{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T10:35:35Z","timestamp":1780396535816,"version":"3.54.1"},"reference-count":47,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2026,3,10]],"date-time":"2026-03-10T00:00:00Z","timestamp":1773100800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2026,3,10]],"date-time":"2026-03-10T00:00:00Z","timestamp":1773100800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"Shenzhen Research Insitute","award":["JCYJ20170817115500476"],"award-info":[{"award-number":["JCYJ20170817115500476"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>\n                    This paper presents a scalable group authentication and key agreement protocol for dynamic IoT environments that integrates Physical Unclonable Function (PUF)-derived device bases with inner product space projections. During registration, each device is assigned a private basis\n                    <jats:inline-formula>\n                      <jats:alternatives>\n                        <jats:tex-math>$${\\mathcal {B}}_i$$<\/jats:tex-math>\n                        <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                          <mml:msub>\n                            <mml:mi>B<\/mml:mi>\n                            <mml:mi>i<\/mml:mi>\n                          <\/mml:msub>\n                        <\/mml:math>\n                      <\/jats:alternatives>\n                    <\/jats:inline-formula>\n                    derived from its PUF responses, enabling efficient group authentication without per-device centralized verification and thereby mitigating long-term reliance on the group manager (GM). The protocol provides single-broadcast operations for member joining and leaving as well as decentralized group key updates. Formal security analysis under the Real-or-Random (ROR) model and experimental evaluation demonstrate robustness against common attacks, low communication overhead (6.5-\n                    <jats:inline-formula>\n                      <jats:alternatives>\n                        <jats:tex-math>$$-$$<\/jats:tex-math>\n                        <mml:math xmlns:mml=\"http:\/\/www.w3.org\/1998\/Math\/MathML\">\n                          <mml:mo>-<\/mml:mo>\n                        <\/mml:math>\n                      <\/jats:alternatives>\n                    <\/jats:inline-formula>\n                    7.9\u00a0KB for 100 devices), and low authentication latency (1.135\u00a0ms for members and 0.051\u00a0ms for guests).\n                  <\/jats:p>","DOI":"10.1186\/s42400-025-00468-0","type":"journal-article","created":{"date-parts":[[2026,3,10]],"date-time":"2026-03-10T03:01:54Z","timestamp":1773111714000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["A Scalable Group Authentication Protocol for IoT Based on PUF-Derived Bases in Inner Product Spaces"],"prefix":"10.1186","volume":"9","author":[{"given":"Pan","family":"Feng","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bing","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Baofu","family":"Han","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yongli","family":"Ma","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuanyuan","family":"Hu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Runan","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,3,10]]},"reference":[{"key":"468_CR1","doi-asserted-by":"crossref","unstructured":"Al-Meer A, Al-Kuwari S (2022) Physical unclonable functions (puf) for iot devices. arXiv e-prints","DOI":"10.1145\/3591464"},{"key":"468_CR2","doi-asserted-by":"crossref","unstructured":"Al-Meer A, Al-Kuwari S (2023) Physical unclonable functions (puf) for iot devices. ACM Comput Surv 55(14s)","DOI":"10.1145\/3591464"},{"issue":"10","key":"468_CR3","doi-asserted-by":"publisher","first-page":"10277","DOI":"10.1109\/JIOT.2020.3004300","volume":"7","author":"Y Aydin","year":"2020","unstructured":"Aydin Y, Kurt