Methods and systems for serializing items and recovering data from serialized items.

By encrypting the item serial number and embedding a symbol string of length L', and using format-preserving encryption or self-synchronizing stream encryption technology, the problem of linear asynchrony in item serialization is solved, and unique identification and authentication of items are achieved.

CN115812289BActive Publication Date: 2026-01-30SICPA HOLDING SA
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202180048340.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-07-06
Filing Date
2021-07-06
Publication Date
2026-01-30
Estimated Expiration
2041-07-06

AI Technical Summary

Technical Problem

Existing technologies suffer from linear asynchrony issues during item serialization, resulting in incorrect code synchronization and ineffective item identification and authentication, especially in scenarios such as banknotes and pharmaceutical blister packs where serialization is difficult to achieve.

Method used

The unique serial number of the item is encrypted using an encryption key to generate a unique code of length L, which is then embedded in a symbol string of length L', where L' is greater than L. The readability and recoverability of the code are ensured by format-preserving encryption or self-synchronizing stream encryption. The serial number is recovered using a decryption key.

Benefits of technology

It enables correct identification and authentication of items under any circumstances, ensures the uniqueness and readability of serial numbers, and solves the serialization failure problem caused by linear asynchrony.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115812289B_ABST
    Figure CN115812289B_ABST
Patent Text Reader

Abstract

A method for serializing items includes: encrypting the serial number of each item using an encryption key k to obtain a unique serial number and marking the unique serial number on the item. The unique serial number, having a length L, is included in a symbol string of length L', where L' is greater than L, and is marked on the item. A corresponding method for recovering the unique code and corresponding serial number from the symbol string marked on the item, along with a corresponding serialization and recovery system, is disclosed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the technical field of secure coding of articles to enable article identification, authentication, tracking and tracing, and more specifically, to methods and corresponding systems for article serialization. Background Technology

[0002] Counterfeit consumer products, particularly pharmaceutical products, have been a major problem for many years, resulting in a large number of low-quality, dangerous products on the global market and significant revenue losses for manufacturers.

[0003] Current solutions to counterfeiting involve item serialization and / or serialization of serial numbers, which involves printing unique codes on a series of products, packaging, stamps, etc., to uniquely identify each individual product. Typically, the code is a sequence of symbols, such as glyphs, characters, numbers, etc., generated by encrypting the unique (serial) number associated with the item. This unique serial number actually specifies the order of items within a given series (e.g., the order of items in a production line); in this respect, the serial number corresponds to an ordinal number. The main goal of encrypting this unique serial number is to hide the actual order of the items to prevent counterfeiters from easily guessing the reliable sequence of serial numbers (corresponding to consecutive items).

[0004] For example, WO2018204319A1 describes the tracking and authentication of products, such as drug tablets and other elements stored in blister packs or similar packaging, to verify their authenticity. The product sequence defined by the physical properties and location of the drug product within the packaging is encrypted and used to mark the packaging using codes.

[0005] Typically, serialization does not have synchronization issues; each product / item / label uses an appropriate trigger or encoder to receive a unique code. Incorrectly printed products can usually be automatically removed from the production line. This classic serialization only works well if each item is strictly marked with its unique code without errors.

[0006] However, in some cases, linear asynchrony can occur, meaning the codes become misaligned (not properly synchronized) within an item, causing the codes to separate between consecutive items, such that an item might have the end of a previous code concatenated with the beginning of the next code. In this case, classical serialization cannot decrypt the codes to find the correct serial number. Linear asynchrony can occur due to various technical reasons, such as applying pre-marks to foil, which is then cut with strict control over the cutting position when applied to the items. For example, the serial numbers of a batch of items may be printed sequentially on a continuous strip (usually paper) and then cut into segments of length corresponding to the length of the codes to be applied to the items: due to possible offsets during the cutting stage, the segments applied to a given item may include only a portion of the corresponding code and parts of adjacent codes. This is especially true for banknotes with serialized security threads: the encoded serial numbers are printed sequentially on a continuous thread, and this thread is cut into segments of length that typically correspond to the width of the banknote, and each segment is applied (or inserted) onto the corresponding banknote, which has the potential for offset problems. The lateral positioning of the thread on the banknote may even vary. In some cases, registration can be difficult due to the high speed of moving objects, the lack of complex registration mechanisms, or the mechanical impossibility of registration. In any case, linear misalignment makes typical serialization impossible, thereby jeopardizing the subsequent identification and / or authentication of coded items (this misalignment can also occur during the acquisition and reading stages).

[0007] Examples involve security threads inserted as authentication features into banknotes of many central banks, such as... Figure 11 As shown. This type of thread is made of large polymer or metal foil and marked with a constant printing process. The foil is continuously cut and divided into threads on a large roller, and these threads are incorporated into the security paper during the papermaking process. After printing, the threads are finally cut only at the ends within the banknote. Due to the lack of linear registration, typical serialization is not possible. Therefore, security threads are not currently used in this manner.

[0008] Therefore, the object of the present invention is to provide a method and a corresponding system for serializing articles, which will allow linear asynchronous-recovery coding and enable the application of appropriate serialization in any situation (including situations where code registration is difficult or impossible).

[0009] Thanks to this invention, the aforementioned drug blister packs can now be serialized before being cut and used for pill packaging. For example... Figure 12As shown, the security thread on banknotes can benefit from this invention and can be serialized. More specifically, the continuous stream of code printed on the security thread now ensures that two different banknotes will never carry the same inscription, and therefore these banknotes can be uniquely authenticated. Furthermore, the asynchronous-recovery property will make them readable under any circumstances. Such additional security features can be both human-readable and machine-readable. Summary of the Invention

[0010] According to one aspect, the present invention relates to a method for serializing articles, comprising:

[0011] - Use encryption key k to encrypt the unique serial number of each item to obtain the corresponding unique code, and

[0012] - Use a unique code corresponding to each item to identify it.

[0013] Each unique code has a length L and is included in a symbol string of length L', which is marked on the corresponding item, and L' is greater than L.

[0014] The symbols in the symbol string may include graphic symbols selected from human-readable characters and machine-readable symbols. These symbols in the symbol string can be selected from a set of glyphs, preferably from the alphabet, alphanumeric, or numeric symbols.

[0015] According to a variation of the above method, the unique key exists in the symbol string with an offset, where L' is greater than or equal to (2L-1). In another variation, the unique key exists in the symbol string with an offset, where L' is less than (2L-1).

[0016] In the above method, the offset of the unique code in the symbol string is preferably performed by applying different alphabets for different positions of the symbols in the unique code, or by applying a marker between consecutive unique codes, wherein the marker is selected from a spacer, a special mark, or a box. Alternatively, an offset indicator may not be used; that is, no marker is used and the same alphabet is used for all symbols.

