An identity authentication method and system based on a PUF double-stimulation pair mechanism

CN122802160APending Publication Date: 2026-09-22Chinese People's Liberation Army Cyberspace Force Information Engineering University
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610761574.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-05-29
Publication Date
2026-09-22

AI Technical Summary

Technical Problem

[0008]针对现有技术中的强PUF应用的安全、开销等问题,本发明提供一种基于PUF双激励对机制的身份认证方法和系统,使设备中强PUF相关信息可以公开传输和存储,解决CRP传输和存储的安全和开销问题

Benefits of technology

[0035]本发明提出了一种PUF的双激励对机制,解决了传输、存储CRP时面临数据泄露问题,使得PUF能够以最低的成本实现最安全的设备物理防护。同时,本发明为无服务器参与的低能源设备间的交互应用提供了一种新颖的解决方案。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122802160A_ABST
    Figure CN122802160A_ABST
Patent Text Reader

Abstract

The application provides an identity authentication method and system based on a PUF double-stimulation pair mechanism. The method server first establishes PUF models of communication equipment of two parties according to stimulation response pairs of the communication equipment of the two parties; then uses the established PUF models of the communication equipment of the two parties to construct double-stimulation pairs required for authentication for the communication equipment of the two parties and sends the double-stimulation pairs to the communication equipment of the two parties; the communication equipment of the two parties stores the received double-stimulation pairs, uses a stimulation corresponding to itself in the stored double-stimulation pairs to perform PUF calculation locally to generate a response, selects a random number to encrypt the response and generate first verification information, and sends the encrypted information and the first verification information to the other communication equipment, so that the other communication equipment recovers the random number in the encrypted information by using the double-stimulation pair agreement and generates second verification information by using the recovered random number; if the first verification information and the second verification information are consistent, the authentication of the communication equipment of the two parties is passed, otherwise the authentication is failed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of security application technology of Physically Unclonable Functions (PUFs), and in particular to an identity authentication method and system based on a PUF dual-incentive pair mechanism. Background Technology

[0002] PUF, as a novel type of hardware security primitive, relies on the physical entity's own parameters to provide a unique identity, achieving keyless storage and effectively solving the problem of key leakage. Combined with its inherent tamper-proof and lightweight characteristics, PUF demonstrates broad application prospects and enormous commercial potential in areas such as lightweight authentication, key generation, and privacy protection.

[0003] Based on the relationship between the size of the incentive response pairs (CRPs) provided externally and the number of underlying hardware units, PUFs can be divided into weak PUFs and strong PUFs. Weak PUFs can provide a smaller number of CRPs, typically linearly related to the number of underlying hardware components, and are generally used as hardware keys. Strong PUFs, due to their high entropy content, can provide a large number of CRPs, with the number of CRPs showing an exponential relationship to the number of underlying hardware components, and are considered a viable alternative to traditional security mechanisms.

[0004] In identity authentication applications, each device relies on its own strong PUF to provide identity information. When devices authenticate each other, in addition to possessing their own strong PUF, each device must also have the strong PUF information of the other party. This information typically exists in the form of the software model of the other party's strong PUF or CRP data. These traditional methods have the following problems and shortcomings:

[0005] 1) The method of storing the other party's strong PUF model has serious security problems. Once a single device is captured, all PUF models stored on that device will be leaked. Even using encrypted model storage is difficult to fundamentally prevent model leakage. Attackers may obtain the model parameters from memory and then carry out spoofing attacks.

[0006] 2) The way CRP data is stored also poses a risk of data leakage. Although the stored CRP is usually small in scale and the harm caused by leakage is less than that caused by model leakage, attackers may use the leaked CRP to carry out modeling attacks and learn the corresponding PUF model.

[0007] 3) CRP data typically needs to be supplemented or updated during system operation. The server stores PUF models of all devices and sends CRP data to each device in real time as needed. This communication process requires encrypting the CRP data, which introduces additional overhead to the system. Summary of the Invention

[0008] To address the security and overhead issues of strong PUF applications in existing technologies, this invention provides an identity authentication method and system based on a PUF dual-incentive pair mechanism, enabling the public transmission and storage of strong PUF-related information in devices, thus resolving the security and overhead issues of CRP transmission and storage.

