IJEM Vol. 16, No. 5, 8 Oct. 2026
Cover page and Table of Contents: PDF (size: 621KB)
PDF (621KB), PP.144-157
Views: 0 Downloads: 0
Industrial Internet of Things, robotic arm security, three-factor authentication, physically unclonable function, command integrity, functional safety, reproducible simulation
Industrial robotic controllers require identity assurance and command-level integrity within bounded control intervals. This study redesigns a fog-assisted three-factor scheme as IIoT-RoboAuth, a PUF-rooted protocol in which the session key is derived from the three participant nonces, an ephemeral P-256 secret, the policy epoch, and the current RPUF epoch; each command is then authenticated over its canonical payload, sequence, timestamp, role scope, and safety-profile hash. The protocol uses four handshake messages (two end-to-end round trips), 483 application-layer bytes, and a 224-byte command envelope. Evaluation used a Python 3.12 message-driven simulator rather than robot hardware or NS-3. Thirty fixed seeds generated 1,000 sessions and 1,000 trials for each of four attack classes per seed. The modeled mean authentication latency was 7.903 ms (95% CI, 7.896-7.909 ms), compared with 22.735 ms (95% CI, 22.698-22.773 ms) for the centralized baseline under the stated delay assumptions. The complete validator rejected 30,000 of 30,000 command modifications, replays, stale commands, and out-of-range commands in each class; removing the command MAC, sequence chain, 5-ms freshness check, or kinematic check caused the corresponding attack class to pass. The result establishes reproducible protocol-level command binding and an explicit deployment boundary; hardware timing, PUF reliability, physical tamper resistance, and safety certification remain outside the evidence provided here.
Haewon Byeon, "IIoT-RoboAuth: PUF-Based Command-Bound Authentication for Industrial Robotic Control Networks", International Journal of Engineering and Manufacturing(IJEM), Vol.16, No.5, pp. 144-157, 2026. DOI:10.5815/ijem.2026.05.08
[1]H. Zhuang, W. Tan, S. Lv, Y. Bi, Y. Chen, and C. Li, 'Three factors identity authentication and key agreement protocol for UAVs-assisted terrain exploration,' Journal of King Saud University - Computer and Information Sciences, vol. 37, art. 342, 2025. https://doi.org/10.1007/s44443-025-00328-4
[2]T. Wan, B. Shi, and H. Wang, 'A continuous authentication scheme for zero-trust architecture in industrial internet of things,' Alexandria Engineering Journal, vol. 122, pp. 555-563, 2025. https://doi.org/10.1016/j.aej.2025.03.012
[3]X. Yu, K. Zhang, Z. Suo, J. Wang, W. Wang, and B. Zou, 'An efficient authentication scheme syncretizing physical unclonable function and revocable biometrics in Industrial Internet of Things,' Journal of King Saud University - Computer and Information Sciences, vol. 36, art. 102166, 2024. https://doi.org/10.1016/j.jksuci.2024.102166
[4]H. Yang, X. Meng, J. Liang, Y. Zhang, and K. Li, 'HCDA: A hidden cross-domain authentication protocol for embodied intelligence in smart manufacturing,' Journal of Industrial Information Integration, vol. 48, art. 100946, 2025. https://doi.org/10.1016/j.jii.2025.100946
[5]K. Yang, Y. Zhang, T. Li, and L. Sun, 'ASIDS: Acoustic side-channel based intrusion detection system for industrial robotic arms,' Computers & Security, vol. 157, art. 104586, 2025. https://doi.org/10.1016/j.cose.2025.104586
[6]Y. Dodis, R. Ostrovsky, L. Reyzin, and A. Smith, 'Fuzzy extractors: How to generate strong keys from biometrics and other noisy data,' SIAM Journal on Computing, vol. 38, no. 1, pp. 97-139, 2008. https://doi.org/10.1137/060651380
[7]B. Gassend, D. Lim, D. Clarke, M. van Dijk, and S. Devadas, 'Identification and authentication of physical devices,' in Cryptographic Hardware and Embedded Systems, pp. 10-19, 2002. https://doi.org/10.1007/3-540-36400-5_2
[8]A. Sajadi, A. Shabani, and B. Alizadeh, 'DC-PUF: Machine learning-resistant PUF-based authentication protocol using dependency chain for resource-constraint IoT devices,' Journal of Network and Computer Applications, vol. 217, art. 103693, 2023. https://doi.org/10.1016/j.jnca.2023.103693
[9]IEC, IEC 62443-3-3:2013, Industrial Communication Networks - Network and System Security - Part 3-3: System Security Requirements and Security Levels, 2013.
