A Method and System for Automatic Synchronization of Measuring Instrument Certificate Information Based on Encrypted API

CN122741071APending Publication Date: 2026-09-11QINGDAO INST OF METROLOGY TECH +3
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611024029.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-10
Publication Date
2026-09-11

AI Technical Summary

Technical Problem

证书存储与器具物理身份存在严重的松耦合现象,数字证书往往仅通过逻辑标识与设备关联,导致合法证书可能被非法移植或篡改,产生身份冒用的安全风险

Benefits of technology

1.本发明通过构建物理不可克隆功能模块与动态噪声注入的协同体系,实现了计量器具物理实体身份与数字证书信息的原子级绑定,解决了现有技术中证书与器具身份脱节导致的滥用难题。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122741071A_ABST
    Figure CN122741071A_ABST
Patent Text Reader

Abstract

This invention relates to the field of data security technology and discloses a method and system for automatic synchronization of measuring instrument certificate information based on an encrypted API. The method includes: extracting a physical fingerprint as a root key using a physically unclonable functional module; generating a dynamic challenge value by collecting random physical quantities from the external environment through a dynamic noise source server; the measuring instrument terminal performing an incentive response calculation based on the challenge value to generate a response value coupled with the physical identity and the real-time environment; and a management platform verifying the response value against the certificate anchor point, establishing an encrypted channel to achieve certificate synchronization upon successful verification. The system includes a terminal, a noise source server, a synchronization gateway, and a management platform. This invention achieves atomic-level binding between physical entities and digital certificates, resists replay attacks, and ensures instantaneous security and the authenticity of the device identity during the synchronization process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of data security technology, specifically relating to a method and system for automatically synchronizing certificate information of measuring instruments based on an encrypted API. Background Technology

[0002] Measuring instruments, as fundamental tools for ensuring accurate and consistent measurement values, are widely used in core areas of the national economy such as energy measurement, industrial production, and commercial settlement. With the deepening of digital transformation, the information management of measuring instruments and the automated synchronization of digital certificates have become key links in ensuring the fairness and compliance of measurement data, playing an important role in building a trustworthy metrological traceability system.

[0003] Automatic certificate information synchronization technology based on encrypted interfaces is a core means of achieving full lifecycle supervision of measuring instruments. This technology, through standardized communication protocols and encryption algorithms, aims to achieve real-time data alignment between the physical entity of the measuring instrument and the cloud-based digital certificate repository, ensuring that the verification status, calibration parameters, and legal validity of each in-service instrument are dynamically maintained.

[0004] Existing metrology instrument certificate synchronization technologies have revealed limitations in practical applications. Certificate storage and the physical identity of the instrument are severely loosely coupled; digital certificates are often associated with devices only through logical identifiers, making legitimate certificates susceptible to unauthorized porting or tampering, leading to identity theft risks. Traditional encryption and authentication mechanisms heavily rely on pre-set static keys, making them vulnerable to side-channel analysis or physical extraction in complex industrial physical environments, resulting in a fragile security foundation. The random number generation mechanisms used in conventional challenge-response processes are predictable and cannot withstand high-intensity replay attacks and man-in-the-middle attacks, failing to guarantee instantaneous security during synchronization. Existing technologies lack deep perception and utilization of physical environment characteristics, causing the authentication process to become disconnected from the actual physical scenario, resulting in insufficient robustness against malicious attacks. These technologies address the shortcomings of traditional methods, including identity disconnect, static keys, weak attack resistance, and lack of environmental awareness. Summary of the Invention

[0005] The purpose of this invention is to provide a method and system for automatic synchronization of measuring instrument certificate information based on an encrypted application programming interface, which can solve the problems mentioned in the background art.

[0006] To achieve the above objectives, this invention proposes a method for automatically synchronizing measuring instrument certificate information based on an encrypted application programming interface, comprising the following steps: S1. By integrating a physically unclonable functional module inside the measuring instrument terminal, physical features are extracted based on micro-process deviations in the hardware manufacturing process, and a unique physical fingerprint is generated accordingly. The physical fingerprint serves as the root key of the measuring instrument terminal. S2. Random physical quantities in the external environment are collected in real time by the dynamic noise source server as the source of entropy value. After being converted into dynamic challenge value, it is sent to the measuring instrument terminal through the encrypted application programming interface of the data synchronization gateway. S3. The measuring instrument terminal receives the dynamic challenge value and calls the physical non-cloning function module to perform stimulus response calculation, generating a response value that is deeply coupled with physical identity and real-time environmental noise. S4. The measuring instrument management platform performs correlation verification based on the response value and the pre-built certificate anchor point. After the verification is successful, an end-to-end encrypted communication channel is established to realize the automatic synchronization and status alignment of measuring instrument certificate information.

[0007] Preferably, step S1 specifically includes the following steps: S11. Deploy an oscillator array or metastable detection circuit consisting of multiple logic units in the integrated circuit of the measuring instrument terminal. S12. Under the trigger of a preset start command, capture the differences in logic state caused by microscopic inconsistencies in transistor threshold voltage, interconnect resistance and parasitic capacitance. S13. The captured raw physical data is denoised and error corrected using a fuzzy extraction algorithm to extract a bit stream with high entropy characteristics, which is then used as the physical fingerprint.

[0008] Preferably, the fuzzy extraction algorithm in step S13 includes a generation process and a reconstruction process. The generation process is configured to map the original physical data into a feature vector and calculate auxiliary error correction data; the reconstruction process is configured to, in subsequent calls, use the currently captured original physical data and the auxiliary error correction data to restore the accurate and consistent physical fingerprint, and the physical fingerprint only exists momentarily in the register during the operation and is strictly prohibited from being stored in non-volatile storage media.

[0009] Preferably, step S2 specifically includes the following steps: S21. Extract uncertain random parameters from the preset external physical environment through a dynamic noise source server. The random parameters include wind speed fluctuation data, power grid frequency perturbation, or environmental electromagnetic radiation noise. S22. Normalize and hash the extracted random parameters to generate an external entropy value that is highly random and unpredictable. S23. The external entropy value is encapsulated in a message structure that conforms to a preset security protocol and sent out as a dynamic challenge value through an encrypted application programming interface.

[0010] Preferably, the normalization process in step S22 adopts an adaptive step size algorithm, which dynamically adjusts the quantization level according to the rate of change of random parameters to ensure that the generated external entropy value conforms to a uniform distribution law in the time domain, thereby enhancing the anti-predictability.

[0011] Preferably, step S3 specifically includes the following steps: S31. The measuring instrument terminal inputs the received dynamic challenge value as the excitation vector of the physically unclonable function module to the excitation end. S32. The physically unclonable functional module generates a corresponding physical response by combining the internal physical feature path under the drive of the excitation vector. S33. Perform feature compression and multi-round nonlinear transformation on the physical response to generate a first response value. The first response value characterizes the unique physical feedback of the specific measuring instrument to a specific environmental noise at a specific time point.

[0012] Preferably, step S4 specifically includes the following steps: S41. The measuring instrument management platform, based on the original registration information of the measuring instrument, performs multiple encryption operations on the hash feature value of the digital certificate, the derived key of the physical fingerprint, and the benchmark challenge value during the first authentication, constructs a quantum-encrypted certificate anchor point, and distributes it to the measuring instrument terminal. S42. The measuring instrument terminal uses the currently generated first response value as the generation factor of the decryption key to parse the certificate anchor point stored locally and obtain the metadata of the certificate to be synchronized. S43. The measuring instrument terminal sends the first response value and the metadata of the certificate to be synchronized to the measuring instrument management platform for consistency comparison. S44. Provided that the comparison results are consistent, the platform updates the verification validity period and calibration parameters of the measuring instruments and completes the synchronization of certificate information.