[0017] The aforementioned markings on an item can include direct markings or printing, the application of pre-printed numbers, or laser engraving. The item's serial number can be encrypted to obtain a unique code by applying block encryption or a combination of block encryption and format-preserving encryption (FPE).

[0018] Alternatively, the serial number of an item can be encrypted using stream cipher cipher feedback based on self-synchronizing ciphertext feedback to obtain a unique code, where the symbols of the serial number are encrypted one by one using a stream cipher structure with formatted preservative encryption (FPE). Ciphertext feedback (“CFB”) means that the encryption of a symbol depends on one or more previously encrypted symbols. Furthermore, the minimum length L' of the symbol string marked on the item can be equal to (L+K), where K>0 is the feedback length, which includes several characters or at least one symbol in addition to the length L of the unique code. In this variation, offsets are preferably indicated by using different alphabets for different positions of symbols in the unique code or by using a specific symbol at the beginning of the code.

[0019] According to another aspect, the present invention relates to a decryption method for recovering a unique code and corresponding serial number from a string of symbols marked on an article according to the above-described serialization method, comprising:

[0020] - Read the symbol string with length L' marked on the item;

[0021] - Based on the decryption key k', decrypt the symbol block of length L with offsets from 0 to L-1 within the symbol string of length L' read from the item, where L' is greater than L;

[0022] - For each sequence number candidate n corresponding to a block with length L, calculate the previous sequence number n-1 and the next sequence number n+1;

[0023] - Encrypt sequence number n-1 and sequence number n+1 using encryption key k respectively to obtain the previous sequence number candidate and the next sequence number candidate represented as symbol strings;

[0024] - The previous sequence number candidate is compared symbol by symbol with the corresponding left portion of a symbol string of length L', and the next sequence number candidate is compared symbol by symbol with the corresponding right portion of a symbol string of length L'.

[0025] in,

[0026] If all compared symbols match, the correct unique key and the corresponding correct sequence number n can be recovered from the read symbol string; and

[0027] If at least one sign comparison for the offset fails, then no serial number corresponds to the offset. According to another aspect, the invention also relates to a system for serializing articles, comprising:

[0028] - A memory and a processor, the memory and processor being configured to enable the system to encrypt the serial numbers of each item using an encryption key k stored in the memory to obtain the corresponding unique code, and

[0029] - A marking device, which is connected to the processor and adapted to mark an item with a unique code received from the processor.

[0030] The system is configured to include each unique code of length L into a symbol string of length L', where L' is greater than L, and is configured to mark the symbol string on the corresponding item.

[0031] The memory, along with the processor, can be configured to enable the system to use block encryption with a combination of format preservation encryption (FPE) or stream encryption based on self-synchronizing feedback.

[0032] Alternatively, the memory, along with the processor, can be configured to enable system application format preservation encryption (FPE), in which the serial number's password is encrypted one by one using a stream cipher structure.

[0033] According to another aspect, the present invention also relates to a system for recovering a unique code and corresponding serial number from a string of symbols marked on an article by a system for serializing articles as described above. The system includes a processing unit equipped with a memory unit and a reader, wherein the reader is adapted to read the string of symbols marked on the article and store the read string of symbols in the memory unit, and the processing unit is configured to cause the system to perform the following operations:

[0034] - Based on the decryption key k' stored in the memory cell, decrypt a symbol block of length L with offsets from 0 to L-1 within a symbol string of length L' stored in the memory cell, where L' is greater than L;

[0035] - For each sequence number candidate n corresponding to a block with length L, calculate the previous sequence number n-1 and the next sequence number n+1;

[0036] - Encrypt sequence number n-1 and sequence number n+1 using encryption key k respectively, and obtain the previous sequence number candidate and the next sequence number candidate respectively;

[0037] - Compare the previous sequence number candidate symbol by symbol with the corresponding left portion of the symbol string of length L', and compare the next sequence number candidate symbol by symbol with the corresponding right portion of the symbol string of length L'.

[0038] in,

[0039] If all compared symbols match, the system is adapted to transmit a signal indicating that the correct unique code and the corresponding correct sequence number n have been recovered from the read symbol string; and

[0040] If a comparison for at least one symbol fails for the offset, then no sequence number corresponds to the offset.

[0041] The invention will be described more fully below with reference to the accompanying drawings, in which the same reference numerals denote the same elements throughout the drawings, and in which prominent aspects and features of the invention are shown. Attached Figure Description

[0042] Figure 1 An example of 7 printed characters (symbols of a concatenated string of length L' = 7) with a 4-character length code (symbols of a code with length L = 4).

[0043] Figure 2 An example of 6 printed characters (L'=6) with a 4-character length code (L=4) is shown.

[0044] Figure 3 This is a schematic diagram of a method for decrypting serial numbers with printed codes that are longer than the actual sequence length.

[0045] Figure 4 This is a diagram illustrating a method for decrypting a serial number when L' is less than 2L-1 and there is no L-length code within the L' character.

[0046] Figure 5 This example demonstrates serialization using format-preserving encryption.

[0047] Figure 6 An example is given of using a stream cipher format to preserve encryption for serialization for ciphertext feedback of 4-character length (L=4) and 3-character length (K=3).

[0048] Figure 7 An example of a serialization decryption scheme is given, which requires at least L' = L + K printed characters to properly decrypt L characters.

[0049] Figure 8 This is a schematic diagram of stream cipher serialization encryption, where L' = L + K + T, and T is an optional extra length, i.e., T ≥ 0 (here: T = 1 and L' = 8).

[0050] Figure 9 An example of stream cipher serialization and decryption of characters is shown.

[0051] Figure 10 An example of a proprietary barcode / symbol system is shown, consisting of linearly printed miniature 1D / 2D patterns, each pattern representing a symbol of the alphabet.

[0052] Figure 11 Examples of standard security threads integrated into banknotes in many countries are shown, illustrating the asynchronous nature of their inscriptions along their length and the varying lateral positioning.

[0053] Figure 12 An example is shown of a security thread marked with linear asynchronous-recovery serialization, which can be used as an additional authentication feature for banknotes. Detailed Implementation

[0054] A serial number is a unique identifier associated with a single item. The serial number corresponds to an ordinal number belonging to a set of serial numbers, logically ordered in a known sequence (such as 0, 1, 2, 3, 4, ..., n-1, n, n+1, ..., M-1): this set contains a total of M distinct serial numbers, where M is greater than or equal to the total number of items that must be labeled (e.g., the total number of items in a production batch). Therefore, each item is uniquely associated with a serial number, such as serial number n being associated with the nth item, n+1 with the (n+1)th item, and so on. Serial numbers can be represented in any base, such as decimal or binary: the minimum bit length L required to encode these M distinct serial numbers is... bin It is L bin =ceil(log2(M)), or the minimum decimal digit length L dec It is L dec =ceil(log) 10 (M))(where log2(.) and log 10 (.) are the base-2 and base-10 logarithms respectively, and ceil(.) is the smallest integer greater than or equal to 10.