GK, Ozdemir E et al (2020) A flexible and lightweight group authentication scheme. IEEE Internet Things J 7(10):10277\u201310287","journal-title":"IEEE Internet Things J"},{"issue":"11","key":"468_CR4","doi-asserted-by":"publisher","first-page":"12088","DOI":"10.1109\/TVT.2021.3116163","volume":"70","author":"G Bansal","year":"2021","unstructured":"Bansal G, Sikdar B (2021) S-maps: Scalable mutual authentication protocol for dynamic uav swarms. IEEE Trans Veh Technol 70(11):12088\u201312100","journal-title":"IEEE Trans Veh Technol"},{"issue":"4","key":"468_CR5","doi-asserted-by":"publisher","first-page":"557","DOI":"10.1145\/1008731.1008734","volume":"51","author":"R Canetti","year":"2004","unstructured":"Canetti R, Goldreich O, Halevi S (2004) The random oracle methodology, revisited. Journal of the ACM (JACM) 51(4):557\u2013594","journal-title":"Journal of the ACM (JACM)"},{"key":"468_CR6","unstructured":"Cervesato I (2010) The dolev-yao intruder is the most powerful attacker. IEEE Computer Society"},{"issue":"16","key":"468_CR7","doi-asserted-by":"publisher","first-page":"14408","DOI":"10.1109\/JIOT.2021.3065836","volume":"9","author":"S Chen","year":"2022","unstructured":"Chen S, Li B, Chen Z et al (2022) Novel strong-puf-based authentication protocols leveraging shamir\u2019s secret sharing. IEEE Internet Things J 9(16):14408\u201314425","journal-title":"IEEE Internet Things J"},{"key":"468_CR8","doi-asserted-by":"crossref","unstructured":"Chen Y, Ni T, Xu W, et\u00a0al (2022b) Swipepass: Acoustic-based second-factor user authentication for smartphones. Proc ACM Interact Mob Wearable Ubiquitous Technol 6:106:1\u2013106:25","DOI":"10.1145\/3550292"},{"key":"468_CR9","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1155\/2017\/3109624","volume":"2017","author":"HY Chien","year":"2017","unstructured":"Chien HY (2017) Group authentication with multiple trials and multiple authentications. Security and Communication Networks 2017:1\u20137","journal-title":"Security and Communication Networks"},{"key":"468_CR10","doi-asserted-by":"crossref","unstructured":"Dodis Y, Reyzin L, Smith A (2004) Fuzzy extractors: How to generate strong keys from biometrics and other noisy data. In: Advances in Cryptology\u2013EUROCRYPT 2004. Springer, pp 523\u2013540","DOI":"10.1007\/978-3-540-24676-3_31"},{"key":"468_CR11","doi-asserted-by":"crossref","unstructured":"Dorri A, Kanhere SS, Jurdak R (2017) Blockchain for iot security and privacy: The case study of a smart home. 2017 IEEE International Conference on Pervasive Computing and Communications Workshops (PerCom Workshops) pp 618\u2013623","DOI":"10.1109\/PERCOMW.2017.7917634"},{"key":"468_CR12","unstructured":"Federal Information Processing Standards Publication (2013) Digital Signature Standard (DSS). Tech. Rep. FIPS PUB 186-4, Nat. Inst. Stand. Technol, Gaithersburg, MD, USA"},{"issue":"6","key":"468_CR13","first-page":"4710","volume":"7","author":"MA Ferrag","year":"2020","unstructured":"Ferrag MA, Derdour M, Mukherjee M et al (2020) Blockchain technologies for the internet of things: Research issues and challenges. IEEE Internet Things J 7(6):4710\u20134732","journal-title":"IEEE Internet Things J"},{"issue":"2","key":"468_CR14","doi-asserted-by":"publisher","first-page":"81","DOI":"10.1038\/s41928-020-0372-5","volume":"3","author":"Y Gao","year":"2020","unstructured":"Gao Y, Al-Sarawi SF, Abbott D (2020) Physical unclonable functions. Nature Electronics 3(2):81\u201391","journal-title":"Nature Electronics"},{"key":"468_CR15","doi-asserted-by":"publisher","first-page":"338","DOI":"10.1016\/j.comcom.2019.12.042","volume":"152","author":"P Gope","year":"2020","unstructured":"Gope P (2020) Pmake: Privacy-aware multi-factor authenticated key establishment scheme for advance metering infrastructure in smart grid. Comput Commun 152:338\u2013344","journal-title":"Comput