enters the session key derivation and connection establishment phase. IoT terminal node 1 and centralized identity management server 3 synchronously call the HMAC-based key derivation function (HKDF). The input entropy source for the derivation process consists of three parts: terminal random numbers... Server challenge value And the hardware mask generated by physically unclonable function unit 5. The final derived 256-bit session key. The AES-GCM module, loaded into the lightweight cryptographic operator accelerator 6, is used for symmetric encryption of all subsequent business data. To maintain authentication, the system employs a heartbeat monitoring mechanism with a 60-second interval. The centralized identity management server 3 periodically issues short, random challenges, requiring the terminal to return a response based on... An encrypted, monotonically increasing counter value. If the counter value is discontinuous or the feedback times out, the server will determine that the terminal has been hijacked and automatically identify its implicit certificate. Add to the Certificate Revocation List (CRL).

[0042] To further quantify and demonstrate the superiority of the system and method described in this invention, this embodiment sets up a specific experimental environment for testing and verification. The experiment selected 500 typical IoT terminal nodes as test samples. These nodes use an ARM Cortex-M4 core and operate at a clock speed of 80MHz.

[0043] [Example]

[0044] This invention employs the aforementioned three-stage two-way authentication logic. The 256-bit fingerprint generated by the physically unclonable function unit 5 serves as the core key material. The implicit certificate length is fixed at 42 bytes. A smart gateway with primary filtering capabilities is deployed at the edge. The verification process uses an improved elliptic curve algorithm, with the dot product operation taking approximately 22 milliseconds.

[0045] [Comparative Example]

[0046] The comparison uses a TLS 1.2 one-way authentication scheme based on the traditional X.509 certificate system. The certificate length is 512 bytes, and it uses the standard RSA-2048 algorithm. The verification process involves a complete recursive verification of the certificate chain (including the CA root certificate, intermediate certificates, and device certificates).

[0047] The comparative data obtained from the experiment are shown in the table below:

[0048] Table 1: Comparison of performance parameters between embodiments of the present invention and comparative examples

[0049] Evaluation indicators Embodiments of the present invention Comparative Scheme (X.509+RSA) Improvement Amount / Optimization Ratio Initial authentication latency (ms) 48.5 312.4 84.47% (decreased) Single authentication communication overhead (Bytes) 128 1540 91.68% (decreased) Peak power consumption of the terminal (mW) 14.2 86.5 83.58% (decreased) Memory usage (Flash / RAM KB) Aug-32 256 / 64 87.5% (decreased) Anti-replay attack success rate (%) 100 94.2 5.8% (increase) Hardware fingerprint uniqueness bias (%) < 0.2 N / A (based on software key) Significant (safety) Resistance to physical disassembly and hacking Physical layer destruction Logic layer read risk Qualitative change (safety)

[0050] The data in Table 1 clearly demonstrates that this invention exhibits significant non-obvious improvements in several key engineering indicators. Regarding initial authentication latency, this invention reduces the total latency to 48.5 milliseconds by omitting lengthy certificate chain verification and employing an efficient Edwards curve dot product algorithm. In contrast, the comparative method, due to the need to handle large-scale RSA exponentiation calculations and multiple handshake interactions, suffers from a latency as high as 312.4 milliseconds, which often leads to connection timeouts in high-speed mobile industrial IoT scenarios. In terms of communication overhead, this invention significantly compresses messages through an implicit certificate mechanism, requiring only 128 bytes for a single authentication. For terminals based on narrowband IoT protocols such as NB-IoT or LoRa, this significantly extends battery life and reduces bandwidth consumption.

[0051] Further analysis of security indicators reveals that, due to the introduction of physically unclonable function unit 5, the root identity feature of this invention exhibits "volatile" characteristics. In its static storage state, the root key is not present in plaintext form within the terminal; the keystream can only be reconstructed through hardware activation at the moment of verification. This mechanism makes this invention highly resilient to side-channel attacks and physical probing. In contrast, the software key in the comparative scheme is stored in Flash memory; even with encryption, it still faces the risk of being fully extracted by attackers using physical methods such as a slice microscope.