[0055] These serial numbers are then scrambled (e.g., encrypted) to hide their actual order, preventing potential forgers from easily guessing the sequence from several known serial numbers. For this purpose, the serial numbers are encrypted using an encryption algorithm with an encryption key k that should be kept secret, resulting in scrambled serial numbers. These scrambled serial numbers are then converted / formatted into encoded numbers or codes for marking on items. Since encryption is one-to-one reversible, there is a bijective relationship between the serial numbers and the scrambled serial numbers (i.e., codes): the latter is also unique, and each original serial number can be recovered by decrypting the scrambled serial number using a decryption key k' corresponding to the key k used for encryption. The order of the scrambled serial numbers is unpredictable to forgers without knowing the decryption key k'. The scrambled formatted serial numbers can be represented using a base other than the unscrambled formatted serial numbers, but both are typically represented using the same base.

[0056] An alternative to encryption is to simply generate a series of truly random codes and store them in a database, each associated with a sequential index of 0, 1, ..., n, n+1, ... However, this does not guarantee their uniqueness over very long code sequences. Furthermore, checking each new code not yet in the database would be computationally impractical.

[0057] In contrast, due to the bijective nature of encryption, the first advantage of serial number encryption is that it is a very easy and commonly used method for generating codes in a shuffled order. These codes can also be stored in a database (indexed by their associated serial numbers) as if they were truly random, but without requiring uniqueness checks.

[0058] The second advantage of encrypting the serial number is that it allows us to avoid using a code database: finding the serial number from the code only requires the key.

[0059] Typically, encryption used for serialization employs symmetric encryption, i.e., k = k', which should be kept secret. Figure 3 The text is a series of seemingly unrelated phrases and sentences, making it impossible to translate coherently. It appears to be a collection of fragments from various sources, possibly related to a document or chart. -1 The inverse decryption of the labeled sequence. Generalization to asymmetric cryptography is theoretically possible (different k and k', k remains private), but at the cost of significantly longer scrambling sequence numbers to ensure sufficient cryptographic security: for example, a minimum of 2048 bits is recommended for RSA, or 256 or 384 bits for elliptic curve cryptography, and so on. Requiring such long sequence numbers (and scrambling sequence numbers) is typically a problem of serializing items using sequence numbers, where the shortest possible length L' of the labeled string needs to be.

[0060] In contrast, symmetric encryption offers the possibility of reducing the bit length of the sequence number to the shortest possible value that ensures a sufficient total number of sequence numbers M. Symmetric block encryption, such as AES, Twofish, IDEA, DES, Triple-DES, etc., is typically used to encrypt the sequence number one by one. However, they use fixed block lengths: 64 bits, 128 bits, etc., so steps must be applied to ensure a better fit to the block size of M desired sequence numbers (typically shorter than 64 bits). This can be done by applying well-known and verified compositional methods on top of these schemes (such as the Feistel structure). Ad-hoc block-length key cryptography can also be derived from non-key-secure hash algorithms with Luby-Rackoff structures (such as the SHA-2 family, Whirlpool, etc.).

[0061] In the case of symmetric encryption, another generalization involves using non-block encryption, such as stream encryption or stream ciphers: bits or groups of bits of the input data are encrypted sequentially and continuously by combining these bit groups with a pseudo-random sequence of bit groups, which is cryptographically generated depending on a key k (typically the bits are XORed with the original data bits). However, a resynchronization mechanism should be used to ensure the decoding phase. Stream encryption is neither relevant nor recommended for the first serialization method (i.e., "Method 1") via symmetric block encryption. In contrast, stream encryption with ciphertext feedback is fully utilized, and a second serialization method (i.e., "Method 2") is described in a later paragraph.

[0062] Before marking items, the scrambling serial numbers must be formatted into strings of L symbols (i.e., strings of length L or L-length codes), resulting in codes that are also scrambled (because their order within the code sequence is unpredictable). The formatting in... Figure 3 The operation is represented as "A", and its reciprocal, i.e., the deformatted form, is "A". -1 Each symbol is taken from a finite set of N possible symbols, called the set of alphabets with a base N. This formatting is typically a base transformation, where the base equals the alphabet base N, and optionally the code is divided into smaller groups of symbols to make the transformation more efficient. Symbols at positions different from the beginning of an L-length code can generally be encoded by different symbols, from one alphabet, or from a different alphabet, depending on that position in the code, and may have different bases. However, for all L symbols, the same alphabet and the same base are generally used. An L-length code uniquely represents a sequence number, but is typically based on a base other than base 2 (binary) and is generally in a format more suitable for item marking and human readability.

[0063] Therefore, the length L of the code should be large enough to allow for the total number of items to be marked: L = ceil(log N (M)), where N is the alphabet cardinality (for simplicity, we consider the same alphabet for all symbols), log N (.) is the logarithm of the base N, ceil(.) is the smallest integer value greater than or equal to -1, and M is the total number of distinct serial numbers and codes of the item to be marked.

[0064] In the field of serialization, a common practice is to choose a value M that is many times larger than the expected total number of items to make the code less susceptible to guessing by attackers. This reduces the probability that a random (guessed) code might accidentally correspond to an existing serial number / existing item.

[0065] Finally, in order to mark physical items, the individual symbols of the code should be given a graphical representation. These can be (and are not limited to) any human-readable characters, graphic symbols, ideographic symbols, glyphs, drawings, etc., or even monochrome or color machine-readable symbols, such as 1D or 2D barcodes. Alternatively, they may be imperceptible to the human eye (e.g., printed with IR or UV ink) and can only be detected by machines and algorithms. We call this representation of the code ready to be marked a markable code.

