The application relates to the technical field of
Internet of Things equipment security, and particularly discloses a device unique identity generation and trusted certification method and
system, which comprises the following steps: in the device identity endogenous initialization stage, a secure
password chip generates a device unique identity seed based on a PUF circuit and a
password hash function, takes the device unique identity seed as a deterministic random entropy source to endogenously generate public and private keys, and uses the private key to issue a self-signed device
certificate for the public key; in the device network access registration stage, a device
identity management platform verifies the signature value and extended information of the signed device
certificate, and after
verification, issues a device identity
certificate for the public key; in the device running stage, the
verification party sends a true random number to the device as a challenge, the secure
password chip generates a certification signature, and the device identity certificate,
system state information and the certification signature are sent to the
verification party for verification. The application can ensure that the identity of each device and each
chip is absolutely unique, and fundamentally eliminates certificate replication and hardware counterfeiting.