Secure UPnP Resource Discovery Using a PUF-Assisted Hardware Accelerator for IoT
Abstract
1. Introduction
- A novel RHE-PUF architecture is developed using triple-path propagation, adaptive cross-coupling, recursive feed-forward timing, and entropy injection to improve challenge–response nonlinearity and resistance to machine-learning modeling attacks.
- The RHE-PUF is integrated with a privacy-preserving UPnP/SSDP discovery architecture.
- A dynamic ephemeral identity mechanism is introduced to support authenticated discovery without transmitting permanent device identifiers.
- Encrypted SSDP advertisements and protected service enumeration are used to reduce metadata leakage, unauthorized discovery, spoofing, replay, and traffic-correlation attacks.
2. Related Works
2.1. Software-Based Authentication
2.2. PUF-Based Authentication
2.3. Privacy-Preserving Service Discovery
2.4. Research Gap
3. The Proposed Method
3.1. Enrollment and Authentication Procedure
| Algorithm 1 Enrollment and Authentication Procedure. |
| 1: Generate random challenge 2: Evaluate RHE-PUF 3: Compute response 4: Repeat evaluation m times 5: Generate helper data 6: Store 7: for each authentication request do 8: Send unused challenge 9: Generate response 10: Reconstruct 11: if then 12: Generate temporary identity 13: Allow secure UPnP discovery 14: else 15: Reject authentication 16: end if 17: end for |
3.1.1. Entropy Source Generation
3.1.2. Enrollment Phase
3.1.3. Authentication (Validation) Phase
3.1.4. Challenge Management
3.1.5. Protection of CRPs and PUF Security
4. Experimental Setup and Results
4.1. Experimental Setup
4.2. Hardware Resource Utilization
4.3. Statistical Evaluation of the Proposed RHE-PUF
4.4. Secure UPnP Discovery Performance Analysis
4.5. Machine Learning Modeling Attack Evaluation
4.6. Replay and Spoofing Attack Evaluation
4.7. Privacy Preservation Analysis
4.8. Comparison with Existing Methods
5. Conclusions
Funding
Data Availability Statement
Conflicts of Interest
References
- Ghaffari, A.; Jelodari, N.; Pouralish, S.; Derakhshanfard, N.; Arasteh, B. Securing Internet of Things Using Machine and Deep Learning Methods: A Survey. Clust. Comput. 2024, 27, 9065–9089. [Google Scholar] [CrossRef] [Scilit]
- Aarella, S.G.; Yanambaka, V.P.; Mohanty, S.P.; Kougianos, E. Fortified-Edge 2.0: Advanced Machine-Learning-Driven Framework for Secure PUF-Based Authentication in Collaborative Edge Computing. Future Internet 2025, 17, 272. [Google Scholar] [CrossRef] [Scilit]
- Jeddou, S.; Diez, L.; Baina, A.; Abdellah, N.; Agüero, R. A Review of the Internet of Things (IoT) Landscape: Technologies, Applications, and Open Challenges. J. Electr. Comput. Eng. 2026, 2026, 6657578. [Google Scholar] [CrossRef] [Scilit]
- Vadivel, S.R.S.; Karthikeyan, V.; Gopalakrishnan, K.; Dani Reagan Vivek, J. Introduction to the internet of things (iot). In Internet of Things Security; Elsevier: Amsterdam, The Netherlands, 2026; pp. 3–31. [Google Scholar]
- Seliem, M.; Elgazzar, K.; Khalil, K. Towards privacy preserving iot environments: A survey. Wirel. Commun. Mob. Comput. 2018, 2018, 1032761. [Google Scholar] [CrossRef] [Scilit]
- Khalil, K.; Elgazzar, K.; Seliem, M.; Bayoumi, M. Resource discovery techniques in the internet of things: A review. Internet Things 2020, 12, 100293. [Google Scholar] [CrossRef] [Scilit]