[0066] The above has described how sequence numbers can be scrambled (i.e., encrypted) before being formatted into L-length codes, but this is not mandatory: sequence numbers can also be formatted before scrambling. In this case, we obtain formatted sequence numbers consisting of L-length symbols from the alphabet described above (but not yet scrambled, and therefore not "codes"). Their generation order is still predictable, and they then need to be scrambled. To preserve the formatting in encryption, format-preserving encryption (FPE) should be used, which is a cipher that takes a string of symbols of length L as input and obtains an L-length string of symbols typically used for encryption from the same alphabet with the same base. In the prior art, FPE is used, for example, to encrypt credit card numbers; to encrypt text (such as words) in a language to encrypt other words in the same language; and so on. Several algorithms exist, but FPE can also be constructed, for example, using Feistel structures from block ciphers (such as AES and DES described above). Such ciphers work at the symbol level rather than the bit level. Finally, the final code must be converted into a string of glyphs of length L to produce a tokenizable code. All the prior considerations for using symmetric block encryption are the same; the sequence number is encrypted one by one into a taggable code.

[0067] When codes are synchronized with items, this serialization is easy to read and decode: simply read and decrypt the codes one by one. However, this method no longer works when desynchronization occurs: there are no triggers, no visible markers, intervals, etc., to allow finding the beginning and end of each code. Worst of all, a portion of a previous code might concatenate with a portion of a subsequent code on a marked item.

[0068] Therefore, additional techniques are used to recover from such codes, along with marking each item with more code symbols / glyphs, i.e., L', instead of the actual code length L, to aid in this resynchronization. For this purpose, L-length markable codes are generated sequentially, with the code corresponding to a sequence number n (and the corresponding item), the next code corresponding to the next sequence number (let's label it n+1), the code after that corresponding to the sequence number n+2, and so on. All the markable codes form a long (continuous) string consisting of consecutive L-length strings of symbols concatenated in the described order. Typically, to mark an item with a code, this long string is truncated at (more or less) uncontrolled positions / lengths, resulting in a short "concatenation," i.e., a string of symbols that includes only a portion (shorter than L) of the code of length L. This short concatenation is the string of symbols that is effectively marked on the item. Therefore, the short concatenation is asynchronous, i.e., it is unknown which symbols / glyphs are the first of the markable codes within this short concatenation. We are operating in a situation where other synchronization techniques cannot be used, for example, when reading codes, there are no visible markers or trigger signals to aid resynchronization. According to the invention, to avoid this potential asynchronous effect (or desynchronization effect), the length L' of the concatenated string should be strictly greater than L (L'>L), thus the concatenated string now contains at least two portions of two consecutive codes.

[0069] For general purposes, this also includes situations where such asynchrony occurs during the reading phase rather than the marking phase, for example, when there is a long, continuous stream of marked symbols without visible synchronization marks.

[0070] The method 1 described above according to the present invention is a method for recovering an appropriate code and corresponding serial number from a marked item generated by the above code generation and marking process. Therefore, we have a concatenated string of length L', where L'>L (L is the length of the code) and an unknown synchronization within the item. Two cases can be distinguished: the case where L'≥(2L-1) and the case where L'<(2L-1).

[0071] 1) Case L'≥(2L-1):

[0072] Figure 1 The case described is a string of symbols (i.e., a concatenated string) with a code of length L = 4 and a token of length L' = 7, so L' = (2L - 1). Synchronization is unknown, that is, the position of the first symbol of the L-length code within the L'-length concatenated string is unknown. Let us call this position the offset of the L-length code from the beginning of the L'-length concatenated code, or simply the offset. However, it is known that a string with four symbols S... 0 n S 1 n S 2 n S 3n The complete L-length code (see) Figure 1 The box (5) in the middle always exists at least once in the concatenation of length L', that is, the concatenation block (5) + (6), the incomplete part of the code (that is, part (6)) (the corresponding three symbols S of the next item n+1) 0 n+1 S 1 n+1 S 2 n+1 Left and / or right enclosing. L different offset positions should be tried; this is sufficient because the number of possible desynchronizations is obviously equal to the length of the full code, and any additional offsets repeat the offsets previously tested.

[0073] Figure 3 The method shown includes the following steps:

[0074] -For each offset position (by...) Figure 3 The arrow above indicates the current position 1), starting from the beginning of the L' length concatenation from 0 to L-1, pruned by the symbol S. i n The candidate key S of length L, composed of (i = 0, 1, 2, 3) n (5).

[0075] - Decrypt the candidate code using the decryption key k' to obtain the sequence number candidate n. Decryption is applied in the reverse manner of encryption and depends on this:

[0076] (1) Reverse formatting (i.e., applying A) -1 That is, the candidate symbol code of length L is deformatted to obtain the corresponding scrambled sequence number, and then the result is decrypted using the decryption key k' to obtain the corresponding sequence number candidate n (i.e., applying E). -1 );

[0077] Alternatively: Use the decryption key k' to decrypt the L-length symbol code with format-preserving encryption (applying FPE). -1 (not shown here) to obtain formatted serial number candidates, then reverse the format of the latter (i.e., apply A) -1 To find the corresponding sequence number candidate n;

[0078] For the candidate n of the sequence number, calculate its previous candidate n-1 and its next candidate n+1 (2);

[0079] - Obtain the corresponding encrypted and formatted previous and next candidates from the previous candidate n-1 and the next candidate n+1 respectively through the following steps (3):

[0080] The encryption key k is used to encrypt the previous (n-1) and next (n+1) sequence number candidates, and the obtained previous and next scrambled sequence number candidates are formatted (via operation A) to form the previous and next code candidates S', respectively. n-1 S' n+1 ;

[0081] Alternatively: Format the previous sequence number candidate n-1 and the next sequence number candidate n+1 respectively to obtain formatted sequence number candidates, and encrypt them with FPE using the encryption key k to obtain the previous code candidate S' respectively. n-1 and the next code candidate S' n+1 . Figure 5 The document describes encoding using FPE: applying encryption after formatting, rather than before.

[0082] -The previous candidate S' n-1 The sign of (7) is compared with the corresponding sign of the remaining read concatenation (6) before the current offset position (if present) (4) (see Figure 3 ); the next candidate S' n The sign of -1(7) is compared with the corresponding sign of the concatenated string (6) read from the offset +L of the current attempt (4):

[0083] If all symbols match (from the result M of 4, left and right), then the correct offset, the correct code, and the correct sequence number n are found: this sequence number n can be kept as a candidate for correct decoding;

[0084] If at least one symbol comparison fails (i.e., mismatch, result MM, left or right), then no sequence number corresponds to that offset;

[0085] If all offsets from 0 to L-1 have been tried, and for all cases at least one sign pair mismatch (MM) of the comparison, the code cannot be decoded: the code read may have errors.