[0052] In actual simulation tests of complex channel environments, the adaptive environment awareness mechanism described in this invention demonstrated excellent robustness. When simulated multipath fading caused the packet loss rate to rise to 15%, this invention, by switching to a low-entropy authentication mode, maintained a handshake success rate above 98%. In contrast, the comparative scheme, due to excessively large packets, experienced frequent retransmissions at the same packet loss rate, leading to an exponential increase in the authentication cycle and ultimately a success rate below 72%. This further demonstrates the engineering advantages of this invention in addressing the imbalance between limited terminal computing resources and defense strength requirements.

[0053] In summary, the two-way authentication system and method for IoT terminals described in this invention constructs a defense-in-depth system at the underlying architecture through the organic collaboration of the hardware secure execution environment 4, the physically unclonable function unit 5, and the edge-side authentication auxiliary module 2. It not only solves the completeness problem of two-way authentication through a three-stage dynamic challenge-response mechanism in mathematical logic, but also achieves a dual leap in performance and security through optimized cryptographic operator accelerator 6 and the introduction of an implicit certificate mechanism in engineering implementation. The technical solution provided by this invention not only covers the topological connections of the system architecture, but also verifies its efficiency and reliability in practical application scenarios through specific parameter specifications and comparative data, providing a highly operable engineering blueprint for the standardization of IoT security.

[0054] Furthermore, the system architecture described in this invention exhibits excellent scalability. In larger-scale deployment environments, the centralized identity management server 3 can be horizontally scaled through a distributed cluster, while the edge authentication auxiliary module 2 can be embedded into the MEC (Multi-access Edge Computing) nodes of 5G base stations, leveraging stronger edge computing power to further distribute the global authentication pressure. This layered and decoupled design ensures that the system can smoothly evolve from thousands to hundreds of millions of terminals, fully meeting the identity governance needs of the future Internet of Things era. In subsequent optimized versions of this invention, for ultra-low-power sensor nodes, the physically unclonable function unit 5 can be further evolved into an architecture based on a ring oscillator (RO-PUF) to further reduce the surge current at power-on. Simultaneously, the encryption algorithm of the non-volatile secure storage area 7 can be dynamically adjusted according to national standards to ensure the system's compliance and forward-looking nature. Through the aforementioned comprehensive and multi-layered technical implementation path, this invention successfully solves the long-standing challenge of balancing security, efficiency, and cost in IoT identity verification.

[0055] The technical solutions of the present invention are not limited to the specific embodiments described above. Any technical modifications made in accordance with the technical solutions of the present invention fall within the protection scope of the present invention.

