A Blockchain-PUF-based Secure Mutual Authentication Scheme for IoT
Eric C Li, Hui‐Tang Lin, Hao-Ren Yang · 2024
The Internet of Things (IoT) offers significant convenience but also exposes users to heightened risks from malicious attacks aiming to compromise device authentication and forge identities. Existing identity authentication systems typically rely on centralized architectures, leading to single points of failure and trust issues. This study introduces a mutual identity authentication scheme leveraging blockchain technology and the unique properties of physical unclonable functions (PUFs) embedded in IoT devices. PUFs are inherently unpredictable and unique, even among chips manufactured in the same batch, rendering it virtually impossible for attackers to replicate device authentication information and forge identities. By integrating blockchain technology with zero-knowledge proof protocols, the proposed scheme ensures secure authentication within open and transparent networks. Once the authentication process is completed, results are recorded on the blockchain to prevent tampering, and aggregate signature technology safeguards against man-in-the-middle attacks during data transmission from gateways to devices. Security analysis demonstrates that the proposed blockchain-PUF method is robust against common IoT security threats and is suitable for IoT devices with limited computational and storage capacities, offering a secure and efficient solution for modern IoT networks.