Related Experiment Video
Updated: Sep 16, 2026

Large Scale Energy Efficient Sensor Network Routing Using a Quantum Processor Unit
Published on: September 8, 2023
Secure UPnP Resource Discovery Using a PUF-Assisted Hardware Accelerator for IoT
Kasem Khalil1,2
1Electrical and Computer Engineering Department, University of Mississippi, Oxford, MS 38677, USA.
Abstract:
Universal Plug and Play (UPnP) is widely used for resource discovery in internet of things and smart-edge environments because of its lightweight and decentralized operation. However, conventional UPnP and Simple Service Discovery Protocol (SSDP) mechanisms expose static identifiers and service metadata, making them vulnerable to spoofing, replay, unauthorized resource enumeration, device fingerprinting, and long-term traffic correlation. Existing software-based authentication methods rely on stored credentials and do not protect discovery privacy, while conventional Arbiter Physical Unclonable Functions (PUFs) remain vulnerable to machine-learning modeling attacks and are typically used only for device authentication. This paper presents a novel Recursive Hybrid Entropy PUF (RHE-PUF) and a privacy-preserving secure UPnP discovery architecture. The proposed RHE-PUF introduces recursive adaptive delay propagation, entropy injection, feed-forward coupling, and multi-path timing diversification to increase challenge-response nonlinearity and modeling resistance. Its responses are used to generate dynamic ephemeral identities, authenticate devices anonymously, and encrypt SSDP service advertisements without exposing permanent device identifiers. The complete framework was implemented on a Xilinx Spartan-7 FPGA and evaluated under realistic UPnP discovery and attack scenarios. The RHE-PUF achieved 49.31% uniqueness, 98.14% reliability, 50.22% uniformity, and 98.91% entropy. The implementation operated at up to 192 MHz with 0.84 W dynamic power, 0.88 µs authentication latency, and 13.4 ms secure discovery delay. The strongest deep-neural-network modeling attack achieved only 58.27% prediction accuracy. Replay and spoofing attack success rates were reduced to at or below 1.1% and 0.8%, respectively, while long-term tracking probability remained below 13%. These results demonstrate that the proposed joint hardware-security and privacy-preserving discovery framework provides resource-efficient authentication, anonymous UPnP resource discovery, and resistance to network and machine-learning attacks.