- Khalil, K.; Kumar, A.; Bayoumi, M. Hardware acceleration of CoAP protocol for high-speed and low-power Internet of Things communication. IEEE Internet Things J. 2024, 12, 8206–8218. [Google Scholar] [CrossRef] [Scilit]
- Khalil, K.; Mohaidat, T.; Darwich, M.; Kumar, A.; Bayoumi, M. An efficient hardware design of coap protocol for the internet of things. In Proceedings of the 2024 IEEE 17th Dallas Circuits and Systems Conference (DCAS), Richardson, TX, USA, 19–21 April 2024; IEEE: New York, NY, USA, 2024; pp. 1–5. [Google Scholar]
- Khalil, K.; Abdelgawad, A.; Bayoumi, M. Intelligent resource discovery approach for the internet of things. In Proceedings of the 2021 IEEE 7th World Forum on Internet of Things (WF-IoT), New Orleans, LA, USA, 14 June–31 July 2021; IEEE: New York, NY, USA, 2021; pp. 264–269. [Google Scholar]
- van Dongen, B.; van de Kaa, G.; Ludema, M. Stakeholder salience and standardisation: The case of the industrial internet of things. J. Bus. Res. 2026, 205, 115895. [Google Scholar] [CrossRef] [Scilit]
- Vijayakumar, S.; Thilagavathy, A.; Sankar, R.; Ramesh, T.; BanuPriya, N.; Srijayanthi, S. Internet of Things in Smart and Secure Applications Development-Based Sustainability. In Predictive Methods in Next-Generation Computing: An Approach Toward Sustainability; John Wiley Sons: Hoboken, NJ, USA, 2026; pp. 83–106. [Google Scholar]
- Khalil, K.; Elgazzar, K.; Abdelgawad, A.; Bayoumi, M. A security approach for coap-based internet of things resource discovery. In Proceedings of the 2020 IEEE 6th World Forum on Internet of Things (WF-IoT), New Orleans, LA, USA, 2–16 June 2020; IEEE: New York, NY, USA, 2020; pp. 1–6. [Google Scholar]
- Gołofit, K. Security Primitives for Memoryless IoT Devices Based on Physical Unclonable Functions and True Random Number Generators. Sci. Rep. 2024, 14, 24060. [Google Scholar] [CrossRef] [Scilit]
- Zhang, Q.; Liu, Y.; Wu, N.; Chen, C. SPUF-KG and SSL-TRNG Enhanced Lightweight IoT Authentication and Key Exchange Protocol. J. King Saud Univ. Comput. Inf. Sci. 2025, 37, 279. [Google Scholar] [CrossRef] [Scilit]
- Ghaleb, B.; Ahmad, J.; Al-Dubai, A.; Khan, M.K.; Latif, S.; Khan, M.S. Lightweight Authentication Protocols for Secure IoT Communication Networks: A Comprehensive Survey, Taxonomy, and Open Challenges. IEEE Commun. Surv. Tutor. 2026, 28, 6282–6317. [Google Scholar] [CrossRef] [Scilit]
- Samal, L.; Kori, R.; Mahapatra, K. A Secure FPGA-Based IoT Gateway for Smart Home Automation Using PUF-Based Authentication. Eng. Proc. 2025, 118, 61. [Google Scholar] [CrossRef] [Scilit]
- Khalil, K.; Idriss, H.; Idriss, T.; Bayoumi, M. Lightweight Hardware Security and Physically Unclonable Functions: Improving Security of Constrained IoT Devices; Springer: Cham, Switzerland, 2025. [Google Scholar] [CrossRef] [Scilit]
- Alahmadi, S.; Khalil, K.; Bayoumi, M.; Idriss, H. Fortifying Strong PUFs: A Modeling Attack-Resilient Approach Using Weak PUF for IoT Device Security. In Proceedings of the 2024 IEEE International Symposium on Circuits and Systems (ISCAS), Singapore, 19–22 May 2024; IEEE: New York, NY, USA, 2024. [Google Scholar]
- Khalil, K.; Idriss, H.; Idriss, T.; Bayoumi, M. Advanced PUF Designs. In Lightweight Hardware Security and Physically Unclonable Functions; Springer: Cham, Switzerland, 2025; pp. 97–113. [Google Scholar]
- Khalil, K.; Idriss, H.; Idriss, T.; Bayoumi, M. Security in Resource-Constrained IoT Devices. In Lightweight Hardware Security and Physically Unclonable Functions; Springer: Cham, Switzerland, 2025; pp. 41–48. [Google Scholar]
