Hardware-assisted zero-knowledge authentication scheme for resource-constrained IoT terminals: USBKEY implementation and evaluation based on GSVOLE-2DLC
Abstract When resource-constrained Internet of Things (IoT) terminals connect to industrial control, sensing, and edge systems, it is necessary to balance low-overhead authentication, credential privacy protection, and cross-platform deployment. Traditional password and USBKEY authentication methods rely on static credentials and certificate mechanisms, which are vulnerable to eavesdropping, replay, and forgery attacks, while simultaneously suffering from privacy leakage and high platform adaptation costs. To address the above issues, this paper proposes a hardware-assisted zero-knowledge identity authentication scheme for resource-constrained terminals. The scheme employs a USBKEY as the local trusted hardware carrier and incorporates a quadratic-constrained zero-knowledge proof protocol within the Generalized Subspace Vector Oblivious Linear Evaluation framework (GSVOLE-2DLC) to construct a session-bound dynamic authentication process. In the registration phase, the scheme binds protocol parameters with user credentials and writes them into the USBKEY. In the authentication phase, the server (acting as the verifier $${{\\mathcal{V}}}$$ V ) generates a random challenge, and the USBKEY (acting as the prover $${{\\mathcal{P}}}$$ P ) generates temporary proof parameters based on local witness information. Subsequently, the verifier $${{\\mathcal{V}}}$$ V completes the verification through constraint consistency and GSVOLE consistency, thereby avoiding the transmission of original identity credentials over the network. To adapt to terminals with varying computational capabilities, this paper further designs configurable finite field parameters and cross-platform modular arithmetic interfaces, which are implemented in a PowerPC-architecture USBKEY prototype and a host-side verification environment. Experimental results demonstrate that under the parameter configuration of a 64-bit prime field, n C = 4, k C = 3, d C = 3, ℓ = 2, and t = 7, the total system authentication time is approximately 0.5476 s, and the verification time for the verifier $${{\\mathcal{V}}}$$ V is 0.0031 s. Protocol performance and functional tests indicate that the proposed scheme can correctly execute identity authentication under the assumed threat model, making it suitable for IoT edge scenarios requiring privacy protection and lightweight authentication.
Authors
- Chaoen Xiao (ORCID: https://orcid.org/0000-0001-6885-9063)
- Jianxin Wang (ORCID: https://orcid.org/0000-0001-5988-1883)
- Lei Zhang (ORCID: https://orcid.org/0000-0002-1609-4326)
- Zifan Xu (ORCID: https://orcid.org/0000-0003-3491-8429)
- Runze Zhou
Publication Details
- Journal
- Journal of King Saud University - Computer and Information Sciences
- Published
- 2026-09-22
- DOI
- https://doi.org/10.1007/s44443-026-01300-6
- Primary Topic
- Advanced Authentication Protocols Security
- Type
- article
- Field-Weighted Citation Impact
- 0.00