SPUF-KG and SSL-TRNG Enhanced lightweight IoT authentication and key exchange protocol
摘要
With the rapid advancement of Internet of Things (IoT) applications, the frequency of data interactions has increased significantly, exposing security vulnerabilities in key storage due to the constrained security capabilities of IoT devices. To address these challenges, this paper proposes a lightweight IoT authentication and key exchange protocol based on SRAM PUF Key Generator (SPUF-KG) and Semiconductor Superlattice True Random Number Generator (SSL-TRNG), designed for IoT Device-to-Server (D2S) and Device-to-Device (D2D) scenarios. SPUF-KG eliminates repeated helper data transmission during protocol interaction, while SSL-TRNG provides a highly secure initial challenge for the protocol. Security analysis demonstrates that the number produced by SPUF-KG exhibits excellent uniformity, uniqueness, and reliability, while SSL-TRNG is capable of generating random numbers that pass the NIST SP 800–22 Statistical Testing. The protocol is verified by using scyther automatic verification tool and informal security analysis to confirm that the protocol has resistance to Man-in-the-Middle (MiTM), Replay, Physical, Quantum Computing, and Modeling attacks. In terms of performance, our approach has significantly low computational complexity while reducing D2S communication costs by 18.99%, D2D by 5.09%, and server storage overhead by 17.4% compared to existing PUF-based protocols.