Related Experiment Videos
A Lightweight Certificateless Identity Authentication Protocol Using SM2 Algorithm and Self-Secured PUF for IoT
Meili Zhang1, Qianqian Zhao2, Chao Li1
1Hubei Provincial Research Institute of Water Resources and Hydropower, Wuhan 430070, China.
Abstract:
The rapid proliferation of the Internet of Things (IoT) leaves terminal devices vulnerable to considerable security challenges, notably the absence of robust yet efficient identity authentication mechanisms. Traditional certificate-based approaches incur substantial management overhead and storage expenditure, whereas Identity-Based Cryptography poses inherent key escrow risks. To tackle these challenges, this paper proposes a PUF and SM2-based certificateless identity authentication mechanism that integrates SM2 Certificateless Public Key Cryptography (a Chinese national cryptographic standard) with Physical Unclonable Functions (PUFs). Initially, the proposed solution utilizes PUF technology to derive a unique hardware-generated "fingerprint" from an IoT device, which functions as a root key to generate a partial user private key. This approach essentially binds the terminal's identity to its physical hardware, thereby effectively mitigating physical cloning attacks against nodes. Moreover, through the adoption of a Certificateless Public Key Cryptography (CLPKC) framework, the complete user private key is jointly generated by a semi-trusted Key Generation Centre (KGC) and the terminal device itself. The comprehensive security analysis proves that the proposed scheme is provably secure under the random oracle model, capable of resisting various common attacks such as physical cloning, man-in-the-middle, and replay attacks. Performance evaluation confirms that the implemented PUF + SM2 certificateless mechanism significantly reduces the size of user public key identifiers to within 64 bytes, offering a substantial advantage over the 1-2 KB certificates typically required in conventional PKI/CA systems, thereby enhancing efficiency in storage and communication.
Related Concept Videos
Strategies of Self-Presentation II: Self-Verification
Role-Based Identity
PPE Use in Healthcare Settings I: Donning