Towards Understanding and Enhancing Security of Proof-of-Training for DNN Model Ownership Verification