Commun"},{"issue":"21","key":"468_CR16","doi-asserted-by":"publisher","first-page":"35086","DOI":"10.1109\/JIOT.2024.3436652","volume":"11","author":"S Guzey","year":"2024","unstructured":"Guzey S, Kurt GK, Ozdemir E (2024) Group authentication and key establishment scheme. IEEE Internet Things J 11(21):35086\u201335099","journal-title":"IEEE Internet Things J"},{"issue":"9","key":"468_CR17","doi-asserted-by":"publisher","first-page":"1893","DOI":"10.1109\/TC.2012.251","volume":"62","author":"L Harn","year":"2013","unstructured":"Harn L (2013) Group authentication. IEEE Trans Comput 62(9):1893\u20131898","journal-title":"IEEE Trans Comput"},{"key":"468_CR18","doi-asserted-by":"crossref","unstructured":"Hasan MK, Weichen Z, Safie N, et\u00a0al (2024) A survey on key agreement and authentication protocol for internet of things application. IEEE Access p\u00a012","DOI":"10.1109\/ACCESS.2024.3393567"},{"issue":"1","key":"468_CR19","doi-asserted-by":"publisher","first-page":"867","DOI":"10.1109\/JIOT.2022.3204410","volume":"10","author":"D He","year":"2023","unstructured":"He D, Zhao Z, Chan S et al (2023) A novel authentication protocol for iot-enabled devices. IEEE Internet Things J 10(1):867\u2013876","journal-title":"IEEE Internet Things J"},{"issue":"1","key":"468_CR20","doi-asserted-by":"publisher","first-page":"347","DOI":"10.1109\/COMST.2023.3327327","volume":"26","author":"E Illi","year":"2024","unstructured":"Illi E, Qaraqe M, Althunibat S et al (2024) Physical layer security for authentication, confidentiality, and malicious node detection: A paradigm shift in securing iot networks. IEEE Communications Surveys & Tutorials 26(1):347\u2013388","journal-title":"IEEE Communications Surveys & Tutorials"},{"issue":"16","key":"468_CR21","doi-asserted-by":"publisher","first-page":"15336","DOI":"10.1109\/JIOT.2022.3149117","volume":"9","author":"TF Lee","year":"2022","unstructured":"Lee TF, Ye X, Lin SH (2022) Anonymous dynamic group authenticated key agreements using physical unclonable functions for internet of medical things. IEEE Internet Things J 9(16):15336\u201315348","journal-title":"IEEE Internet Things J"},{"issue":"3","key":"468_CR22","doi-asserted-by":"publisher","first-page":"408","DOI":"10.1109\/JIOT.2015.2495321","volume":"3","author":"J Li","year":"2016","unstructured":"Li J, Wen M, Zhang T (2016) Group-based authentication and key agreement with dynamic policy updating for mtc in lte-a networks. IEEE Internet Things J 3(3):408\u2013417","journal-title":"IEEE Internet Things J"},{"key":"468_CR23","doi-asserted-by":"crossref","unstructured":"Liu C, Tan R, Wu Y, et\u00a0al (2024) Dissecting zero trust: research landscape and its implementation in iot. Cybersecurity (2523-3246) 7(1)","DOI":"10.1186\/s42400-024-00212-0"},{"key":"468_CR24","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2020.107192","volume":"178","author":"APG Lopes","year":"2020","unstructured":"Lopes APG, Gondim PR (2020) Group authentication protocol based on aggregated signatures for d2d communication. Comput Netw 178:107192","journal-title":"Comput Netw"},{"issue":"5","key":"468_CR25","doi-asserted-by":"publisher","first-page":"8065","DOI":"10.1109\/JIOT.2019.2902840","volume":"6","author":"M Ma","year":"2019","unstructured":"Ma M, He D, Wang H et al (2019) An efficient and provably secure authenticated key agreement protocol for fog-based vehicular ad-hoc networks. IEEE Internet Things J 6(5):8065\u20138075","journal-title":"IEEE Internet Things J"},{"key":"468_CR26","volume-title":"Physically Unclonable Functions: Constructions","author":"R Maes","year":"2012","unstructured":"Maes R (2012) Physically Unclonable Functions: Constructions. Springer, Properties and Applications"},{"key":"468_CR27","doi-asserted-by":"publisher","first-page":"1001","DOI":"10.1109\/TIFS.2023.3330577","volume":"19","author":"W Mao","year":"2024","unstructured":"Mao W, Jiang P, Zhu L (2024) Locally verifiable batch authentication in