[0009] In a first aspect, the present invention provides an identity authentication method based on a PUF dual-incentive pair mechanism, comprising:

[0010] The server obtains the incentive response pairs dataset from both communicating devices;

[0011] The server builds a PUF model of both communication devices based on the stimulus responses of both devices in the dataset.

[0012] The server uses its own established PUF model for both communication devices to construct the dual incentive pairs required for authentication and sends them to both communication devices. The dual incentive pairs refer to the data combination formed by two incentives, and satisfy the following convention: the response obtained by one incentive after being calculated by the PUF model of one communication device is equal to the response obtained by the other incentive after being calculated by the PUF model of the other communication device.

[0013] Both communication devices store the received dual-excitation pair, perform PUF calculation locally using the corresponding excitation from the stored dual-excitation pair to generate a response, and select a random number to encrypt the response and generate first verification information. The encrypted information and the first verification information are sent to the other communication device, so that the other communication device can use the agreement to recover the random number in the encrypted information and use the recovered random number to generate second verification information. If the first verification information and the second verification information are consistent, the two communication devices authenticate successfully; otherwise, the authentication fails.

[0014] Furthermore, the server acquires the stimulus-response pair dataset of both communicating devices, including:

[0015] The server generates incentive datasets for both communicating devices and sends them to both devices.

[0016] After receiving their respective incentive datasets, both communication devices perform PUF calculations locally using their respective incentive datasets to generate response datasets, and return their respective response datasets to the server. The server integrates the incentive datasets and response datasets of both communication devices to obtain the incentive-response pair datasets of both communication devices.

[0017] Furthermore, it also includes: after the dual-incentive pairs stored locally by both communication devices are exhausted, the server reconstructs new dual-incentive pairs required for authentication using the PUF model of both communication devices established by itself, for subsequent continuous device authentication.

[0018] Furthermore, the server utilizes its established PUF model for both communication devices to construct the dual-incentive pair required for authentication and sends it to both communication devices, including:

[0019] The server randomly generates incentives. And receive a random number from one of the communication devices A. and a random number from another communication device B ;

[0020] The server utilizes the PUF model of its own communication device A. For the incentive Calculate the response ;

[0021] The server uses the random number Identification of the communication device A Encryption is performed to generate ciphertext identity. ;

[0022] The server utilizes the PUF model of its own communication device B. Selection Incentives Make the response and using the random number Identification of the communication device B Encryption is performed to generate ciphertext identity. ;

[0023] The server will send messages Send to communication devices A and B, where The two-incentive pair required for the constructed authentication is represented by i and j, where i and j are the incentive numbers.

[0024] Further, the step of using the stored dual-excitation pair to perform PUF calculation locally to generate a response, selecting a random number to encrypt the response and generate first verification information, and sending the encrypted information and first verification information to the other party's communication device includes:

[0025] Communication device A selects a random number Record the current timestamp Then, using the local PUF model Incentives Calculate the response Encrypted information and first verification information and send a verification message. Give the other party communication device B.

[0026] Furthermore, the counterparty communication device uses the agreement to recover the random number in the encrypted information and uses the recovered random number to generate second verification information, including:

[0027] After receiving the verification message sent by communication device A, communication device B records the current timestamp. According to timestamp and timestamp Determine whether the verification message is valid. If it is valid, communication device B uses its local PUF model. Incentives Calculate the response Thus, the encrypted information can be recovered. random numbers in And using the recovered random numbers Generate second verification information .

[0028] Secondly, the present invention provides an identity authentication system based on a PUF dual-incentive pair mechanism, comprising: a server and a communication device;

[0029] The server is used to obtain the incentive response pair dataset of both communication devices; to establish a PUF model of both communication devices based on the incentive response pair dataset; and to construct the dual incentive pairs required for authentication for both communication devices using the PUF model it has established and send them to both communication devices. The dual incentive pair refers to a data combination formed by two incentives, satisfying the following convention: the response obtained after one incentive is calculated by the PUF model of one communication device is equal to the response obtained after the other incentive is calculated by the PUF model of the other communication device.