[0086] Typically, it is expected that only one attempt at offset in a concatenated string will yield a valid decoded sequence number n. However, sometimes it is possible to successfully decode more than one sequence number n' and n'" from the same L'-length concatenated string: this is a potentially unavoidable ambiguity: for any valid code, there may be another code in the complete sequence of M codes that matches when out of sync. However, in this case, only one of n' and n'" is the correct sequence number, i.e., it has already been used for encoding. To reduce this ambiguity, the following techniques can be applied:

[0087] - Ensure that L is large enough so that the alphabet used has a sufficient cardinality N; in fact, tests have shown that for a length - 6 code with L = 6, using base - 32 Crockford encoding (i.e., alphabet cardinality N = 32), for L' = 2L - 1 = 11, there is an ambiguity with a probability of 1.7x10 -7 and for L' = 2L = 12, there is an ambiguity with a probability of 6.2x10 -9 ;

[0088] - Utilize prior - known information, which is not encoded in the code itself but is usually associated with the corresponding batch of items. From this prior - known information, the expected characteristics of the serial - number sequence can be known. An example can be the expected batch number, i.e., the starting n1 serial number and the ending n2 serial number, so any decoded n that does not comply with the condition n1 ≤ n ≤ n2 can be rejected.

[0089] In principle, L' has no upper limit, and increasing L' reduces the occurrence of the above - mentioned ambiguity. However, of course, L' is chosen to be as small as actually acceptable in the target context.

[0090] 2) Case L' < 2L - 1:

[0091] This case is described in Figure 2 where L = 4 and L' = 6, so L' < 2L - 1. In this case, for some offset positions, there are complete L - length codes (5), but for some other offsets, there are no complete codes within the L' - length concatenated string: for these latter cases, the concatenated string is composed of the concatenation of parts (6) from two consecutive codes, but neither of them is complete. However, since L' > L, complete - code candidates can still be trimmed for some offsets.

[0092] The decoding process is the same as in the case of L' ≥ 2L - 1 above, and no modification is required when trimming complete L - length code candidates from the concatenated string. However, as Figure 4 shows, in the case of code candidates with length < L, a specific method is required. In this situation, as described below, when L' < (2L - 2), the starting offset position P is defined as negative. Additional techniques are used for offsets where there are only two incomplete candidate - code parts. This is the case when P is negative (P < 0: the symbol is missing on the left) or when the position of the last symbol of the candidate code exceeds the length of the concatenated string (i.e., P + L > L': the symbol is missing on the right).

[0093] The incomplete - code - candidate cases are solved by an exhaustive search for the missing symbol(s). The process of solving incomplete - code - candidate cases works as follows:

[0094] The first (leftmost) offset position tried can be given by: P = floor((L’-(2L-1)) / 2), relative to the start of the L’-length concatenated string, where floor(.) is the largest integer less than or equal to - the integer value, and " / " is the division; |P| is actually half of the potentially maximum missing symbols relative to the length (2L-1). The goal is to minimize the missing symbols on the left or right of the candidate code, which is why P can be negative;

[0095] The last offset position is P’ = P + L - 1; let's also define the position of the last symbol of this last offset as Q = P’ + L - 1 = (P + L - 1) + L - 1 = P + 2(L - 1), Q being the rightmost position of the last symbol of the candidate code within the L’-length concatenated string;

[0096] For each offset position p from P to P’ (including P’), trim the L-length code candidate. We have the following sub-cases:

[0097] If p ≥ 0 and p + L - 1 < L’, then there are no missing symbols on the left or right of the L-length candidate code: it is complete and nothing more needs to be done;

[0098] If p < 0 (which is possible if P < 0), there are |p| missing symbols on the left; thus, R = |P| is the maximum missing symbol on the left of the L-length candidate code. On the other hand, if p + L > L’, there are missing symbols on the right; thus, at most R = Q - (L’ - 1) = P + 2(L - 1) - (L’ - 1) = P + 2L - L’ - 1 missing symbols on the right of the L-length candidate. In both cases, the missing symbols on the left or right are filled with all combinations (8) of the missing symbols from their alphabet (a i , i = 0, ….., N - 1) (see Figure 4 ), resulting in the same number of L-length code candidates (5). Note that as a result of the condition L’ > L, symbols can be missing on the left or right, but never on both sides.

[0099] For each such candidate L-length code, the subsequent steps are exactly the same as those for the case L’ ≥ 2L - 1 above. The only difference is that for each case of missing symbols, one candidate here becomes many candidates according to the exhaustive search of the missing symbols.

[0100] To reduce ambiguity, for the case L’ >= 2L - 1, prior known information related to batches can be used: the expected batch range, i.e., starting n1 and ending n2 serial numbers, etc.

[0101] In the above method 1:

[0102] - Exhaustive search for missing symbols can be computationally intensive, limiting the maximum number of missing symbols that this method can handle in real-world scenarios. Therefore, L' should be reasonably close to 2L-1: the maximum number of exhaustive searches required for a given offset position is N. R , where R is the maximum number of missing symbols from the alphabet of radix N, and this number increases rapidly. For example, the maximum number of missing symbols R = 2 or 3 can be considered the acceptable maximum for a 32-radix alphabet (i.e., for N = 32, R = 2 results in 1024 iterations, and R = 3 results in 32768 iterations!).

[0103] - As already mentioned, the starting offset position P is negative to limit the maximum number of missing symbols R; otherwise, if the offset position simply started from 0, this number would be more than twice as many.

[0104] Finally, guessing missing symbols increases the likelihood of ambiguity during the decoding phase because less information is available in the L'-length concatenation as L' decreases. In the extreme case of L' = L, all attempted offsets will be ambiguous, which is why the constraint L' > L has been fixed. Again, L' should be kept reasonably close to 2L-1 to achieve a low probability of ambiguity.

[0105] Compared to method 2, where the sequence number is encrypted and decrypted one by one, method 1 according to the present invention relies on a block encryption method. However, there are ciphers with self-resynchronization capabilities that can be used to solve the desynchronization problem. These are called self-synchronizing stream ciphers, and such a property makes them naturally suitable for desynchronized serialization.

[0106] Stream ciphers are encryption schemes in which plaintext bits (or characters, symbols, etc.) are combined with a pseudo-random stream associated with a key. Each plaintext bit is encrypted one-by-one with the corresponding bit of the pseudo-random stream to produce encrypted bits. Because the encryption of each bit depends on the current state of the cipher, it is also called a state cipher. Typically, bits are used, and the combination operation is XOR. To achieve symbol-by-symbol (not bit-by-bit) encryption, format-preserving cipher (FPE) is used, which preserves the alphabet for each symbol. Because it is also a stream cipher, it is named stream FPE or sFPE.