Claims

1. A two-way authentication system for Internet of Things (IoT) terminals, characterized in that, The system consists of an IoT terminal node (1), an edge authentication auxiliary module (2), and a centralized identity management server (3); The IoT terminal node (1) integrates a hardware secure execution environment (4), which achieves physical isolation at the underlying hardware logic level and includes a physically unclonable function unit (5), a lightweight cryptographic operator accelerator (6), and a non-volatile secure storage area (7). The physically unclonable function unit (5) adopts an SRAM-PUF architecture based on the initial state difference of static random access memory at power-on, which is used to generate a unique device hardware fingerprint and serve as the entropy source for key derivation. The lightweight cryptographic operator accelerator (6) is configured to execute a digital signature algorithm based on Edwards curves and a message authentication code operation based on hash functions. The non-volatile secure storage area (7) is used to solidify the global root public key distributed by the centralized identity management server (3) and the terminal's own implicit certificate identifier. The centralized identity management server (3) is the holder of the root of trust. Its hardware layer includes a high-performance cryptographic coprocessing matrix (8) for handling concurrent certificate issuance and revocation requests. The server has an attribute-based access control database (9) built inside, which records the hardware feature hash values ​​of all legitimate terminal nodes and their corresponding business permission levels. The edge authentication assistance module (2) is deployed at the access gateway close to the terminal to alleviate the communication pressure of the centralized identity management server (3) and perform preliminary identity filtering; the edge authentication assistance module (2) maintains a dynamically updated temporary challenge sequence pool (10), and each challenge value in the temporary challenge sequence pool (10) is associated with a preset timestamp threshold. The system employs a three-stage dynamic challenge-response logic when performing two-way authentication; The first stage is the access request stage initiated by the terminal, in which the IoT terminal node (1) generates a 128-bit random number. And combined with the current high-precision system timestamp and implicit certificate identifier Construct access request vector Send to the edge-side authentication assistance module (2); The second stage is the server-to-terminal one-way authentication stage, in which the centralized identity management server (3) retrieves data from the database... The corresponding terminal public key parameters are used to generate a random challenge value. And calculate the verification value ,in This serves as the base point for the curve; subsequently, the server utilizes a method based on... Derived temporary session key Calculate message authentication code and will contain , and server digital signature The response message is sent; The third stage is the terminal's reverse identity verification stage with the server. The IoT terminal node (1) uses the hardware mask generated by the physically unclonable function unit (5) to verify the identity of the server. Perform a nonlinear transformation to generate the terminal response value. The centralized identity management server (3) constructs a confirmation message and returns it to the server; the centralized identity management server (3) uses the stored hash value of the terminal hardware feature to perform reverse reconstruction and verifies the reconstruction result against the sent message. Does it satisfy the homomorphic mapping relationship? 2. The two-way authentication system for IoT terminals according to claim 1, characterized in that: The physically unclonable function unit (5) utilizes the random fluctuations of the transistor threshold voltage in the CMOS process to make the SRAM cell present a definite zero-state or one-state distribution when initially powered on, and the average value of the inter-chip Hamming distance distribution of the generated 256-bit response value is 0.498; the hardware secure execution environment (4) is also equipped with an error correction module, which uses the BCH error correction algorithm and pre-stored auxiliary data to perform stability repair on the response value generated by the physically unclonable function unit (5) to correct bit flips caused by ambient temperature drift or power supply noise.

3. The two-way authentication system for IoT terminals according to claim 1, characterized in that: The lightweight cryptographic operator accelerator (6) uses the Ed25519 curve as its Edwards curve, and its curve equation is defined as follows: Operating in the prime number field The lightweight cryptographic operator accelerator (6) optimizes the dot product operation logic by merging base point pre-computation and sliding window method, so that the number of loops for dot product operation does not exceed 256 times under 128-bit security strength; the non-volatile secure storage area (7) adopts flash memory space that has been physically masked and is equipped with anti-disassembly self-destruct circuit, which performs sensitive data erasure when abnormal package voltage or clock glitches are detected.

4. A two-way authentication system for an IoT terminal according to claim 1, characterized in that: The system is based on an improved elliptic curve implicit certificate mechanism for device registration and public key recovery. During the registration phase, the IoT terminal node (1) uses the physical non-cloning function unit (5) to generate an original incentive response pair, extracts a 256-bit device private key seed, and calculates the corresponding public key component to send to the server. The centralized identity management server (3) uses the server private key and the received public key component to perform algebraic synthesis to generate an implicit certificate.

5. A two-way authentication system for an IoT terminal according to claim 1, characterized in that: The edge authentication auxiliary module (2) is configured to execute access pre-verification logic; each challenge value in the temporary challenge sequence pool (10) is generated by a hardware random number generator, and the timestamp threshold of the life cycle is 500 milliseconds; the edge authentication auxiliary module (2) performs deep traffic fingerprint analysis on the messages uploaded by the IoT terminal node (1) to identify and filter identity request packets with illegal formats; after passing the verification, the edge authentication auxiliary module (2) appends a geographic label derived from its own geographic location coordinates to the message and forwards it to the centralized identity management server (3) along with the original request.