[0030] A communication device is used to store the received dual-excitation pair, perform PUF calculation locally using the excitation corresponding to itself in the stored dual-excitation pair to generate a response, select a random number to encrypt the response and generate first verification information, and send the encrypted information and the first verification information to the other party's communication device so that the other party's communication device can use the agreement to recover the random number in the encrypted information and use the recovered random number to generate second verification information. If the first verification information and the second verification information are consistent, the two communication devices authenticate each other; otherwise, the authentication fails.

[0031] Thirdly, the present invention provides an electronic device including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, implements the method as described in the first aspect.

[0032] Fourthly, the present invention provides a non-transitory computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the method described in the first aspect.

[0033] Fifthly, the present invention provides a computer program product, including a computer program that, when executed by a processor, implements the method described in the first aspect.

[0034] The beneficial effects of this invention are as follows:

[0035] This invention proposes a dual-excitation pair mechanism for PUF (Power-Only Function) to solve the data leakage problem faced during the transmission and storage of CRP (Content Retention Function), enabling PUF to achieve the most secure physical protection of devices at the lowest cost. Simultaneously, this invention provides a novel solution for serverless, low-energy device interaction applications. Attached Figure Description

[0036] Figure 1 A flowchart illustrating an identity authentication method based on a PUF dual-incentive pair mechanism provided in an embodiment of the present invention;

[0037] Figure 2 This is a schematic diagram of a simulation of an identity authentication system based on a PUF dual-incentive pair mechanism, provided as an embodiment of the present invention.

[0038] Figure 3 This is a schematic diagram of the device registration stage provided in an embodiment of the present invention;

[0039] Figure 4 A schematic diagram of the device certification stage provided in an embodiment of the present invention.

[0040] Figure 5 This is a structural block diagram of an electronic device provided in an embodiment of the present invention. Detailed Implementation

[0041] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of the embodiments of this invention will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0042] like Figure 1As shown, this embodiment of the invention provides an identity authentication method based on a PUF dual-incentive pair mechanism, including the following steps:

[0043] S101: The server obtains the stimulus-response pair dataset from both communicating devices;

[0044] S102: The server establishes a PUF model for both communication devices based on the stimulus responses of both parties in the dataset;

[0045] S103: The server uses its own established PUF model for both communication devices to construct the dual incentive pair required for authentication for both communication devices and sends it to both communication devices; the dual incentive pair refers to the data combination formed by two incentives, and satisfies the following convention: the response obtained after one incentive is calculated by the PUF model of one communication device is equal to the response obtained after the other incentive is calculated by the PUF model of the other communication device.

[0046] Specifically, a challenge-challenge pair (CCP) refers to a data combination formed by two stimuli. The two stimuli correspond to different PUFs. Assume communication device A has... Communication device B possesses ,excitation The response obtained after inputting PUF is denoted as The prerequisite for communication device A to verify the identity of communication device B is that communication device A possesses... Information or CRP. Assume a dual-excitation pair. middle for Incentives for When constructing a two-incentive pair, the following relationship must be satisfied:

[0047] (1)

[0048] Through dual incentives Communication device A can obtain information from communication device B. CRP. for Incentives, communication device A through its own It can be obtained However, based on the limitations of formula (1), and Equal. This means that communication device A, through its own... It can be used as a dual-excitation pair Transform into CRP: The above process can be described by the following formula:

[0049] (2)

[0050] It is important to note here that dual incentives... Corresponding communication device B can also use its own The dual incentive pair Transform into CRP: .

[0051] S104: Both communication devices store the received dual-excitation pair, use the corresponding excitation in the stored dual-excitation pair to perform PUF calculation locally to generate a response, and select a random number to encrypt the response and generate first verification information. The encrypted information and the first verification information are sent to the other communication device so that the other communication device can use the agreement to recover the random number in the encrypted information and use the recovered random number to generate second verification information. If the first verification information and the second verification information are consistent, the two communication devices authenticate successfully; otherwise, the authentication fails.