[0013] Preferably, the quantum encryption in step S41, by introducing a lattice cryptosystem or a multivariate public-key cryptography algorithm, ensures that the certificate anchor still has sufficient security strength in the face of future high-performance computing attacks, and achieves strong coupling between certificate information and physical hardware.

[0014] Preferably, the first response value, while serving as a decryption key generation factor, is also configured as the basis for negotiating the session key. The entropy feature of the first response value is injected into the key scheduling algorithm of the symmetric encryption algorithm using a diffusion algorithm to generate a session key with one-time pad characteristics, used to ensure the confidentiality and integrity of subsequent certificate data transmission.

[0015] Preferably, when the measuring instrument management platform performs step S44, if the comparison results are inconsistent, it immediately initiates a security warning process, locks the identifier of the measuring instrument, and records the currently collected environmental noise characteristics and response anomaly patterns for subsequent physical attack behavior tracing.

[0016] An automatic synchronization system for metrological instrument certificate information based on an encrypted application programming interface (API) is provided to implement the aforementioned method. The system includes: a metrological instrument terminal with a built-in physically unclonable module for generating physical fingerprints and performing stimulus-response calculations; a dynamic noise source server connected to external physical environment sensors for generating external entropy values ​​and providing dynamic challenge sources; a data synchronization gateway configured with an encrypted API for forwarding encrypted signaling between the metrological instrument terminal, the dynamic noise source server, and the metrological instrument management platform; and a metrological instrument management platform for storing a digital certificate repository, generating certificate anchors, and performing correlation verification of response values.

[0017] Preferably, the measuring instrument terminal has a security isolation area inside, and the operating environment of the physically unclonable functional module is physically isolated from the main processor and ordinary storage area to ensure that the electrical signals during the physical response generation process are not monitored or extracted by the outside world.

[0018] Preferably, the dynamic noise source server includes multiple heterogeneous noise acquisition modules, which are configured to periodically switch between different types of environmental noise sources to eliminate the periodicity that may exist in a single physical noise source and further improve the entropy intensity of the dynamic challenge value.

[0019] Preferably, the measuring instrument management platform includes a certificate anchor generation engine, which is configured to use hash chain technology to solidify the historical change records of certificates, ensuring that each synchronized certificate information has tamper-proof traceability.

[0020] Compared with the prior art, the present invention has the following beneficial effects: 1. This invention achieves atomic-level binding between the physical entity identity of a measuring instrument and digital certificate information by constructing a collaborative system of physically unclonable functional modules and dynamic noise injection, thus solving the problem of abuse caused by the disconnect between certificate and instrument identity in the prior art.

[0021] 2. The physical fingerprint generated by the physically unclonable module is unique and cannot be cloned by software, ensuring the security of the root key at the physical layer. Dynamic random noise from the external environment is introduced as a challenge value, ensuring that the authentication logic of each certificate synchronization process is both instantaneous in time and unique in space.

[0022] 3. With the combined effect of physical non-cloning functionality and dynamic noise challenges, it achieves accurate identification of measuring instruments and high-strength protection of the synchronization process, thereby improving the authentication robustness of measuring instruments and the overall security of the system in harsh industrial environments. Attached Figure Description

[0023] Figure 1 This is a schematic diagram of the overall technical solution architecture of the present invention; Figure 2 This is a schematic diagram of the core principle framework of identity authentication based on physical non-cloning function and dynamic noise excitation in this invention; Figure 3 This is a flowchart illustrating the logical process of physical fingerprint extraction and root key generation for measuring instrument terminals in this invention. Figure 4 This is a schematic diagram of the multi-level interaction relationship and data flow between the measuring instrument terminal, the dynamic noise source server, and the management platform in this invention; Figure 5 This is a schematic diagram of the core principle framework of certificate anchor construction and correlation verification based on quantum encryption in this invention. Detailed Implementation

[0024] To further illustrate the technical means and effects adopted by the present invention to achieve the intended purpose, the following description is provided in conjunction with the appendix. Figures 1 to 5 The following is a detailed description of the specific implementation methods, structures, features, and effects of the present invention, as well as preferred embodiments.

[0025] Example 1: In the context of the deep integration of current industrial digitalization and metrological traceability system, this example provides an automatic synchronization method for metrological instrument certificate information based on encrypted application programming interface. It aims to build an automated synchronization mechanism with extremely high security by combining physical uniqueness at the hardware level with randomness at the environmental level.

[0026] In this embodiment, step S1 is first executed. The physical non-clonable functional module integrated inside the measuring instrument terminal extracts physical features based on microscopic process deviations in the hardware manufacturing process and generates a unique physical fingerprint, which serves as the root key of the measuring instrument terminal.

[0027] In the specific implementation process, step S1 is achieved through the following detailed steps.

[0028] In step S11, an oscillator array consisting of multiple logic units is deployed in the integrated circuit of the measuring instrument terminal. These oscillator arrays are formed by a series of inverters connected end to end to form a closed loop. Due to the non-uniformity of semiconductor manufacturing processes at the nanoscale, the gate delay time of each inverter has subtle and unpredictable differences.

[0029] In step S12, triggered by a preset startup command, the system captures the logic state differences caused by microscopic inconsistencies in transistor threshold voltage, interconnect resistance, and parasitic capacitance. Specifically, when two identical ring oscillators start simultaneously, their oscillation frequencies will have a very small phase difference due to the aforementioned microscopic deviations. By quantizing and sampling this phase difference, raw data reflecting the physical characteristics of the chip can be obtained.

[0030] In step S13, the captured raw physical data is denoised and error-corrected using a fuzzy extraction algorithm to extract a bitstream with high entropy characteristics, which serves as the physical fingerprint.

[0031] In one specific embodiment, the fuzzy extraction algorithm employs a BCH code-based construction method to achieve stable extraction and reconstruction of physical fingerprints.

[0032] Eigenvector construction: Suppose the raw physical data captured from the oscillator array is a bit string of length n. Each bit This reflects the quantization result of the phase difference between a pair of oscillators. Due to manufacturing process variations and environmental noise, the W generated by the same physically non-clonable functional module at different times may have a small bit difference.

[0033] Generation process (Gen): During initial registration, the system executes the generation algorithm: , where R is the extracted stable physical fingerprint (root key) and P is the public auxiliary data.

[0034] The system first selects BCH code C, where Let K be the code length, K be the information bit length, and t be the error correction capability. This code can correct a maximum of t bit errors. The system randomly selects codewords. Then, calculate the stable physical fingerprint R as the hash value of C: .

[0035] Where Hash is a cryptographic hash function (such as SHA-256). P is obtained by XORing w and c: This auxiliary data can be stored publicly without leaking information about R.

[0036] Reconstruction process (Rep): During subsequent authentication, the system captures new, noisy physical data. ( and At most One bit difference, The system uses auxiliary data P to recover the codeword: .

[0037] because It is an error vector, and its Hamming weight is... ,therefore It's typing The result after superimposing the error vector. The system executes an iterative decoding algorithm for the BCH code (such as the Berlekamp-Massey algorithm or Chien search) to find the distance. Recent legal writing : .