[0107] A self-synchronizing stream cipher is a stream cipher in which the current state depends on the K preceding bits, characters, etc., of the ciphertext. This scheme is also known as an asynchronous stream cipher. The idea of ​​self-synchronization has the following advantages: the receiver automatically synchronizes with the keystream generator after receiving K bits of ciphertext; in case of an error, the scheme automatically resynchronizes after decrypting K bits. An example of a self-synchronizing stream cipher is a block cipher used in Cipher Feedback (CFB) mode.

[0108] Stream ciphers are frequently used due to their speed and simplicity, especially in applications where plaintext appears in quantities of unknown length. This also avoids the problem of padding block ciphers (and the resulting performance or space penalty) when data should be transmitted bit-by-bit (typically: characters, bytes) consecutively.

[0109] Examples of general stream ciphers are: ChaCha, RC4, A5 / 1, A5 / 2, Chameleon, FISH, Helix, ISAAC, MUGI, Panama, Phelix, Pike, SEAL, SOBER, SOBER-128, and WAKE. Secure stream ciphers can also be constructed from block ciphers or cryptographically secure hashes with specific structures.

[0110] The same considerations as in Method 1 represent the encryption key k and the decryption key k': theoretically, stream encryption can be either symmetric or asymmetric.

[0111] However, existing stream and FPE cryptosystems are actually symmetric cryptosystems. This is due to their symbol-by-symmetric nature, where symbols are short-bit elements, whereas asymmetric encryption like RSA would require large (or very large) words, which is impractical. Most importantly, the pseudo-random sequence used for encryption needs to be regenerated with the same seed, meaning a symmetric key with k' = k.

[0112] Although the stream encryption / decryption automatically resynchronizes, it doesn't provide information about the actual start of the L-length code. Therefore, additional techniques are needed to identify code synchronization within the concatenated string, which will be described below.

[0113] like Figure 6 As shown, to generate serial numbers and tags, this invention uses a self-synchronizing stream cipher applied to format the serial numbers. As in Method 1, the serial numbers are uniquely associated with the item in a sequential manner (labeled 0, 1, 2, 3, 4, ..., n-1, n, n+1, ..., M-1). However, unlike Method 1, they are preferably first formatted, concatenated into a continuous stream, and then encrypted. Therefore, sFPE (“stream FPE”) is required.

[0114] Through encryption Figure 6 And for decryption Figure 7 To illustrate this method, we apply it to serialization where the code length L = 4, the number of received encrypted symbols L' = 7, and therefore K = L' - L = 3. The one-way encryption function F takes K previously encrypted symbols S... i n (i = 0, 1, 2...) and the key k continuously generate pseudo-random values, progressing in the direction of the arrow. For generality, the pseudo-random stream values ​​are related to the plaintext data symbols C. in The combination is represented as an addition "+" used for encryption (e.g., in...). Figure 6 Add to C 3 n ), and is represented as a subtraction "-" used for decryption (e.g., in Figure 7 In the middle, from S 1 n (Middle reduction). During decryption, the first K symbols cannot be decrypted because these symbols are missing the first K symbols in a concatenated string of length L', and... Figure 7 The text is marked with a "?".

[0115] Let L' = L + K (where K > 0) be defined as the minimum length of a symbol string capable of decrypting at least L symbols. However, typically L' ≥ L + K, or L' = L + T + K, where T ≥ 0. In encryption... Figure 8 In and used for decryption Figure 9 The overall method is described in the figure, where L = 4, T = 1, K = 3 and therefore L' = 8.

[0116] The code generation process corresponding to Method 2 is as follows:

[0117] - As defined in Method 1, the sequence number is formatted using code symbols from the alphabet to obtain... Figure 8 Formatted serial number C i n They haven't been scrambled yet.

[0118] - The formatted sequence numbers can be viewed as being concatenated, arranged in the same order as the input sequence numbers, to form a longer, unencrypted contiguous string. The length of the concatenated string is L' = L + T + K, where K > 0 is the feedback length, and T ≥ 0 is the number of extra symbols that help with resynchronization when the sequence numbers must be decoded.

[0119] Then, using the encryption key k, the self-synchronizing stream cipher is applied to this unencrypted string, changing the string symbol C. i n The input is taken sequentially, and a sequence of K (where K>0) previously encrypted symbols is used as feedback to achieve self-synchronization during decryption. The feedback propagates across consecutive codes, meaning that one or more of the first symbols of each code depend on the feedback from the encrypted symbols of the previous code.

[0120] - To work within symbols, the cipher is a stream-formatted preserved encryption (sFPE), thus encrypting the formatted sequence number symbol by symbol from one alphabet(s) to one alphabet(s) (usually the same alphabet), thereby producing the encrypted symbols S. i nThis produces an "endless" string of L-length codes that are encrypted sequentially and concatenated. Encrypting a symbol can be done, for example, by arithmetically adding the output of the encryption function to the input symbol and modulo N the radix of the corresponding alphabet.

[0121] - For method 1, the string is cut into substrings of length L' in a (more or less uncontrolled) manner, where L' > L, forming a concatenated string. It should be ensured that L' = L + T + K, where K > 0 and T ≥ 0, to enforce future decodability generated by the ciphertext feedback mechanism.

[0122] - Symbols of these L' length concatenated strings, which are converted into glyphs or graphic elements in Method 1 to form a tagged code MC, are then applied to consecutive items.

[0123] The concatenated string should have a length of at least L' = L + K (where T = 0) to ensure proper decoding of at least L symbols. After decryption, these symbols may be discontinuous with a portion of the previous code concatenated with the current code. Then, as in Method 1, knowing that the previous code is n-1 relative to the current code n, a resynchronization technique described below is used. Additionally, extra symbols (where T > 0) are used to provide further information to aid resynchronization, and the known stream cipher ensures that (L + T) symbols are properly decrypted (but does not indicate the actual code offset), as described below.

[0124] In the assumption of a continuous, uninterrupted, and unique code sequence corresponding to serial numbers from 0 to M-1, each code depends on its preceding code. In the case of codes generated from different batches of items: the first L'-length concatenation of each batch must include the K-length ending portion of the last code of the previous batch; all batches must be generated consecutively to know the last code of each batch; and the first concatenation (corresponding to serial number 0) will require an initial K-length feedback string, which is defined as random, or for simplicity, set to a fixed constant, such as "all zeros".

[0125] Apart from the encryption key k, the entire code sequence corresponding to sequence numbers from 0 to M-1 will depend entirely on this initial feedback string. This value is needed for future decryption, but by definition it is included in the concatenated string. This initialization value that affects subsequent encrypted streams is commonly referred to as a random number or initialization vector (“IV”) in the cryptographic community.