[0052] S105: After the dual-incentive pairs stored locally by both communication devices are exhausted, the server reconstructs new dual-incentive pairs required for authentication using the PUF model of both communication devices established by itself, for subsequent continuous device authentication.

[0053] When used for authentication, the dual-incentive pair mechanism can implement both centralized and decentralized authentication. This embodiment belongs to a centralized authentication scenario, which includes a server and terminal nodes. The server is generally considered secure, storing the PUF model of all terminal nodes, eliminating the risk of leakage. Each terminal node deploys a PUF, but does not store the PUF models of other nodes; a storage area is provided for storing the dual-incentive pair data. The authentication method based on the PUF dual-incentive pair mechanism provided in this embodiment has the following advantages: 1) It hides the response information from the outside world, enhancing security. Even if the dual-incentive pair is obtained by an attacker, due to the attacker's lack of... or 1) The physical entities of the two PUFs cannot be identified, thus preventing modeling attacks. 2) Updating the dual stimulus pairs during authentication does not require encryption, reducing computational and communication overhead. 3) Dual stimulus pairs are abundant, allowing for the division of stimuli into different regions for selection, facilitating the implementation of different security management strategies.

[0054] Based on the above embodiments, the identity authentication system provided by the present invention includes a server and a communication device, which are applied to, for example... Figure 2In the application scenario shown, the ground station acts as the server, and satellites A and B are communication devices A and B that need to authenticate each other. According to the authentication method provided in this embodiment of the invention, the authentication process between satellites A and B is as follows: Figure 3 and Figure 4 As shown, it includes: initialization phase, registration phase, authentication phase and update phase;

[0055] (I) Initialization Phase

[0056] During the initialization phase, the server assigns a unique real identity ID to each device and publicly selects a one-way hash function. Each device embeds a unique PUF circuit.

[0057] (II) Registration Stage

[0058] (1) Device A initiates a registration request to the server and sends... The server generates incentives randomly. and send The stimulus is given to device A. Device A performs PUF calculation based on the received stimulus. and will The results are returned to the server. The server then builds a model of the PUF chip held by device A based on the collected CRPs. and store Next, device A randomly generates a random number. And send it to the server. Similarly, device B and the server also perform the above-mentioned interactions, and the server also stores device B's... Device B randomly generates a random number. And send it to the server.

[0059] (2) After modeling the PUF chips held by communication devices A and B, the server needs to construct the dual-incentive pair required for authentication for both communication devices. First, the server randomly generates incentives. Using the PUF model of device A that it has built itself calculate Then, the server uses the PUF model based on device B. Selection Incentives Make Upon receiving random numbers sent by devices A and B respectively. and Then, the server constructs temporary identities respectively. and Finally, the server sends... Assign data to devices A and B. Devices A and B store data respectively. The registration process is as follows: Figure 3 As shown.

[0060] (III) Certification Stage

[0061] (1) When device A needs to perform two-way authentication with device B, device A first selects a random number. Record the current timestamp Then calculate the response. Encrypted information and verify hash and send Give it to device B.

[0062] (2) Device B receives the information sent by Device A. Then, first verify the time. ,in, The validity period applies. If it is within the validity period, equipment B calculates... Restore random numbers Generate verification hash Then verify Is it true or false? If the verification passes, then B verifies A.

[0063] (3) Device B selects a random number. Record the current timestamp Then calculate the unique session key. ,calculate To encrypt random numbers Simultaneously calculate the verification hash ,send Give it to device A.

[0064] (4) Device A receives information sent by Device B. Then, first verify the time. If it is within the validity period, equipment A calculates Session key ,calculate and verify Is the verification successful? If so, A verifies B. Used incentive pairs will be deleted after each successful mutual authentication.