iomt. IEEE Trans Inf Forensics Secur 19:1001\u20131014","journal-title":"IEEE Trans Inf Forensics Secur"},{"issue":"8","key":"468_CR28","doi-asserted-by":"publisher","first-page":"10286","DOI":"10.1109\/TITS.2024.3360251","volume":"25","author":"J Miao","year":"2024","unstructured":"Miao J, Wang Z, Ning X et al (2024) A uav-assisted authentication protocol for internet of vehicles. IEEE Trans Intell Transp Syst 25(8):10286\u201310297","journal-title":"IEEE Trans Intell Transp Syst"},{"key":"468_CR29","doi-asserted-by":"publisher","first-page":"2451","DOI":"10.1109\/TIFS.2023.3266624","volume":"18","author":"O Millwood","year":"2023","unstructured":"Millwood O, Miskelly J, Yang B et al (2023) Puf-phenotype: A robust and noise-resilient approach to aid group-based authentication with dram-pufs using machine learning. IEEE Trans Inf Forensics Secur 18:2451\u20132465","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"468_CR30","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.104310","volume":"151","author":"R Mishra","year":"2025","unstructured":"Mishra R, Mishra A (2025) Current research on internet of things (iot) security protocols: A survey. Computers & Security 151:104310","journal-title":"Computers & Security"},{"key":"468_CR31","doi-asserted-by":"crossref","unstructured":"Modarres AMA, Sarbishaei G (2024) A lightweight authentication protocol for iot-based applications using reconfigurable noisy pufs. IEEE Transactions on Industrial Informatics","DOI":"10.1109\/TII.2024.3403265"},{"issue":"1","key":"468_CR32","doi-asserted-by":"publisher","first-page":"840","DOI":"10.1109\/JIOT.2022.3204335","volume":"10","author":"M Nakkar","year":"2023","unstructured":"Nakkar M, Altawy R, Youssef A (2023) Gase: A lightweight group authentication scheme with key agreement for edge computing applications. IEEE Internet Things J 10(1):840\u2013854","journal-title":"IEEE Internet Things J"},{"issue":"4","key":"468_CR33","doi-asserted-by":"publisher","first-page":"3412","DOI":"10.1109\/TNSE.2024.3373386","volume":"11","author":"M Nakkar","year":"2024","unstructured":"Nakkar M, AlTawy R, Youssef A (2024) Lightweight group authentication scheme leveraging shamir\u2019s secret sharing and pufs. IEEE Transactions on Network Science and Engineering 11(4):3412\u20133429","journal-title":"IEEE Transactions on Network Science and Engineering"},{"key":"468_CR34","unstructured":"National Institute of Standards and Technology (2016) Recommendation for Key Management Part 1: General (Revision 4). Tech. Rep. Special Publication 800-57, NIST SP 800-57pt1r4, Gaithersburg, MD, USA"},{"key":"468_CR35","unstructured":"Ni T, Lan G, Wang J, et\u00a0al (2023) Eavesdropping mobile app activity via $$\\{$$Radio-Frequency$$\\}$$ energy harvesting. In: 32nd USENIX Security Symposium (USENIX Security 23), pp 3511\u20133528"},{"issue":"4","key":"468_CR36","doi-asserted-by":"publisher","first-page":"5849","DOI":"10.1109\/TVT.2023.3335839","volume":"73","author":"C Pu","year":"2024","unstructured":"Pu C, Warner C, Choo KKR et al (2024) litegap: Lightweight group authentication protocol for internet of drones systems. IEEE Trans Veh Technol 73(4):5849\u20135860","journal-title":"IEEE Trans Veh Technol"},{"issue":"5","key":"468_CR37","doi-asserted-by":"publisher","first-page":"3642","DOI":"10.1109\/JIOT.2021.3098224","volume":"9","author":"X Ren","year":"2022","unstructured":"Ren X, Cao J, Ma M et al (2022) A novel puf-based group authentication and data transmission scheme for nb-iot in 3g pp 5g networks. IEEE Internet Things J 9(5):3642\u20133656","journal-title":"IEEE Internet Things J"},{"key":"468_CR38","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/ACCESS.2019.2946713","volume":"7","author":"P Shabisha","year":"2019","unstructured":"Shabisha P, Braeken A, Kumar P et al (2019) Fog-orchestrated and server-controlled anonymous group authentication and key agreement. IEEE Access 