- Julià Farré, P.; Galetsky, V.; Belhassen, M.; Pieplow, G.; Nilesh, K.; Boche, H.; Schröder, T.; Nötzel, J.; Deppe, C. Secure authentication via quantum physical unclonable functions: A review. Adv. Quantum Technol. 2026, 9, e00648. [Google Scholar] [CrossRef] [Scilit]
- Oduro-Antwi, M.; Nguyen, D.; Sood, K. Physically unclonable functions (PUF)-based IoT security: Challenges and opportunities. In Internet of Things Security; Elsevier: Amsterdam, The Netherlands, 2026; pp. 201–217. [Google Scholar]
- Ebrahimabadi, M.; Younis, M.; Mehjabin, S.S.; Tekeoglu, A.; Sookoor, T.I.; Karimi, N. Robust and Lightweight Challenge Obfuscation Mechanism for Anti-Modeling Protection of Arbiter-PUFs. J. Hardw. Syst. Secur. 2024, 8, 205–216. [Google Scholar] [CrossRef] [Scilit]
- Ibrahim, H.M.; Skovorodnikov, H.; Alkhzaimi, H. Resilience Evaluation of Memristor Based PUF Against Machine Learning Attacks. Sci. Rep. 2024, 14, 23962. [Google Scholar] [CrossRef] [Scilit]
- Li, G.; Shao, X.; Wang, P.; Ma, X.; Li, H.; Ye, H. Anti-machine-learning-attack strong PUF design based on multi-path delay selection strategy. Microelectron. J. 2024, 153, 106434. [Google Scholar] [CrossRef] [Scilit]
- Maghanaki, M.; Shahin, M.; Keramati, S.; Chen, F.F.; Contreras, E. Feature-Engineered Trojan Malware Detection on Windows-Based IoT Gateways Using a Custom Deep Neural Network and Automated Monitoring Pipeline. J. Cybersecur. Priv. 2026, 6, 90. [Google Scholar] [CrossRef] [Scilit]
- Deng, H.; Pei, H.; Zhang, Q.; Du, M. Attribution explanations for deep neural networks: A theoretical perspective. IEEE Trans. Pattern Anal. Mach. Intell. 2026, 48, 7387–7406. [Google Scholar] [CrossRef] [Scilit]
- Sadhu, P.K.; Yanambaka, V.P.; Abdelgawad, A. Internet of things: Security and solutions survey. Sensors 2022, 22, 7433. [Google Scholar] [CrossRef] [Scilit]
- Pereira, P.P.; Eliasson, J.; Delsing, J. An authentication and access control framework for CoAP-based Internet of Things. In Proceedings of the IECON 2014-40th Annual Conference of the IEEE Industrial Electronics Society, Dallas, TX, USA, 9 October–1 November 2014; IEEE: New York, NY, USA, 2014; pp. 5293–5299. [Google Scholar]
- Aman, M.N.; Chua, K.C.; Sikdar, B. Mutual Authentication in IoT Systems Using Physical Unclonable Functions. IEEE Internet Things J. 2017, 4, 1327–1340. [Google Scholar] [CrossRef] [Scilit]
- He, Z.; Chen, W.; Zhang, L.; Chi, G.; Gao, Q.; Harn, L. A Highly Reliable Arbiter PUF With Improved Uniqueness in FPGA Implementation Using Bit-Self-Test. IEEE Access 2020, 8, 181751–181762. [Google Scholar] [CrossRef] [Scilit]
- Ge, W.; Hu, S.; Huang, J.; Liu, B.; Zhu, M. FPGA implementation of a challenge pre-processing structure arbiter PUF designed for machine learning attack resistance. IEICE Electron. Express 2020, 17, 20190670. [Google Scholar] [CrossRef] [Scilit]
- Anandakumar, N.N.; Hashmi, M.S.; Sanadhya, S.K. Efficient and lightweight FPGA-based hybrid PUFs with improved performance. Microprocess. Microsyst. 2020, 77, 103180. [Google Scholar] [CrossRef] [Scilit]
- Agarwal, S.K.; Joshi, A.M. Device authentication with FPGA based self correcting Physical Unclonable Function for Internet of Things. Microprocess. Microsyst. 2022, 95, 104717. [Google Scholar] [CrossRef] [Scilit]