[0065] (iv) Update phase

[0066] After the dual-stimulus pairs used for authentication stored in devices A and B are used up, the server regenerates new stimulus pairs using the stored PUF model for subsequent continuous device authentication. Specifically, the server randomly generates new stimulus pairs. Using the PUF model of device A calculate Then, the server uses the PUF model based on device B. Selection Incentives Make Upon receiving new random numbers sent by devices A and B respectively and Then, the server constructs temporary identities respectively. and and send Assign data to devices A and B. Devices A and B store data respectively. The embodiments of this invention, based on informal security analysis, demonstrate that the invention satisfies common security attributes and can resist common network attacks such as man-in-the-middle and replay attacks, as well as physical capture attacks on devices. Specific implementation is as follows:

[0067] (1) Mutual authentication G1: In the protocol of this invention, device A first sends an authentication request to device B. Device B generates relevant parameters and verifies them. Whether the verification is successful is used to confirm the legitimacy of device A's identity. Similarly, device A passes the verification... Whether the condition is met is used to verify the legitimacy of device B's identity. Therefore, the protocol of this invention supports mutual authentication.

[0068] (2) Secure session key: After device A and device B mutually authenticate and confirm each other's legitimate identity, device B generates a response based on its own PUF. Random numbers generated by yourself and use Decrypted random number from end A Generate session key Device A also uses its own PUF response. random numbers and Build session key Because of the dual-excitation pair mechanism of this invention, Each response is protected by its own PUF, and random numbers are generated. and By using encrypted transmission, the protocol of this invention supports secure session keys.

[0069] (3) Anonymity and non-linkability: This invention employs a dynamic temporary identity mechanism. During the authentication process, both parties use temporary identities. Replace real identity The devices interact with each other in a way that avoids the plaintext transmission of their real identities over public channels, thus achieving anonymity. After authentication, each device's temporary identity is dynamically updated independently, preventing attackers from connecting to the same device using a temporary identity, thereby ensuring unlinkability.

[0070] (4) Forward confidentiality: In this invention, the session key or With PUF response or random numbers and Binding is performed. The PUF response is also included. and All are physically protected by their own PUF circuits and are dynamically updated after each authentication, while the random number... and It is also updated synchronously after use. Since these transient parameters are unrelated to the long-term key, a leak of the long-term key will not affect its security. Therefore, attackers cannot reconstruct past session keys.

[0071] (5) Simulated attack: If an attacker wants to impersonate device A, they need to forge messages. However, due to the physical non-cloning nature of PUF circuits, attackers cannot obtain the key without a PUF. Then construct an effective encrypted message Therefore, an attacker cannot impersonate device A. Similarly, if an attacker wanted to impersonate device B, they would need to forge messages. However, due to the physical non-cloning nature of PUF circuits, attackers cannot obtain the key without a PUF. Then construct an effective encrypted message Therefore, attackers cannot impersonate device B. This invention can defend against device emulation attacks.

[0072] (6) Man-in-the-middle attack: In this invention, device A and device B send messages respectively and This interaction enables mutual authentication. If an attacker wants to launch a man-in-the-middle attack by intercepting and modifying this information, they would need to construct a legitimate message. However, once... and If a change is sent, the verification device will be unable to verify it through its own response. and Decrypt random numbers and Therefore, it becomes impossible to synthesize the correct verification information. and Verification has been successful. Therefore, this invention can resist man-in-the-middle attacks.

[0073] (7) Replay Attack: This invention uses a combination of random numbers and timestamps to prevent replay attacks. Device A and Device B each generate random numbers. and and timestamp and Both parties verify the freshness of the timestamp after receiving each other's message. Furthermore, a random number is generated for each session. and Each message is generated independently and updated synchronously. Therefore, attackers cannot pass authentication by replaying previous messages. This invention can resist replay attacks.

[0074] (8) Device physical capture attack: The session key SK is generated from the critical PUF response. and These parameters are generated by the communication device based on its internal PUF circuitry. Due to the inherent unpredictability and non-cloning nature of PUFs, attackers cannot recover the correct response values ​​even if the device is physically captured. Therefore, this protocol effectively defends against physical capture attacks.