7:1\u20131","journal-title":"IEEE Access"},{"issue":"11","key":"468_CR39","doi-asserted-by":"publisher","first-page":"612","DOI":"10.1145\/359168.359176","volume":"22","author":"A Shamir","year":"1979","unstructured":"Shamir A (1979) How to share a secret. Commun ACM 22(11):612\u2013613","journal-title":"Commun ACM"},{"issue":"7","key":"468_CR40","doi-asserted-by":"publisher","first-page":"6903","DOI":"10.1109\/TVT.2019.2911672","volume":"68","author":"J Srinivas","year":"2019","unstructured":"Srinivas J, Das AK, Kumar N et al (2019) Tcalas: Temporal credential-based anonymous lightweight authentication scheme for internet of drones environment. IEEE Trans Veh Technol 68(7):6903\u20136916","journal-title":"IEEE Trans Veh Technol"},{"key":"468_CR41","doi-asserted-by":"crossref","unstructured":"Sun Z, Yang H, Liu K, et\u00a0al (2022) Recent advances in lora: A comprehensive survey. ACM transactions on sensor networks","DOI":"10.1145\/3543856"},{"key":"468_CR42","unstructured":"Yang A, Weng J, Yang K, et\u00a0al (2020) Delegating authentication to edge: A decentralized authentication architecture for vehicular networks. IEEE Transactions on Intelligent Transportation Systems PP(99):1\u201315"},{"issue":"7","key":"468_CR43","doi-asserted-by":"publisher","first-page":"5682","DOI":"10.1109\/JIOT.2020.3032757","volume":"8","author":"H Y\u0131ld\u0131z","year":"2021","unstructured":"Y\u0131ld\u0131z H, Cenk M, Onur E (2021) Plgakd: A puf-based lightweight group authentication and key distribution protocol. IEEE Internet Things J 8(7):5682\u20135696","journal-title":"IEEE Internet Things J"},{"issue":"3","key":"468_CR44","first-page":"12","volume":"27","author":"W Yu","year":"2020","unstructured":"Yu W, Liang F, He X et al (2020) Blockchain-based solutions to security and privacy issues in the internet of things. IEEE Wirel Commun 27(3):12\u201318","journal-title":"IEEE Wirel Commun"},{"key":"468_CR45","doi-asserted-by":"crossref","unstructured":"Zhang Y, Li B, Liu B, et\u00a0al (2024) Building puf as a service: Distributed authentication and recoverable data sharing with multidimensional crps security protection. IEEE Internet of Things Journal 11","DOI":"10.1109\/JIOT.2024.3358011"},{"key":"468_CR46","doi-asserted-by":"crossref","unstructured":"Zhang Y, Gu C, Shi P, et\u00a0al (2025) Bring your device group (bydg): Efficient and privacy-preserving user-device authentication protocol in multi-access edge computing. IEEE Transactions on Information Forensics and Security","DOI":"10.1109\/TIFS.2025.3550051"},{"issue":"1","key":"468_CR47","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1186\/s42400-024-00247-3","volume":"7","author":"Z Zhao","year":"2024","unstructured":"Zhao Z, Hsu C, Harn L et al (2024) Lightweight ring-neighbor-based user authentication and group-key agreement for internet of drones. Cybersecurity 7(1):1\u201314","journal-title":"Cybersecurity"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00468-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-025-00468-0","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00468-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,10]],"date-time":"2026-03-10T03:02:06Z","timestamp":1773111726000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1186\/s42400-025-00468-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3,10]]},"references-count":47,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,12]]}},"alternative-id":["468"],"URL":"https:\/\/doi.org\/10.1186\/s42400-025-00468-0","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,3,10]]},"assertion":[{"value":"16 June 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"11 August 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 March 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that there is no confict of interest regarding the publication of this paper.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"41"}}