- Babaei, A.; Schiele, G.; Zohner, M. Reconfigurable Security Architecture (RESA) Based on PUF for FPGA-Based IoT Devices. Sensors 2022, 22, 5577. [Google Scholar] [CrossRef] [Scilit]
- Yoon, S.; Han, S.; Hwang, E. Joint Heterogeneous PUF-Based Security-Enhanced IoT Authentication. IEEE Internet Things J. 2023, 10, 18082–18096. [Google Scholar] [CrossRef] [Scilit]








| Hardware Metric | Baseline Arbiter PUF | Standard UPnP | Proposed Framework |
|---|---|---|---|
| LUTs | 894 | 612 | 2217 |
| FFs | 641 | 487 | 1784 |
| BRAMs | 1 | 2 | 7 |
| DSP Slices | 0 | 2 | 15 |
| Maximum Frequency (MHz) | 238 | 205 | 192 |
| Dynamic Power (W) | 0.29 | 0.37 | 0.84 |
| Static Power (W) | 0.18 | 0.18 | 0.20 |
| Authentication Latency (s) | 0.41 | – | 0.88 |
| Discovery Delay (ms) | – | 8.9 | 13.4 |
| Method | HW Rooted | PUF-Based | Anonymous Discovery | Replay Protection | ML Attack Evaluation | Privacy Protection | FPGA Validated | Lightweight |
|---|---|---|---|---|---|---|---|---|
| He et al. [31] | ✓ | ✓ | × | × | Partial | × | ✓ | ✓ |
| Ge et al. [32] | ✓ | ✓ | × | × | ✓ | × | ✓ | ✓ |
| Anandakumar et al. [33] | ✓ | ✓ | × | × | Partial | × | ✓ | ✓ |
| Agarwal and Joshi [34] | ✓ | ✓ | × | × | × | × | ✓ | ✓ |
| Babaei et al. [35] | ✓ | ✓ | × | ✓ | ✓ | × | ✓ | ✓ |
| Yoon et al. [36] | ✓ | ✓ | × | ✓ | ✓ | Partial | × | ✓ |
| Proposed RHE-PUF Framework | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Method | Implementation Platform | Reliability (%) | ML Prediction Accuracy (%) | Authentication/Privacy | Reported Measurement Conditions |
|---|---|---|---|---|---|
| He et al. [31] | Xilinx FPGA | – | – | PUF-based authentication | FPGA implementation; reliability and uniqueness evaluated experimentally |
| Ge et al. [32] | FPGA, 64-stage APUF | – | <61.33 | ML-resistant PUF | Experimental CRP acquisition and ML modeling attack |
| Anandakumar et al. [33] | Xilinx Spartan-6 FPGA | – | – | Hardware authentication | Hybrid RS-latch/Arbiter PUF with programmable delay lines and temporal majority voting |
| Agarwal et al. [34] | FPGA | 97 | – | IoT device authentication | Golay-code-based self-error correction; reliability evaluated under environmental variations |
| Babaei et al. [35] | FPGA-based IoT platform | – | – | Lightweight authentication | PUF-based reconfigurable security architecture for long-lifetime IoT devices |
| Yoon et al. [36] | Raspberry Pi + USRP + SRAM-PUF | – | – | Replay-resistant authentication | Physical-layer information combined with device PUF; experimental IoT testbed |
| Proposed RHE-PUF | Xilinx Spartan-7 XC7S50 | 98.14 | 58.27 | Authentication, identity, metadata, and tracking protection | Placed-and-routed FPGA implementation; CRPs for ML evaluation |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the author. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Khalil, K. Secure UPnP Resource Discovery Using a PUF-Assisted Hardware Accelerator for IoT. Sensors 2026, 26, 5410. https://doi.org/10.3390/s26175410
Khalil K. Secure UPnP Resource Discovery Using a PUF-Assisted Hardware Accelerator for IoT. Sensors. 2026; 26(17):5410. https://doi.org/10.3390/s26175410
Chicago/Turabian StyleKhalil, Kasem. 2026. "Secure UPnP Resource Discovery Using a PUF-Assisted Hardware Accelerator for IoT" Sensors 26, no. 17: 5410. https://doi.org/10.3390/s26175410
APA StyleKhalil, K. (2026). Secure UPnP Resource Discovery Using a PUF-Assisted Hardware Accelerator for IoT. Sensors, 26(17), 5410. https://doi.org/10.3390/s26175410