[0075] Based on the same inventive concept, embodiments of the present invention provide an identity authentication system based on a PUF dual-incentive pair mechanism, comprising: a server and a communication device;

[0076] The server is used to obtain the incentive response pair dataset of both communication devices; to establish a PUF model of both communication devices based on the incentive response pair dataset; and to construct the dual incentive pairs required for authentication for both communication devices using the PUF model it has established and send them to both communication devices. The dual incentive pair refers to a data combination formed by two incentives, satisfying the following convention: the response obtained after one incentive is calculated by the PUF model of one communication device is equal to the response obtained after the other incentive is calculated by the PUF model of the other communication device.

[0077] A communication device is used to store the received dual-excitation pair, perform PUF calculation locally using the excitation corresponding to itself in the stored dual-excitation pair to generate a response, select a random number to encrypt the response and generate first verification information, and send the encrypted information and the first verification information to the other party's communication device so that the other party's communication device can use the agreement to recover the random number in the encrypted information and use the recovered random number to generate second verification information. If the first verification information and the second verification information are consistent, the two communication devices authenticate each other; otherwise, the authentication fails.

[0078] It should be noted that the identity authentication system based on the PUF dual-incentive pair mechanism provided in this embodiment of the invention is for the purpose of the above-described method. Its specific functions can be referred to in the above-described method embodiments, and will not be repeated here.

[0079] Figure 5 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 5As shown, the electronic device may include: a processor 501, a communication interface 502, a memory 503, and a communication bus 504. The processor 501, communication interface 502, and memory 503 communicate with each other via the communication bus 504. The processor 501 can call logical instructions in the memory 503 to execute an authentication method based on a PUF dual-incentive pair mechanism. This method includes: a server acquiring a dataset of incentive response pairs between the two communication devices; the server establishing a PUF model for both communication devices based on the incentive response pair dataset; and the server using its established PUF model to construct the dual-incentive pair required for authentication between the two communication devices and sending it to both communication devices. The dual-incentive pair refers to a data combination formed by two incentives, satisfying the following convention: one incentive is obtained after calculation by the PUF model of one of the communication devices. The response is equal to the response obtained after calculation by the PUF model of another communication device using another stimulus; both communication devices store the received dual stimulus pair, use the stimulus corresponding to themselves in the stored dual stimulus pair to perform PUF calculation locally to generate a response, and select a random number to encrypt the response and generate first verification information. The encrypted information and the first verification information are sent to the other communication device so that the other communication device can use the agreement to recover the random number in the encrypted information and use the recovered random number to generate second verification information. If the first verification information and the second verification information are consistent, the two communication devices authenticate successfully; otherwise, the authentication fails.

[0080] Furthermore, when the logical instructions in the aforementioned memory 503 are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0081] This invention also provides a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions, and when the program instructions are executed by a computer, the computer can execute an identity authentication method based on a PUF dual-incentive pair mechanism provided in the above-described method embodiments.

[0082] This invention also provides a non-transitory computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements an identity authentication method based on a PUF dual-excitation pair mechanism provided in the above-described method embodiments.

[0083] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0084] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. An identity authentication method based on a PUF dual-incentive pair mechanism, characterized in that, include: The server obtains the incentive response pairs dataset from both communicating devices; The server builds a PUF model of both communication devices based on the stimulus responses of both devices in the dataset. The server uses its own established PUF model for both communication devices to construct the dual incentive pairs required for authentication and sends them to both communication devices. The dual incentive pairs refer to the data combination formed by two incentives, and satisfy the following convention: the response obtained by one incentive after being calculated by the PUF model of one communication device is equal to the response obtained by the other incentive after being calculated by the PUF model of the other communication device. Both communication devices store the received dual-excitation pair, perform PUF calculation locally using the corresponding excitation from the stored dual-excitation pair to generate a response, and select a random number to encrypt the response and generate first verification information. The encrypted information and the first verification information are sent to the other communication device, so that the other communication device can use the agreement to recover the random number in the encrypted information and use the recovered random number to generate second verification information. If the first verification information and the second verification information are consistent, the two communication devices authenticate successfully; otherwise, the authentication fails.