[0126] However, forcing the complete code sequence to be unique (as explained earlier) is not necessary for serialization. In practice, codes can be generated from different batches that do not need to be consecutive or consistent with each other from the perspective of cryptographic feedback. The only required constraint for different batches is a range of non-overlapping sequence numbers relative to each other. Arbitrary IV values ​​(or fixed constants or "all zeros") can be defined at the beginning of each batch. In an extreme case, though impractical, random IVs can be generated for each new code. It is possible to skip the first code (or the first few codes) to generate the first concatenation of a batch. This is possible because the IV / feedback symbol is included within the concatenation and therefore does not need to be stored for decryption: the decryption from the concatenation always yields the correct sequence number n.

[0127] However, it is only necessary to store the IV for the batch (the batch has a start and an end) if the same batch must be regenerated in the same way several times, unless a constant (e.g., "all zeros") IV is used. Furthermore, this batch-attached IV can be used as additional information (or "auxiliary information") to check that the decoded concatenation was actually decrypted correctly.

[0128] During the decoding phase, self-synchronizing stream ciphers ensure that any input symbol after the first K symbols is always correctly decrypted, but they do not provide synchronization information themselves: the start (and end) of at least one code must still be found. Therefore, additional methods are needed to find the offset position of the code within the concatenated string.

[0129] The first approach is to provide additional symbols (T>0) to allow verification of the attempted offset position via symbol-by-symbol comparison. This corresponds to Case 1 of the decoding phase described below in "Sequence Number Decoding," where synchronization information is not included in the L-length cryptographic encoding. Then, T>0 simply adds symbols for more accurate decoding, helping to reduce decoding ambiguity.

[0130] The second method involves appending synchronization information (added before encryption) as part of the L-length code during serial number formatting (the added information is now encrypted). Case 2 is described in "Serial Number Decoding." This can be achieved, but is not limited to, through the following:

[0131] - Type 1 tags: In addition to the (L-1) remaining symbols of the formatted sequence number, for example, add a synchronization symbol at the beginning of each formatted sequence number.

[0132] - Type 2 label: Use symbols from a subset of the alphabet for the first symbol of each formatted sequence number (usually half of the alphabet), and use symbols from another subset of the alphabet for the (L-1) remaining symbols (usually the complementary half subset).

[0133] Importantly, this synchronization label is completed in the unencrypted domain, hiding it within the resulting encryption and concatenation: it doesn't reveal any information about the synchronization to the attacker, who knows they only have access to the scrambling code. To achieve this, the symbols are encrypted on the full radix N of the alphabet, regardless of the different alphabet subsets used for the input symbols or whether delimiter symbols are used. As a result, such a label is not equivalent to a visible mark that introduces a delimiter code.

[0134] The tag should be reversible during the decoding phase to allow the original serial number n to be recovered from the decrypted formatted serial number. Aside from the basic transformation, the tag can be viewed as an additional step when only the serial number is formatted.

[0135] Because the tag adds synchronization information that is not part of the original serial number information, the tag can increase the required code length L to cover all M items with a given alphabet relative to the untagged version. Based on the two tag examples above, for a total of M serial numbers and an alphabet of cardinality N, the following code length L values ​​are obtained:

[0136] Type 1 label: Insert delimiter symbol:

[0137] L = ceil(log N (M))+1,

[0138] Type 2 labels: using two distinct subsets of the alphabet, each with a base of N / 2 (assuming N is even), one for the first symbol and the other for the remaining symbols:

[0139] L = ceil(log N / 2 (M))

[0140] In practice, L is usually increased by 1 or 2: for example, for an alphabet with 32 different symbols (called the value of the cardinality):

[0141] For M=10 6 For each item: L=4 without a label, L=6 for a label of type 1, and L=5 for a label of type 2. The latter will be chosen to minimize L for the item label.

[0142] For M=10 11 If L = 8 without a label, 9 with a label of type 1, and 10 with a label of type 2, then type 1 is preferred.

[0143] For an alphabet with a base of 40:

[0144] For M=10 11L = 7 without a label, 8 with a type 1 label, and 9 with a type 2 label, therefore type 1 labels are the best.

[0145] Regarding Method 1, each symbol of the code should be given a graphic representation in monochrome or color before marking physical items (such as any human-readable characters, graphic symbols, or machine-readable symbols like barcodes).

[0146] Regarding serial number decoding, Figure 9 The text describes the decoding of the serial number according to Method 2. For Method 1, the actual serial number can be decoded from a concatenated string of length L' read from the item. However, unlike Method 1, decryption always outputs the correctly decoded symbols, but only after the first K symbols in the processed concatenated string of length L'.

[0147] Therefore, only the symbols from position K up to the last position (L'-1) of the concatenated string can be accurately decrypted. After decryption, ignoring the first K undecrypted symbols (marked as "?" in the diagram), we obtain a string of length (L'-K) of correctly decrypted symbols. Thus, typically, we obtain a string of length (L'-K) = (L+T) of correctly decrypted symbols, where T≥0 is the number of extra symbols. However, these symbols may still be out of sync. The correct synchronization, i.e., the actual offset of the L-length code within the decrypted concatenated string, is still unknown. Therefore, further synchronization techniques are needed after decryption.

[0148] The decryption of the cascaded string is performed as follows:

[0149] - Using the sFPE decryption key k', the concatenated string of length L” is decrypted to obtain a decrypted concatenated string of length (L'-K) or (L+T). Therefore, regarding the described encryption stage, the symbol can be decrypted by subtracting the output of the encryption function modulo the radix N of the corresponding alphabet from the input symbol. This process is as follows:

[0150] Starting from offset K and preferably to offset (L'-1) to sequentially decrypt each concatenated string symbol using T additional symbols (if present), or at least to offset (L+K-1). For each symbol decryption, the first K symbols of the encrypted concatenated string are used as feedback;

[0151] Symbols at offsets from 0 to (K-1) (represented by "?") cannot be decrypted because the encrypted symbols in the feedback cannot be used for them: therefore, they are ignored in the resulting decryption concatenation of length (L'-K).

[0152] The resulting (L'-K) length string is an exactly decoded symbol string of length (L+T), where T≥0. It contains the complete L length formatted serial number, or two possibly incomplete parts of consecutive formatted serial numbers.

[0153] Synchronization should be determined to reconstruct the original serial number, i.e., the boundary between the two code parts within the decrypted concatenated string should be found. The following two cases can be distinguished: Case 1, where there is no additional synchronization label; Case 2, where there is a synchronization label. And for both cases, T = 0, or T>0, reminder:

[0154] - The concatenation has a length: L'=(L+T+K), where T≥0 and K>0;

[0155] - The decrypted concatenated string has a length: (L'-K)=(L+T) and may be out of sync.