[10]IEC, IEC 62443-4-2:2019, Security for Industrial Automation and Control Systems - Part 4-2: Technical Security Requirements for IACS Components, 2019.
[11]ISO, ISO 10218-1:2025, Robotics - Safety Requirements - Part 1: Industrial Robots, 2025.
[12]ISO, ISO 10218-2:2025, Robotics - Safety Requirements - Part 2: Industrial Robot Applications and Robot Cells, 2025.
[13]ISO, ISO 13849-1:2023, Safety of Machinery - Safety-Related Parts of Control Systems - Part 1: General Principles for Design, 2023.
[14]IEEE, IEEE Std 802.1Qbv-2015, Bridges and Bridged Networks - Amendment: Enhancements for Scheduled Traffic, 2015. https://doi.org/10.1109/IEEESTD.2016.8613095
[15]OPC Foundation, OPC Unified Architecture Part 14: PubSub, Version 1.05.06, 2025. https://reference.opcfoundation.org/specs/OPC-10000-14/
[16]IEEE, IEEE Std 802.1AS-2020, IEEE Standard for Local and Metropolitan Area Networks - Timing and Synchronization for Time-Sensitive Applications, 2020. https://standards.ieee.org/ieee/802.1AS/7121/
[17]EtherCAT Technology Group, Safety over EtherCAT Protocol Specification, Version 1.0.4, 2024. https://www.ethercat.org/
[18]PROFIBUS & PROFINET International, Security Guideline - PROFINET Security, 2024. https://www.profibus.com/
[19]D. Dolev and A. C. Yao, 'On the security of public key protocols,' IEEE Transactions on Information Theory, vol. 29, no. 2, pp. 198-208, 1983. https://doi.org/10.1109/TIT.1983.1056650
[20]R. Canetti and H. Krawczyk, 'Analysis of key-exchange protocols and their use for building secure channels,' in Advances in Cryptology - EUROCRYPT 2001, pp. 453-474, 2001. https://doi.org/10.1007/3-540-44987-6_28
[21]B. Blanchet, 'An efficient cryptographic protocol verifier based on Prolog rules,' in Proceedings of CSFW, pp. 82-96, 2001. https://doi.org/10.1109/CSFW.2001.930138
[22]NIST, FIPS 180-4, Secure Hash Standard, 2015. https://doi.org/10.6028/NIST.FIPS.180-4
[23]E. Barker, L. Chen, and R. Davis, NIST SP 800-56C Rev. 2, Recommendation for Key-Derivation Methods in Key-Establishment Schemes, 2020. https://doi.org/10.6028/NIST.SP.800-56Cr2
[24]H. Krawczyk, M. Bellare, and R. Canetti, HMAC: Keyed-Hashing for Message Authentication, RFC 2104, 1997. https://doi.org/10.17487/RFC2104
[25]R. C. Merkle, 'A digital signature based on a conventional encryption function,' in Advances in Cryptology - CRYPTO '87, pp. 369-378, 1988. https://doi.org/10.1007/3-540-48184-2_32
[26]S. Schulz, M. H. Cruz, and M. U. Iqbal, 'Remote attestation for industrial control systems: A systematic review,' Computers & Security, vol. 128, art. 103166, 2023. https://doi.org/10.1016/j.cose.2023.103166
[27]M. Fagan, K. Megas, K. Cuthill, J. Marron, and B. Hoehn, NIST IR 8259 Rev. 1, Foundational Cybersecurity Activities for IoT Product Manufacturers, 2026. https://doi.org/10.6028/NIST.IR.8259r1
[28]NIST, FIPS 203, Module-Lattice-Based Key-Encapsulation Mechanism Standard, 2024. https://doi.org/10.6028/NIST.FIPS.203
[29]NIST, FIPS 204, Module-Lattice-Based Digital Signature Standard, 2024. https://doi.org/10.6028/NIST.FIPS.204
[30]NIST, FIPS 205, Stateless Hash-Based Digital Signature Standard, 2024. https://doi.org/10.6028/NIST.FIPS.205