2. The identity authentication method based on the PUF dual-incentive pair mechanism according to claim 1, characterized in that, The server acquires a dataset of stimulus-response pairs between the two communicating devices, including: The server generates incentive datasets for both communicating devices and sends them to both devices. After receiving their respective incentive datasets, both communication devices perform PUF calculations locally using their respective incentive datasets to generate response datasets, and return their respective response datasets to the server. The server integrates the incentive datasets and response datasets of both communication devices to obtain the incentive-response pair datasets of both communication devices.

3. The identity authentication method based on the PUF dual-incentive pair mechanism according to claim 1, characterized in that, Also includes: Once the dual-incentive pairs stored locally by both communicating devices are exhausted, the server reconstructs new dual-incentive pairs required for authentication using the PUF model of both communicating devices that it has established, for subsequent continuous device authentication.

4. The identity authentication method based on the PUF dual-incentive pair mechanism according to claim 1, characterized in that, The server utilizes its own established PUF model for both communication devices to construct the dual-incentive pair required for authentication and sends it to both communication devices, including: The server randomly generates incentives. And receive a random number from one of the communication devices A. and a random number from another communication device B ; The server utilizes the PUF model of its own communication device A. For the incentive Calculate the response ; The server uses the random number Identification of the communication device A Encryption is performed to generate ciphertext identity. ; The server utilizes the PUF model of its own communication device B. Selection Incentives Make the response and using the random number Identification of the communication device B Encryption is performed to generate ciphertext identity. ; The server will send messages Send to communication devices A and B, where The two-incentive pair required for the constructed authentication is represented by i and j, where i and j are the incentive numbers.

5. The identity authentication method based on the PUF dual-incentive pair mechanism according to claim 4, characterized in that, The process of using the stored dual-excitation pair to perform PUF calculation locally to generate a response, selecting a random number to encrypt the response and generate first verification information, and sending the encrypted information and first verification information to the other party's communication device includes: Communication device A selects a random number Record the current timestamp Then, using the local PUF model Incentives Calculate the response Encrypted information and first verification information and send a verification message. Give the other party communication device B.

6. The identity authentication method based on the PUF dual-incentive pair mechanism according to claim 5, characterized in that, The other party's communication device uses the agreement to recover the random number in the encrypted information and uses the recovered random number to generate second verification information, including: After receiving the verification message sent by communication device A, communication device B records the current timestamp. According to timestamp and timestamp Determine whether the verification message is valid. If it is valid, communication device B uses its local PUF model. Incentives Calculate the response Thus, the encrypted information can be recovered. random numbers in And using the recovered random numbers Generate second verification information .

7. An identity authentication system based on a PUF dual-incentive pair mechanism, characterized in that, include: Servers and communication equipment; The server is used to obtain the stimulus-response pair datasets from both communicating devices. Based on the incentive responses of both communication devices, a PUF model for both communication devices is established on the dataset. Using the PUF model established by the communication devices, a dual incentive pair required for authentication is constructed for both communication devices and sent to both communication devices. The dual incentive pair refers to a data combination formed by two incentives, and satisfies the following convention: the response obtained by one incentive after being calculated by the PUF model of one communication device is equal to the response obtained by the other incentive after being calculated by the PUF model of the other communication device. A communication device is used to store the received dual-excitation pair, perform PUF calculation locally using the excitation corresponding to itself in the stored dual-excitation pair to generate a response, select a random number to encrypt the response and generate first verification information, and send the encrypted information and the first verification information to the other party's communication device so that the other party's communication device can use the agreement to recover the random number in the encrypted information and use the recovered random number to generate second verification information. If the first verification information and the second verification information are consistent, the two communication devices authenticate each other; otherwise, the authentication fails.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the method as described in any one of claims 1 to 6.

9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1 to 6.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method of any one of claims 1 to 6.