[0038] The conditions for successful decoding are Finally, the system restored the physical fingerprint. : .

[0039] When decoding is successful This achieves accurate reconstruction of the physical fingerprint. The error correction capability t of the BCH code is pre-set based on the stability of the physically non-cloning functional module. For example, when the bit error rate of the original data is about 5%, a BCH code with t of 10⁻¹⁵ is selected. The decoding iteration process finds the error location by solving the error location polynomial and using Chien search. The entire process is implemented in hardware logic and does not involve floating-point operations.

[0040] In this process, the fuzzy extraction algorithm consists of two core stages: generation and reconstruction. In the generation stage, the system maps the original physical data into feature vectors and calculates a set of auxiliary error-correcting data using error-correcting coding logic. This auxiliary data is stored in a non-secure area. In the reconstruction stage, when the measuring instrument terminal subsequently calls this function, it uses the currently captured, potentially noisy, original physical data along with the previously stored auxiliary error-correcting data. Through logical XOR operations and algebraic decoding algorithms, it reconstructs a physical fingerprint that is precisely consistent with the initial extraction. It is particularly important to emphasize that this physical fingerprint only exists momentarily in the register during the computation process and is immediately erased after authentication or encryption. It is strictly forbidden to store it in any non-volatile storage media such as flash memory or electrically erasable read-only memory, thus eliminating the risk of the key being physically extracted.

[0041] Subsequently, in this embodiment, step S2 is executed, where random physical quantities in the external environment are collected in real time by the dynamic noise source server as the source of entropy values. After being converted into dynamic challenge values, these values ​​are sent to the measuring instrument terminal via the encrypted application programming interface of the data synchronization gateway.

[0042] In one specific embodiment, the dynamic noise source server uses adaptive step-size quantization combined with the SHA-256 hash function to generate dynamic challenge values. Sliding window statistics: Let the collected random physical quantity sequence be... (e.g., instantaneous value of power grid frequency) They represent the sequence of random physical quantities obtained from the collection, i.e., the th... The physical quantity measurement values ​​corresponding to each sampling time point. The system maintains a sliding window of length L (e.g., 100) and calculates the mean value within the window. and standard deviation : ; ;

[0043] This represents the measured value of the physical quantity at the i-th sampling moment in the sequence of random physical quantities collected.

[0044] Adaptive step-size quantization: The system quantizes the step size based on the rate of change (i.e., standard deviation) within the current window. Dynamically adjust the quantization step size The step size adjustment formula is: ;

[0045] in, It is the initial quantization step size. It is the reference standard deviation (such as the historical mean). This is an adjustment factor (e.g., 0.5). When When the values ​​are large (fluctuations are significant), the step size is increased to cover a wider numerical range; when... When the fluctuations are small, the step size is reduced to improve the quantization resolution.

[0046] Quantization output for: , The distribution of values ​​tends to be uniform after adaptive adjustment.

[0047] Nonlinear Transformation and Hash Mapping: The system concatenates M consecutive quantized values ​​(e.g., 16) into a bit string B, and then performs multiple rounds of nonlinear transformation. First, the bit order is shuffled through a cyclic left shift operation: ;

[0048] Where ROL represents a circular left shift of r bits. and The preset shift amount (e.g., 7 and 13). For bitwise XOR, This is the intermediate bit string output after the first round of cyclic left shift and XOR obfuscation.

[0049] Next, regarding Bit expansion and compression are performed, followed by multi-round (e.g., 8 rounds) obfuscation using a Feistel network structure: ; ;

[0050] in,( , ) is the state block of the i-th round, ( , ) is the state block of the (i+1)th round, and F is the round function (composed of S-Box and linear transformation). It is the round key (derived from the physical fingerprint).

[0051] After multiple rounds of transformation, the final state is input into the SHA-256 hash function to generate a 256-bit dynamic challenge value, Chal. ;

[0052] in, This represents a bit string concatenation, where timestamp is a high-precision timestamp and salt is a random salt value. This challenge value possesses temporal immediacy and spatial uniqueness, and is unpredictable due to the one-way nature of the hash function. SHA-256 is a standard secure hash algorithm in the field of cryptography.

[0053] In the detailed implementation of step S2, step S21 is first executed, whereby uncertain random parameters are extracted from the preset external physical environment through a dynamic noise source server. In this embodiment, these random parameters are selected as small disturbance data of the power grid frequency. Due to the random connection and disconnection of loads in a large-scale power system, the power grid frequency always fluctuates around the standard frequency in an extremely weak and unpredictable manner. This fluctuation has a natural global consistency and unpredictability.

[0054] Step S22 involves normalizing and hashing the extracted random parameters to generate highly random and unpredictable external entropy values. To ensure the generated entropy values ​​have good statistical properties, an adaptive step-size algorithm is used for normalization. This algorithm dynamically adjusts the width of the quantization step based on the rate of change of the power grid frequency within the current time window. When frequency fluctuations are severe, the step size is increased to smooth noise; when fluctuations are weak, the step size is decreased to capture subtle features. In this way, it is ensured that the generated external entropy values ​​conform to a uniform distribution in the time domain.

[0055] Execute step S23, encapsulate the external entropy value in a message structure that conforms to the transport layer security protocol, and send it as a dynamic challenge value to the designated metering instrument terminal through the encrypted application programming interface.

[0056] Next, step S3 is executed, whereby the measuring instrument terminal receives the dynamic challenge value and calls the physically unclonable function module to perform stimulus response calculation, generating a response value that is deeply coupled with physical identity and real-time environmental noise.

[0057] In the specific logic of step S3, step S31 is executed first, where the measuring instrument terminal inputs the received dynamic challenge value as the excitation vector of the physically unclonable functional module to the excitation end. Step S32 is then executed, where the physically unclonable functional module, driven by the excitation vector, generates a corresponding physical response by combining its internal physical feature paths. Specifically, the dynamic challenge value determines the selection order and combination method of the oscillator pairs participating in the calculation, making the output physical response not only dependent on the chip's own physical fingerprint but also highly correlated with the current challenge value.

[0058] Step S33 involves performing feature compression and multi-round nonlinear transformation on the physical response to generate a first response value. This transformation process employs permutation mapping and multi-bit diffusion logic to ensure that each bit of the original response fully influences the final output first response value. This first response value characterizes the unique physical feedback of a specific measuring instrument to specific environmental noise at a specific point in time, exhibiting strong anti-cloning and time-varying properties.

[0059] In one specific embodiment, the measuring instrument terminal performs a nonlinear transformation on the physical response based on an SPN (substitution-permutation network) structure to generate a first response value.

[0060] Input definition: Suppose that the original physical response generated by the physically non-clonable functional module is a bit string of length N. Where N depends on the size of the oscillator array (e.g., 256 bits). The dynamic challenge value Chal determines the selection order of the oscillator pairs participating in the computation, i.e. It is a function of Chal.

[0061] Replacement box (S-Box): The system will The input is divided into m blocks of length n (e.g., n=8, m=32). Each block is input into a fixed nonlinear permutation box. The S-Box mapping table uses a pre-defined permutation with high non-linearity (such as the S-Box in AES) to ensure that a small change in each input bit will cause a change in the output bit.

[0062] The output of the substitution layer is ; These are the first two parts of the original response R of total length N, obtained by splitting it into its components. Each block, This is the output of the corresponding block after undergoing S-box nonlinear transformation.

