IIoT-RoboAuth: PUF-Based Command-Bound Authentication for Industrial Robotic Control Networks
Журнал: International Journal of Engineering and Manufacturing @ijem
Статья в выпуске: 5 vol.16, 2026 года.
Бесплатный доступ
Industrial robotic controllers require identity assurance and command-level integrity within bounded control intervals. This study redesigns a fog-assisted three-factor scheme as IIoT-RoboAuth, a PUF-rooted protocol in which the session key is derived from the three participant nonces, an ephemeral P-256 secret, the policy epoch, and the current RPUF epoch; each command is then authenticated over its canonical payload, sequence, timestamp, role scope, and safety-profile hash. The protocol uses four handshake messages (two end-to-end round trips), 483 application-layer bytes, and a 224-byte command envelope. Evaluation used a Python 3.12 message-driven simulator rather than robot hardware or NS-3. Thirty fixed seeds generated 1,000 sessions and 1,000 trials for each of four attack classes per seed. The modeled mean authentication latency was 7.903 ms (95% CI, 7.896-7.909 ms), compared with 22.735 ms (95% CI, 22.698-22.773 ms) for the centralized baseline under the stated delay assumptions. The complete validator rejected 30,000 of 30,000 command modifications, replays, stale commands, and out-of-range commands in each class; removing the command MAC, sequence chain, 5-ms freshness check, or kinematic check caused the corresponding attack class to pass. The result establishes reproducible protocol-level command binding and an explicit deployment boundary; hardware timing, PUF reliability, physical tamper resistance, and safety certification remain outside the evidence provided here.
Короткий адрес: https://sciup.org/15020718
IDS: 15020718 | DOI: 10.5815/ijem.2026.05.08