6. A two-way authentication system for an IoT terminal according to claim 1, characterized in that: Between the second and third phases, the centralized identity management server (3) introduces an error learning problem operator based on lattice cryptography when generating challenge values; the server constructs a matrix. and error vector and calculate ,Will The combination is distributed to the terminal as part of the challenge load to achieve an identity metric resistant to quantum attacks.

7. A two-way authentication method for Internet of Things (IoT) terminals, characterized in that, The method is implemented based on the two-way authentication system according to any one of claims 1 to 6, and specifically includes the following steps: Step 1: Initialization and offline registration; The centralized identity management server (3) generates the root key pair and elliptic curve domain parameters of the system; Before leaving the factory, each IoT terminal node (1) generates a set of baseline response values ​​through its physical non-clonable function unit (5), and stores them as root secrets in the non-volatile secure storage area (7) after extracting auxiliary data; The terminal sends the extracted public key parameters to the server to complete the implicit certificate registration; Step 2: Access Request and Environmental Awareness; When accessing the network, the IoT terminal node (1) senses the signal-to-noise ratio and multipath delay parameters of the current physical channel in real time; if the channel quality is lower than the preset threshold, the terminal automatically switches to low-entropy authentication mode and sends a random number. The length is reduced to reduce wireless frame fragmentation; the terminal constructs a request message containing a temporary identifier, a random number and a timestamp, and forwards it after pre-verification by the edge-side authentication assistance module (2); Step 3: Server-side identity reconstruction and challenge distribution; The centralized identity management server (3) extracts the terminal static feature vector according to the temporary identifier in the request message, starts a true random number generator to generate multiple sets of challenge vectors, and uses lattice cryptography to construct an authentication operator with the potential to resist quantum attacks, and encapsulates the challenge payload and the server's own implicit certificate into a response frame and sends it out. Step 4: Hardware fingerprint extraction and bidirectional comparison on the terminal side; After receiving the response frame, the IoT terminal node (1) wakes up the physical unclonable function unit (5) in the hardware secure execution environment (4), restores the internal private key by combining auxiliary data, and performs public key recovery operation to verify the legality of the server's implicit certificate; Subsequently, the terminal uses the current environmental entropy value to map the challenge vector, generates a real-time hardware fingerprint and compares it bit by bit with the reference value. The comparison process adopts a constant time algorithm. Step 5: Session key derivation and connection establishment; After the two-way comparison is successful, the IoT terminal node (1) and the centralized identity management server (3) synchronously start the HMAC-based key derivation function, introducing random numbers. Server challenge value The internal variables generated by physically unclonable functions are used as the source of input entropy to derive a symmetric session key for the encrypted transmission of subsequent application layer data.

8. A two-way authentication method for an IoT terminal according to claim 7, characterized in that: In step two, the edge-side authentication assistance module (2) performs traffic feature analysis on the received request message, and identifies and eliminates denial-of-service attack packets by detecting the consistency between the message sending frequency and the data packet sequence; in step four, the constant-time algorithm ensures that the power consumption and time consumption of the computing unit when processing different bit streams are consistent, so as to avoid side-channel timing attacks against the terminal hardware.

9. A two-way authentication method for an IoT terminal according to claim 7, characterized in that: After step five, step six is ​​also included: maintaining authentication status and dynamic re-authentication; the system starts the heartbeat monitoring mechanism, and the centralized identity management server (3) periodically sends short random challenges to the IoT terminal node (1), requiring the terminal to return a monotonically increasing counter value encrypted based on the current session key within a specified 20-millisecond calculation period; If the counter value returned by the terminal is discontinuous, incorrect, or the feedback times out, the centralized identity management server (3) immediately revokes the access authorization of the terminal and adds the corresponding implicit certificate identifier to the certificate revocation list.

Citation Information

Patent Citations

  • Cloud edge collaborative multi-factor identity authentication method and system for ubiquitous network

    CN120528614A

  • Data security transmission method based on ML-KEM algorithm and PUF

    CN121397538A