[0063] Bit diffusion operation: The system performs a linear transformation on the substituted bit string to achieve diffusion. Let the transformed state be T, and the diffusion operation is defined as: Where M is an N×N binary matrix with a high number of branches (e.g., using a generator matrix with maximum distance separable codes). The spread operation ensures that a change in any input bit affects more than half of the output bits. In actual hardware implementations, spread is achieved through bit shifting and XOR operations, for example: ;in, , ,... are preset offsets (e.g., 1, 3, 5). This represents the i-th bit of the output bit string of the diffusion layer.

[0064] Round key mixing: The system introduces a round key sequence derived from the physical fingerprint. (e.g., the total number of rounds in the SPN nonlinear transformation is 12). They are respectively the first The round key. The derivation of the round key is achieved through a fingerprint input key expansion algorithm (such as key scheduling in AES). The key mixing operation for the r-th round is as follows: ; Let r be the input state for the round key mixing. This represents the output state after the complete transformation in the r-th round. This is the exclusive round key for the r-th round.

[0065] After multiple rounds (e.g., 8-12 rounds) of substitution-permutation-key hybrid iteration, the final output is the first response value Resp: ; This represents the final state after the transformation is completed in the rounds (i.e., the last round).

[0066] This response value is deeply coupled with the physical entity's identity and real-time environmental noise, exhibiting high uniqueness and unpredictability. The selection of the number of rounds needs to balance security and computational overhead; in this embodiment, 12 rounds are chosen.

[0067] Finally, in step S4 of this embodiment, the measuring instrument management platform performs correlation verification based on the response value and the pre-built certificate anchor point. After the verification is successful, an end-to-end encrypted communication channel is established to realize the automatic synchronization and status alignment of the measuring instrument certificate information.

[0068] The implementation details of step S4 are as follows: First, step S41 is executed. Based on the original registration information of the measuring instrument when it joins the network, the measuring instrument management platform performs multiple encryption operations on the hash feature value of the digital certificate, the derived key of the physical fingerprint, and the benchmark challenge value during the first authentication. To combat potential future quantum computing threats, a quantum encryption algorithm based on lattice cryptography is introduced here to construct the certificate anchor and distribute it to the measuring instrument terminal storage.

[0069] In one specific embodiment, the measuring instrument management platform uses a lattice cryptography system based on the Ring-LearningWithErrors (Ring-LWE) problem to construct certificate anchors.

[0070] Parameter definition: System selection polynomial ring: ; It is a synonym for the entire polynomial quotient ring. Let q be the integer residue class ring, and each element of the ring can be represented as a A dimensional vector, where x is a formal indeterminate element of a univariate polynomial.

[0071] Key Generation: The management platform generates a public-private key pair for each measuring instrument. The private key s is randomly selected from a discrete Gaussian distribution x on a ring, satisfying: The public key (a, b) is composed of uniformly randomly selected ring elements. and the calculated Composition, where e is subject to Error terms:

[0072] Certificate Anchor Encryption: Let the hash value of the digital certificate to be synchronized be... (Encode the certificate hash value as a ring element). The platform selects random noise. Calculate ciphertext ( , As a certificate anchor point: , ;

[0073] in, It is a random blinding factor. This is the scaling factor used to map message bits to ring elements. This is the certificate anchor. It is distributed to the terminal storage of measuring instruments.

[0074] Certificate Anchor Decryption: During synchronization, the metering instrument terminal uses its private key 's' derived from its physical fingerprint (which should be consistent with the 's' generated by the platform) to decrypt the anchor. Decryption process calculation:

[0075] Because the metering instrument terminal reconstructs the private key polynomial through the local physical fingerprint and The error is relatively small, and the intermediate approximate polynomial of the decryption output is calculated. Approximately The system recovers the message through rounding: ;

[0076] Only when and Only with an exact match can the hash feature value be correctly restored. The security of this process is based on the computational difficulty of the Ring-LWE problem, which makes it resistant to attacks from quantum computers.

[0077] Anchor point binding to physical fingerprint: The certificate anchor point is further bound through physical fingerprint derivation parameters. When generating the anchor point, the platform uses the derived key of the physical fingerprint as an additional seed in the random number generation to ensure a strong coupling between the certificate anchor point and the physical identity of the specific measuring instrument.

[0078] In step S42, after receiving the synchronization command, the metering instrument terminal uses the currently generated first response value as the generation factor for the decryption key. By fusing the first response value with the locally pre-stored bootstrap vector, a temporary symmetric key is generated. The locally stored certificate anchor is then parsed to obtain the metadata of the certificate to be synchronized.

[0079] In step S43, the measuring instrument terminal sends the first response value generated in real time and the extracted metadata of the certificate to be synchronized to the measuring instrument management platform for consistency comparison through the encrypted application programming interface.

[0080] In step S44, on the management platform side, the system calls the pre-stored reference characteristics of the instrument, simulates the response value generation process, and matches it with the received first response value. If the comparison results are completely consistent, the platform confirms that the request initiator is a legitimate physical entity, and then updates the verification validity period and calibration parameters of the measuring instrument, completing the fully automatic synchronization of certificate information.

[0081] If an inconsistency is found in the comparison results in step S44, the measuring instrument management platform will immediately initiate a security alert process. This includes locking the unique identifier of the measuring instrument, prohibiting it from engaging in any data interaction, and recording in detail the characteristics of the currently collected abnormal environmental noise and response failure modes. Through deep learning analysis of this data, the security system can trace whether malicious behaviors such as physical imitation, replay attacks, or environmental simulation attacks have occurred.

[0082] Furthermore, the first response value generated in this embodiment serves not only as an identity credential but also as the foundation for session key negotiation. Through a diffusion algorithm, the entropy characteristics of the first response value are injected into the key scheduling algorithm of the symmetric encryption algorithm. This mechanism achieves a one-time pad communication effect, meaning that the encryption key used in each certificate synchronization process is determined by the physical environment noise and hardware fingerprint at that time. Even if an attacker cracks the key for a particular communication, it cannot be used for any subsequent data eavesdropping or tampering.

[0083] In one specific embodiment, the measuring instrument terminal and the management platform use a key derivation function based on the first response value to generate a one-time pad session key.

[0084] Key Derivation Input: Let the first response value be... (256 bits). Both parties simultaneously obtain a fresh, non-repeating Nonce value, which is generated by the management platform and sent with the authentication message. This Nonce can be a combination of a high-precision timestamp and a random number.

[0085] Key Derivation Function (KDF): The system uses HMAC-SHA256 as the key derivation function. Session Key The formula for generating it is: ;

[0086] in, Is it using Resp? Perform message authentication code calculation. This represents bit string concatenation. The Counter is an incrementing counter starting from 0 (e.g., 0, 1, 2...) used to derive multiple keys (e.g., encryption keys, authentication keys). Because a different Nonce is used for each synchronization, the derived session keys are also different, achieving the one-time pad feature.

[0087] Diffusion Algorithm: To further enhance the entropy distribution of the key, the diffusion algorithm fully mixes each bit of the first response value. Internally, in HMAC-SHA256, Resp is first expanded to the SHA256 input block size through XOR padding. The diffusion process is accomplished by the compression function within SHA256, which employs a Merkle-Damgård structure and includes 64 rounds of iterative operations. Each round achieves full bit mixing through bitwise operations (XOR, AND, shift) and modulo addition, ensuring that any change in any bit of the input will cause approximately half a bit of the output key to change.

