AI & Computingarticle2026-09-04

HRCred: Revocation-Consistent Hardware-Rooted Credentials for Cross-Domain Industrial Cyber–Physical Systems

Open access0 citations

Abstract

Mobile industrial devices increasingly cross administrative domains. A maintenance terminal certified in one factory can be dispatched to another, while autonomous vehicles cross fog domains while reaching cloud digital twins. Existing solutions force a trade-off. Long-lived certificates expose a stable identity that every visited domain can track and that is clonable once a device is captured, while single-gateway token services concentrate issuing power in one trusted node and asynchronous revocation leaves an unquantified window in which a revoked device is still accepted. Here, we present HRCred, which converts hardware identities rooted in physical unclonable functions (PUFs) into domain-bound, epoch-bound, and threshold-issued short-lived pseudonymous credentials. A device proves possession of its reconstructed root key to its home domain using only symmetric primitives. A set of fog issuers jointly signs each credential with a t-of-n threshold BLS signature, so no coalition of fewer than t issuers can mint one. Finally, a monotonic revocation-epoch mechanism yields a configurable upper bound on how long a revoked credential can still be accepted, which we prove and validate. On constrained hardware, the device side costs 3.6 mJ (18.8 ms authentication and 5.4 ms verification, on par with the lightest single-gateway token) while resisting up to t−1 compromised issuers, cutting cross-domain linkage AUC to 0.55, and keeping all 12,000 measured post-revocation acceptances below the analytical bound.

// Source

View paper (DOI)Open access versionOpenAlexElectronicsPublished 2026-09-04

Authors: Haozhe Zhou, Hang Lei, Maolin Yang

Institutions: University of Electronic Science and Technology of China