[0088] Encrypted communication channel establishment: The derived session key is used to encrypt and protect the certificate synchronization data using a symmetric encryption algorithm (such as AES-GCM). Specifically, let the certificate information to be synchronized be CertData, and the encryption process is as follows: ;

[0089] Ciphertext is the ciphertext of the encrypted output, AES-GCM represents Advanced Encryption Standard - Galois Counter mode, and CertData represents the certificate data. It is by The derived encryption key, The initialization vector (derived from the nonce) and the additional authentication data (such as the device ID) are used to ensure integrity. The decryption end uses the same derived logic recovery key to complete the decryption and verification of the certificate information.

[0090] Through this key derivation mechanism based on the first response value, the encryption key used in each certificate synchronization process is unique and unpredictable. Even if an attacker steals the key of a certain communication, it cannot be used for other synchronization sessions, thus ensuring the instantaneous security of the entire synchronization process.

[0091] This embodiment also relates to an automatic synchronization system for metrological instrument certificate information based on an encrypted application programming interface (API). The system comprises a metrological instrument terminal, a dynamic noise source server, a data synchronization gateway, and a metrological instrument management platform. The metrological instrument terminal has a dedicated secure isolation zone, which is physically isolated from the main processor, general-purpose memory, and storage areas. All computational processes of the physically unclonable functional modules, the instantaneous storage of physical fingerprints, and the logic for generating response values ​​are completed within this secure isolation zone. This physical isolation ensures that the weak fluctuations in electrical signals generated during response generation cannot be extracted by external monitoring equipment through electromagnetic side-channel analysis or other means.

[0092] The dynamic noise source server comprises multiple heterogeneous noise acquisition modules configured to periodically switch between different types of environmental noise sources. For example, it acquires environmental electromagnetic radiation noise during a first preset time period and wind speed fluctuation data captured by meteorological sensors during a second preset time period. This switching strategy eliminates the periodic statistical regularities that may exist in a single physical noise source, improving the entropy intensity and anti-predictability of the dynamic challenge value.

[0093] The measuring instrument management platform includes a certificate anchor generation engine that uses hash chain technology to solidify the historical change records of certificates. This means that each issued and synchronized certificate contains an encrypted link pointing to the previous certificate's state, forming a logically robust traceability chain. Any unauthorized tampering with historical certificate information will cause the entire hash chain to break, ensuring the immutability and authenticity of the certificate information.

[0094] Example 2: Based on Example 1, this example optimizes the implementation of the physically unclonable function module and the dynamic noise extraction logic to meet the high-frequency, low-power measurement instrument certificate synchronization requirements in large-scale industrial parks.

[0095] In step S1, the measuring instrument terminal in this embodiment uses a metastable detection circuit as the source of physical feature extraction. Specifically, the logic unit deployed in step S11 consists of two interleaved complementary metal-oxide-semiconductor flip-flops.

[0096] During step S12, under the excitation of an extremely short pulse signal, the flip-flop enters an unstable intermediate state, namely a metastable state. Due to the minute differences in the microscopic physical characteristics of each transistor, such as internal carrier mobility and oxide layer thickness, the flip-flop exhibits a unique bias when exiting the metastable state and finally locking into a stable logic state. By massively integrating such metastable state detection units, this embodiment can generate higher-dimensional physical feature vectors with lower power consumption.

[0097] In step S2, considering the unique environment of the industrial park, the dynamic noise source server extracts ambient electromagnetic radiation noise as the entropy source. The electromagnetic background noise generated by the operation of numerous transformers, motors, and frequency converters within the park exhibits extremely high spatial complexity and instantaneous randomness. Step S21 captures these stray electromagnetic waves using a high-sensitivity wideband antenna. In step S22, a hash algorithm based on nonlinear chaotic mapping is used to process the electromagnetic noise. This algorithm is extremely sensitive to the initial input, ensuring that even a difference of only one part per million in the ambient noise will result in a significant bit offset in the generated external entropy value. Simultaneously, a noise level monitoring mechanism is introduced during the normalization process. When the ambient electromagnetic interference is too low, potentially leading to insufficient entropy increase, the server automatically integrates backup high-precision clock jitter data to ensure the quality of the dynamic challenge value.

[0098] In step S3, the measuring instrument terminal performs segmented excitation on the received external entropy value. Step S31 splits the challenge value into multiple logical segments, each driving a different sub-region of the metastable detection array. During step S32, the raw physical responses generated by each region are fused through a multi-level feedback shift register network. The response value generated in step S33 is further converted using stream ciphers into a long binary sequence with uniform distribution characteristics. This sequence is used not only for authentication but also directly participates in the encryption process of sensor data within the terminal.

[0099] In step S4, the measuring instrument management platform employs a pre-computation mechanism to improve verification efficiency. In step S41, when constructing the certificate anchor, a set of correlation equations is generated using a multivariate public-key cryptography algorithm and sent to the terminal as the anchor. In step S42, the terminal uses the first response value as a known variable to solve the equations and obtain the decryption key factor. This identity binding method based on a mathematical problem makes it impossible for attackers to solve the correct key within a reasonable timeframe, even through brute-force attacks. In step S43, to reduce data transmission, the terminal only sends a feature digest of the first response value. In step S44, the platform utilizes a high-performance parallel processing cluster for rapid comparison. If the verification failure frequency abnormally increases within a short period, the system automatically determines that there is a risk of coordinated attacks in the current area and dynamically adjusts the synchronization frequency and encryption level of all measuring instruments in that area.

[0100] Furthermore, in the system architecture of this embodiment, the data synchronization gateway is configured as an intelligent node with edge computing capabilities. This gateway can perform traffic shaping and preliminary protocol verification on certificate synchronization requests from tens of thousands of metering instrument terminals, alleviating the concurrency pressure on the management platform. Simultaneously, the gateway maintains an instantaneous challenge value cache pool to ensure that even when external network instability causes connection interruptions to dynamic noise source servers, it can still utilize historical entropy value sequences that meet statistical security requirements to complete emergency certificate alignment operations.

[0101] Example 3: This example proposes an automatic synchronization scheme with an environmental compensation mechanism to address the stability requirements of synchronizing measuring instrument certificates in extreme industrial environments, such as extremely cold or high-temperature regions.

[0102] In step S1, temperature compensation logic is incorporated into the physical fingerprint extraction process. During step S11, the measuring instrument terminal integrates a high-precision bandgap reference voltage source and a temperature sensor. During step S12, when capturing physical differences, the system simultaneously records the current chip junction temperature. This is because the original response generated by the physically non-clonable module drifts with temperature. During step S13, the fuzzy extraction algorithm selects the corresponding offset from the preset feature compensation matrix based on the current temperature value to correct the original bitstream. This method ensures that the consistency of physical fingerprint reconstruction remains at an extremely high level within a wide temperature range of -40 degrees Celsius to +85 degrees Celsius, avoiding authentication failures caused by drastic environmental changes.

[0103] In step S2, the dynamic noise source server selected wind speed fluctuation data as the entropy source. For metering instruments distributed in remote wind farms or coastal areas, the nonlinear turbulent characteristics of wind speed provide excellent randomness. The raw wind speed sequence collected in step S21 is processed by wavelet transform to separate high-frequency impulse noise components. When executing step S22, spatial correlation removal processing is performed on these high-frequency components to ensure that the generated external entropy value only reflects local instantaneous randomness and cannot be used for long-term prediction through meteorological models.

[0104] In step S3, the measuring instrument terminal executes a deeply coupled stimulus-response logic. The dynamic challenge value received in step S31 is first rearranged through a pseudo-random permutation network. During step S32, the physically unclonable module generates a response under the rearranged stimulus. The response value generated in step S33 serves not only as an identity credential but is also injected into the seed pool of a hardware-based true random number generator. This design achieves a secondary entanglement between physical characteristics and environmental randomness, resulting in a highly complex mathematical characteristic in the final generated first response value.

[0105] In step S4, the certificate information synchronization process incorporates multiple consistency checks. During step S41, the metrology management platform uses hash chain technology to deeply bind the current certificate status with the instrument's historical calibration records. In step S42, the terminal must provide its own operational status log while parsing the certificate anchor. During step S43, the platform not only compares the response values ​​but also uses big data analysis to compare whether the instrument's operating mode matches the performance characteristic curve corresponding to its physical fingerprint. After synchronization is completed in step S44, the platform sends a confirmation message signed with a private key. This message contains a temporary authorization code derived from the current first response value. The metrology terminal will only officially apply the synchronized calibration parameters to its core metrology logic after verifying the validity of this authorization code.

[0106] The system in this embodiment also features enhanced encrypted application programming interfaces (APIs) for the data synchronization gateway. This interface supports multipath redundancy transmission protocols, automatically switching to backup wireless spectrum or wired links when the primary communication link is interfered with or congested. Simultaneously, the interface integrates fine-grained access control policies, enabling deep packet inspection for each API call request to prevent maliciously crafted command packets from disrupting the system's synchronization logic.

[0107] Example 4: This example focuses on improving the synchronization system's resistance to physical attacks, especially protection against side-channel attacks and probe sniffing attacks.

[0108] In step S1, the physical fingerprint extraction process of the measuring instrument terminal employs a differential logic structure. When deploying the oscillator array in step S11, each logic unit consists of a pair of perfectly symmetrical differential circuits. When capturing logic state differences in step S12, the system measures the current difference between the two symmetrical nodes rather than the absolute level. This differential design minimizes electromagnetic radiation and power consumption fluctuations generated during chip operation, and these fluctuations cancel each other out, significantly improving the ability to resist power analysis attacks. In step S13, the fuzzy extraction algorithm uses a masking technique, artificially injecting a set of random bit masks during the physical fingerprint extraction process. This ensures that the actual value in the register is constantly changing dynamically, preventing attackers from reconstructing the true physical fingerprint even if they intercept data on the bus.

[0109] In step S2, the dynamic noise source server introduces heterogeneous multi-source fusion technology. Step S21 simultaneously collects power grid frequency disturbances, environmental thermal noise, and pulse sequences generated by cosmic ray impact detectors. During step S22, these heterogeneous data undergo cascaded hashing and cross-correlation extraction to generate ultra-long-period external entropy values. Normalization employs nonlinear quantization technology, which can amplify weak physical disturbances into highly significant feature bits.

[0110] In step S3, before performing the stimulus response calculation, the metering instrument terminal activates the dynamic protection mechanism of the secure isolation zone. During step S31, the clock frequency within the secure zone undergoes random jittering to disrupt the time-domain alignment conditions required for side-channel attacks. The physical response generated in step S32 is directly subjected to non-linear obfuscation processing within the hardware pipeline. Before being sent via the encrypted API, the response value generated in step S33 is encapsulated in an encrypted container with a self-destruct mechanism.

[0111] In step S4, the measuring instrument management platform performs a more stringent correlation verification. When constructing the certificate anchor in step S41, a multivariate multinomial-based encryption algorithm is used. In step S42, the terminal needs to utilize multiple key slices derived from the physical fingerprint and combine them logically to completely parse the certificate anchor. In step S43, to prevent man-in-the-middle attacks, each response value is accompanied by a high-precision timestamp and geographic location feature. In step S44, during comparison, the platform verifies whether these spatiotemporal features match the expected synchronization strategy.

[0112] In this embodiment, the system also incorporates blockchain-based distributed ledger technology on the metering instrument management platform to store certificate anchors and synchronization logs. Each synchronization operation is published as a block to all nodes in the management network for consensus verification. This decentralized storage method ensures the certificate database itself has extremely high tamper resistance; even if the platform's central node is attacked, the trust foundation of the entire certificate synchronization system remains solid. Simultaneously, the system is equipped with an abnormal traffic monitoring engine for encrypted application programming interfaces (APIs), using artificial intelligence algorithms to identify and block API call requests with scanning, probing, or injection characteristics in real time.

[0113] Example 5: This example details the scalability and efficient processing logic of the present invention when handling the synchronization of ultra-large-scale measuring instrument clusters.

[0114] In step S1, to improve production efficiency, the measuring instrument terminal performs a one-time large-scale physical feature mapping before leaving the factory. The physically unclonable functional module deployed in step S11 has self-testing logic. When capturing features in step S12, the system automatically identifies and masks unstable physical units that are susceptible to aging. The physical fingerprint generated in step S13 serves as the physical foundation for all subsequent security logic.

[0115] In step S2, to meet the bandwidth requirements of tens of thousands of terminals simultaneously initiating synchronization requests, the dynamic noise source server adopts a distributed deployment architecture. The environmental entropy value collected in step S21 is synchronized to various regional nodes via a dedicated secure backbone network. During step S22, each node independently generates a non-conflicting dynamic challenge value based on the activity level of its local metering instruments. During step S23, when issuing the challenge value, the load balancing algorithm of the data synchronization gateway ensures that every API call receives a response within milliseconds.

[0116] In step S3, the metering instrument terminal performs pipelined optimization on the complex excitation-response calculations. The long vector challenge value received in step S31 is decomposed into multiple subtasks for parallel processing. In step S32, the physical path switching logic is implemented using a high-speed switching matrix. The first response value generated in step S33 is compressed before transmission, reducing the communication load while retaining sufficient safety entropy.

[0117] In step S4, the measuring instrument management platform employs a hierarchical verification strategy. In step S41, the platform assigns certificate anchors of varying strengths based on the measuring instrument's grade (e.g., industrial, civilian, reference grade). In step S42, the terminal automatically invokes the corresponding encryption / decryption engine based on the anchor level. In step S43, the platform first performs preliminary screening based on fast hash matching, followed by deep verification based on quantum encryption algorithms. In step S44, the system asynchronously updates the certificate database using a message queue mechanism, ensuring that the system's responsiveness remains unaffected under large-scale concurrency.

[0118] Meanwhile, in this embodiment, the physical fingerprint inside the measuring instrument terminal is also used to encrypt and store local logs during the certificate synchronization process. This means that even if someone gains physical control of the measuring instrument and extracts the storage chip, they will not be able to read the instrument's past certificate synchronization records and sensitive calibration parameters due to the lack of the physical fingerprint as a decryption key. Furthermore, the dynamic noise source server is configured to have self-evolution capabilities, automatically adjusting the noise fusion ratio based on historical attack patterns to continuously improve the anti-predictability of the challenge value.

[0119] Example 6: This example describes in detail how, within the framework of the present invention, a complex fuzzy extraction and error correction process can be achieved through purely textual logical descriptions.

[0120] In step S13, the fuzzy extraction algorithm is logically constructed as follows: First, the system acquires a set of original bit sequences with random physical noise interference. To extract stable physical fingerprints from this unstable sequence, the system treats the original sequence as a point in a high-dimensional space during the generation process. Subsequently, the system selects a linear error-correcting code space and finds the bias vector of this point in the code space, defining this bias vector as auxiliary error-correcting data. In the subsequent reconstruction process, when the recaptured original sequence experiences bit flipping due to environmental changes, the system sums and merges the current interference sequence with the previously stored bias vector to obtain the test vector falling within the coverage of the error-correcting code. Next, by executing iterative decoding logic, the system finds the legal codeword with the closest logical distance to the test vector and maps this legal codeword back to the original fingerprint space. This process does not involve any algebraic formulas but is achieved through logical search and criterion selection of bits, ensuring accurate reconstruction of the physical fingerprint even without formulaic expression.

[0121] In step S22, the normalization processing logic is defined in detail as follows: The system first sets a baseline numerical range. For the collected environmental random parameters, the system calculates their mean and standard deviation in real time within the sliding time window. Subsequently, the system maps the current value to a preset discrete ladder set based on its position on the probability distribution curve. If the variation range of the current parameter exceeds the baseline range, the system automatically executes the interval scaling logic, that is, adjusts the threshold limit of the discrete ladder proportionally. Through this dynamic interval mapping, the original physical fluctuations are transformed into a series of uniformly distributed integer indices, and then the final external entropy value is generated through multiple rounds of logical XOR and bit shift operations.

[0122] In step S33, the logical flow of the nonlinear transformation is as follows: First, the physical response sequence is input into a logical permutation box, where each input bit is swapped to a new position according to a preset mapping table. Second, a bit diffusion operation is performed by dividing the permuted sequence into several groups, and performing a logical XOR operation on the bits within each group, so that a change in any input bit causes more than half of the output bits to flip. Third, a constant round key sequence is introduced, which is derived from a partial fragment of the physical fingerprint, and mixed with the diffusion-processed sequence. Through the above cascaded pure logical operations, the generated first response value possesses high pseudo-randomness and uniqueness.

[0123] In step S41, the textual implementation logic of the lattice cryptosystem is as follows: The system constructs a lattice structure defined by basis vectors in a high-dimensional space. The certificate anchor point generation process maps the hash features of the certificate to a target point in this high-dimensional space, and artificially superimposes small random perturbation vectors to make the point deviate from the lattice point. Since finding the lattice point closest to the target point without knowing the specific basis vectors (i.e., the private key derived from the physical fingerprint) is an extremely difficult mathematical problem, the certificate anchor point is essentially a lattice point description with perturbation information. In step S42, only terminals holding the correct physical fingerprint can use the basis vectors reconstructed from the fingerprint to accurately locate the original lattice point through a descrambling algorithm and restore the certificate's metadata. This logic ensures that security is entirely based on the uniqueness of the physical hardware.

[0124] The system in this embodiment achieves extremely high security through this purely logic-driven approach. When forwarding encrypted signaling, the data synchronization gateway executes message integrity verification logic. This logic calculates the cyclic redundancy characteristics of the message sequence and compares it with a preset verification sequence to ensure that no bit errors or malicious tampering occurred during transmission. When processing synchronization requests, the metering instrument management platform also performs frequency threshold determination based on the current system timestamp and historical synchronization cycles. If the synchronization frequency of a terminal exceeds the normal threshold, the system automatically determines that it has suffered a denial-of-service attack or replay attack and immediately suspends the terminal's API access permissions.

[0125] Example 7: This example focuses on the engineering implementation details of the heterogeneous noise acquisition module and the adaptive step size algorithm in the system.

[0126] The heterogeneous noise acquisition module in the dynamic noise source server is configured as multiple physically isolated sampling units. The power grid frequency acquisition unit obtains waveform data of the power lines through high-precision voltage transformers and uses zero-crossing detection technology to calculate the time difference between adjacent cycles, thus reflecting micro-frequency fluctuations. The wind speed acquisition unit acquires instantaneous sampling data of airflow velocity using ultrasonic anemometers deployed in different geographical locations. The environmental electromagnetic radiation acquisition unit uses a wideband antenna and a logarithmic amplifier to capture the envelope changes of background thermal noise.

[0127] The adaptive step-size algorithm mentioned in step S22 has the following logical execution process: The system first initializes the quantization step-size constant. During consecutive sampling periods, the system calculates the logical difference between two adjacent random parameter samples. If the difference exceeds a preset upper threshold for three consecutive periods, the system determines that the current physical noise has entered a period of severe fluctuation and immediately executes the step-size doubling logic to expand the sampling range. Conversely, if the difference is below a preset lower threshold, the system determines that the noise is in a period of weak fluctuation and executes the step-size halving logic to improve the sampling resolution. This logic ensures that no matter how the external environmental noise changes, the entropy value captured by the system can always fill the predetermined bit width, avoiding entropy loss.

[0128] In this embodiment, when the system executes step S44, if the comparison results match, the platform generates a digital signature based on blockchain technology and attaches this signature to the updated certificate information before returning it to the measuring instrument terminal. Upon receiving this data packet, the terminal uses its internal physical fingerprint to generate a checksum again and compares it with the digital signature. This two-way closed-loop verification logic ensures that not only can the platform identify the instrument, but the instrument can also identify a legitimate platform.

[0129] The internal security isolation zone of the measuring instrument terminal is also equipped with a physical shielding layer for side-channel analysis. This shielding layer is made of conductive polymer material, which can effectively absorb high-frequency electromagnetic radiation. At the same time, a miniature decoupling capacitor array is deployed on the power lines within the isolation zone to smooth current fluctuations during chip operation and prevent attackers from inferring physical fingerprints by analyzing power consumption trajectories.

[0130] In summary, the embodiments of this invention, by constructing a collaborative system of physically unclonable functional modules and dynamic noise injection, achieve atomic-level binding between the physical entity identity of measuring instruments and digital certificate information, fundamentally solving the problem of abuse caused by the disconnect between certificate and instrument identity in existing technologies. By deeply coupling the uncertainty of the physical layer, the randomness of the environment layer, and the encryption logic of the application layer, it breaks through the limitations of traditional security solutions that rely solely on software protocols, achieving seamless closed-loop management of measuring instrument identity and certificate information. While ensuring real-time data synchronization, it provides key technical support for building a highly reliable, physically attack-resistant digital metrological supervision system.

[0131] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention in any way. Although the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some modifications or alterations to the above-disclosed technical content to create equivalent embodiments without departing from the scope of the present invention. Any simple modifications, equivalent changes, and alterations made to the above embodiments based on the technical essence of the present invention without departing from the scope of the present invention shall still fall within the scope of the present invention.

Claims

1. A method for automatically synchronizing measuring instrument certificate information based on an encrypted application programming interface, characterized in that, Includes the following steps: Step S1: By using the physically unclonable functional module integrated inside the measuring instrument terminal, capture the logic state differences generated during the manufacturing process of the integrated circuit of the measuring instrument terminal, and extract the original physical bit stream with high entropy characteristics according to the logic state differences to generate a unique physical fingerprint, and use the physical fingerprint as the physical root key of the measuring instrument terminal. Step S2: The dynamic noise source server collects uncertain random physical quantities in the external physical environment in real time as the source of entropy value. After normalizing and hashing the random physical quantities to convert them into dynamic challenge values, the dynamic challenge values ​​are encapsulated in a message structure that conforms to the preset secure transmission protocol and sent to the metering instrument terminal through the encrypted application programming interface set at the data synchronization gateway. Step S3: The measuring instrument terminal inputs the dynamic challenge value as an excitation vector to the excitation end of the physical non-cloning functional module, drives the physical non-cloning functional module to generate the corresponding original physical response by combining the internal physical feature path, and performs feature compression and multi-round nonlinear transformation on the original physical response to generate a first response value that is deeply coupled with the physical entity identity and real-time environmental noise. Step S4: The measuring instrument management platform performs correlation verification based on the first response value and the pre-constructed quantum-encrypted certificate anchor. After the verification is successful, an end-to-end encrypted communication channel is established between the measuring instrument terminal and the measuring instrument management platform. The session key with one-time pad characteristics derived from the first response value is used to ensure the security of the data transmission process, thereby realizing the automatic synchronization and status alignment of the measuring instrument certificate information.

2. The method for automatic synchronization of measuring instrument certificate information based on an encrypted application programming interface according to claim 1, characterized in that, Step S1 specifically includes the following steps: Step S11: Deploy an oscillator array or metastable detection circuit composed of multiple logic units in the integrated circuit of the measuring instrument terminal. The oscillator array is a closed loop formed by a series of inverters connected end to end. Step S12: Under the trigger of the preset start command, capture the phase difference between two ring oscillators with identical structures caused by the non-uniformity of semiconductor manufacturing process at the nanoscale, and quantize and sample the phase difference to obtain raw data reflecting the physical characteristics of the chip. Step S13: Denoise and error correction are performed on the captured original data using a fuzzy extraction algorithm to extract a bit stream with high entropy characteristics, which is used as the physical fingerprint.

3. The method for automatic synchronization of measuring instrument certificate information based on an encrypted application programming interface according to claim 2, characterized in that, The fuzzy extraction algorithm in step S13 includes a generation process and a reconstruction process; The generation process is configured to treat the original data as feature vector points in a high-dimensional space, select a linear error correction code space and find the bias vector of the feature vector points in the code space, and define the bias vector as auxiliary error correction data. The reconstruction process is configured to, when the physical non-cloning function module is called in a subsequent step, use the original interference data captured in the current instant and the previously stored auxiliary error correction data to find the legal codeword that is closest to the logical distance of the vector to be tested by executing iterative decoding logic, and map the legal codeword back to the original fingerprint space to restore the accurate and consistent physical fingerprint. The physical fingerprint is configured to exist only momentarily in the register during the operation and be physically erased after the authentication operation is completed, and is prohibited from being stored in non-volatile storage media.

4. The method for automatic synchronization of measuring instrument certificate information based on an encrypted application programming interface according to claim 3, characterized in that, Step S2 specifically includes the following steps: Step S21: Extract the uncertain random physical quantity from the preset external physical environment through the dynamic noise source server. The random physical quantity includes power grid frequency perturbation data, instantaneous wind speed fluctuation data, or environmental electromagnetic radiation noise envelope. Step S22: Perform adaptive step-size quantization processing on the extracted random physical quantity, dynamically adjust the threshold limit of the quantization ladder according to the rate of change of the random physical quantity within the sliding time window, convert the original physical fluctuation into a uniformly distributed integer index, and generate the dynamic challenge value through multiple rounds of logical XOR and bit shifting operations. Step S23: The dynamic challenge value is sent to the measuring instrument terminal through the encrypted application programming interface, wherein the dynamic challenge value is configured to have temporal instantaneity and spatial uniqueness.

5. The method for automatic synchronization of measuring instrument certificate information based on an encrypted application programming interface according to claim 4, characterized in that, Step S3 specifically includes the following steps: Step S31: The metering instrument terminal inputs the received dynamic challenge value as the excitation vector of the physically unclonable functional module to the excitation end. The dynamic challenge value determines the selection order and combination method of the oscillator pairs participating in the calculation. Step S32: The physically unclonable functional module generates a corresponding physical response under the drive of the excitation vector, combined with the internal physical feature path. Step S33: Perform a nonlinear transformation on the physical response, the nonlinear transformation including: inputting the physical response sequence into a logic permutation box to perform bit position swapping; Performing a bit spread operation causes a change in any input bit to cause more than half of the output bits to be flipped. A constant round key sequence derived from the physical fingerprint is introduced and mixed with the diffused sequence to generate the first response value.

6. The method for automatic synchronization of measuring instrument certificate information based on an encrypted application programming interface according to claim 5, characterized in that, Step S4 specifically includes the following steps: Step S41: Based on the original registration information of the measuring instrument terminal, the measuring instrument management platform uses the hash feature value of the digital certificate, the derived key of the physical fingerprint, and the benchmark challenge value during the first authentication as input parameters, and uses a multivariate public key cryptography algorithm based on lattice cryptography to construct a quantum-encrypted certificate anchor point, and sends the certificate anchor point to the measuring instrument terminal. Step S42: The measuring instrument terminal uses the currently generated first response value as the generation factor of the decryption key, performs a fusion operation on the first response value and the locally pre-stored guiding vector to generate a temporary symmetric key, parses the locally stored certificate anchor point, and obtains the metadata of the certificate to be synchronized. Step S43: The measuring instrument terminal sends the first response value, the metadata of the certificate to be synchronized, and the synchronization request containing high-precision timestamps and geographical location features to the measuring instrument management platform for consistency comparison. Step S44: If the comparison results are consistent, the measuring instrument management platform updates the verification validity period and calibration parameters of the measuring instrument terminal and completes the synchronization of certificate information.

7. The method for automatic synchronization of measuring instrument certificate information based on an encrypted application programming interface according to claim 6, characterized in that, If the comparison results are inconsistent when performing step S4, the measuring instrument management platform will initiate a security warning process, lock the unique identifier of the measuring instrument terminal, record the currently collected environmental noise characteristics and response anomaly patterns, and use the abnormal traffic monitoring engine to identify abnormal call requests with scanning, detection or injection characteristics.

8. The method for automatic synchronization of measuring instrument certificate information based on an encrypted application programming interface according to claim 7, characterized in that, The first response value is configured as the basis for negotiation of the session key. The entropy feature of the first response value is injected into the key scheduling algorithm of the symmetric encryption algorithm by executing the spread diffusion algorithm to generate a session key with one-time pad characteristics. The encrypted communication channel supports a multi-path redundancy transmission protocol and automatically switches to the backup spectrum when the main communication link is interfered with.

9. The method for automatic synchronization of measuring instrument certificate information based on an encrypted application programming interface according to claim 8, characterized in that, The physical fingerprint is configured to encrypt and store the local logs inside the measuring instrument terminal. Any read operation on the local logs requires calling the physical non-cloning function module to reconstruct the fingerprint in real time.

10. An automatic synchronization system for measuring instrument certificate information based on an encrypted application programming interface, characterized in that, For implementing the method as described in any one of claims 1 to 9, the system comprises: a measuring instrument terminal, with a built-in physically unclonable function module, the physically unclonable function module being configured to generate a physical fingerprint based on hardware micro-process deviations and perform an excitation-response operation to generate a first response value. A dynamic noise source server is connected to an external physical environment sensor. The dynamic noise source server is configured to collect random physical quantities in real time and generate dynamic challenge values. The data synchronization gateway is configured with an encrypted application programming interface. The data synchronization gateway is configured to forward encrypted signaling and perform message integrity verification between the metering instrument terminal, the dynamic noise source server and the metering instrument management platform. The measuring instrument management platform is configured to store a digital certificate library, generate certificate anchors, and perform association verification based on the first response value.