[0156] Correspondingly, the synchronization step includes:

[0157] Case 1: There is no synchronization label:

[0158] - Sub-case 1.a: For an L length decrypted synchronization string (i.e., T = 0, or only the first L correctly decoded symbols are retained): Unfortunately, L length formatted serial number candidates starting from the offset position from 0 to (L-1) are extracted, resulting in the same amount of ambiguity! This is because any offset-shifted formatted serial number candidate n is equal to some valid 0-offset-shifted formatted serial number n' elsewhere in the space formed by M possible serial numbers. And no label means no synchronization information is available to indicate the actual code offset. Therefore, this sub-case 1.a does not apply to this case 1 and must be discarded.

[0159] - Sub-case 1.b: An (L+1) length to (2L-1) length decrypted synchronization string with strictly more than L correct symbols (i.e., 0<T<L) is available. To verify, the remaining symbols can be used to verify each offset-shifted L length formatted serial number candidate. Similar to Method 1, this is done by matching n-1 and n+1 calculated from n symbol by symbol in formatted form, but the difference is that decryption / encryption is not required (the symbols have already been decrypted). This is similar to the case of L<L'≤(2L-1) in Method 1. For some offset positions, ambiguity may still occur, but as T increases, the occurrence of ambiguity decreases: Then, the concatenated string of length L' should reasonably be close to (2L+K) (or T should reasonably be close to L) to achieve a practically low probability of ambiguity.

[0160] Subcase 1.c: A concatenated string of length (2L+K), or a decrypted concatenated string of length 2L, or longer, is available, implying T≥L: the L-length formatted sequence number with each offset shift can be verified as described above. This is similar to the case of L'>2L-1 in Method 1. However, in this subcase, the ambiguity can be eliminated because one and only one valid candidate n matches either the pair (n-1, n) or the pair (n, n+1): this can be checked because one has 2L valid symbols. Furthermore, by utilizing more than 2L of correctly decrypted symbols, it may even be possible to detect whether the input concatenated string has errors by checking the decoded symbols with more occurrences of sequence numbers (such as (n-2), (n+2), etc.).

[0161] Scenario 2: Synchronization tags exist:

[0162] Once decrypted, each correctly decrypted concatenation of length (L'-K) or (L+T) contains tags used for encryption. From the non-exhaustive examples of type 1 and type 2 tags given in the description of the encoding, the decrypted tags include:

[0163] Type 1 label: A delimiter symbol inserted at the beginning of each formatted sequence number.

[0164] Type 2 labels: Symbols from one of the alphabet subsets indicate that it is the first symbol of the formatted sequence number, while other symbols come from complementary alphabet subsets.

[0165] The correct offset can then be derived from the label. Additionally, it is possible that:

[0166] - First, verify the consistency of the labels to detect erroneous input, and refuse decoding in case of errors. For example, by checking:

[0167] The delimiter symbol is separated by exactly L positions;

[0168] The first symbol is separated by precisely L positions;

[0169] Then, the decrypted concatenation is resynchronized, the tags are removed, and the appropriate sequence number n is regenerated.

[0170] Considering the sub-case of case 1 above, we have:

[0171] - Subcase 2.a: Decryption concatenation of length L is available (or T=0): Resynchronize, remove tags, and reconstruct sequence number n knowing that the expected sequence number sequence is (n-1), n, (n+1).

[0172] Subcase 2.b: L' = (L + T + K), where T > 0: Due to the label, resynchronization occurs, and additional symbols can be used to match the obtained symbols to ensure that the sequence number n can be correctly decoded. The expected sequence is known to be (n-1), n, (n+1). With more additional symbols T, it is even possible to check more symbols, possibly including (n-2), (n+2), or more. Therefore, as in Case 1 and Subcase 1.c above, it becomes easier to detect whether the input concatenation is incorrect and refuse to decode.

[0173] For subcase 2.b, since the comparison of the decrypted concatenated strings is not performed directly using the binary sequence number n (although this is not excluded) but is easier to do in the formatted field, it can be done as follows:

[0174] Use the corresponding basic (symbol C) i The calculation is performed in the formatted field, not in the sequence number field (n), but the synchronization tag is removed if it exists.

[0175] The first and second parts of the decrypted concatenated string must be reconcatenated in the correct order. Since the previous one corresponds to sequence number n-1 and the current one is n, the previous one is incremented by 1, or since it is n+1, the next sequence number is decremented by 1 to recover the appropriate L-length unencrypted string. Since sFPE is capable of outputting the correct decrypted value, it is known that the reconstructed formatted sequence number is correct.

[0176] Finally, the reconstructed formatted sequence number can be unformatted to obtain the actual sequence number n.

[0177] For the two sub-cases above, auxiliary information can still be used to reduce ambiguity, for example:

[0178] For the decoded n, check the expected batch range: the first n1 and the last n2 sequence numbers, and check n such that n1≤n≤n2.

[0179] As explained in the discussion of initialization vectors above, the stored initialization vector (IV) and the resulting intermediate code values ​​stored for each batch.

[0180] Regarding the feedback length K:

[0181] The feedback length K can be small, such that K ≤ L. However, it should be reasonably large enough, i.e., close to L, especially if L is small. The feedback length K is defined by the alphabetic base N as the variability V (i.e., the number of possible different encryptions) of the encryption for a given encryption key k: V = N K .

[0182] Attackers should not be able to easily guess the valid feedback string. On the other hand, there is no upper limit to K, but values ​​of K that may be significantly greater than L do not provide much additional security. It is proposed that the variability V should be at least in the millions to achieve good security, thus limiting the effectiveness of brute-force methods for attacking serialization.

[0183] For example, for an alphabetic base of 32, for small values ​​of L such as 6, we can propose K = L or (L-1), and for larger values ​​of L, K is fixed at 6. For an alphabetic base N = 32, K = 4 ensures the variability of encryption V = 1 million, and K = 6 achieves V = 1 billion.

[0184] This invention primarily targets human-readable serialization, where users potentially manually type and query codes. However, the techniques described in this document are not limited to human-readable encoding and can also address machine-readable encoding. Encoding may include:

[0185] - Human-readable encoding, using the Latin alphabet, Cyrillic alphabet, Asian alphabet or any other alphabet;

[0186] - Human-readable encoding, but optimized for machine reading using special strategies and fonts (such as (but not limited to) OCRA for optical character recognition);

[0187] - Machine-readable code that can be linearly printed, such as (but not limited to):

[0188] A very small sequence of 1D / 2D barcodes;

[0189] Smart mail barcodes (IM) or similar for postal applications;

[0190] A proprietary code consisting of small graphic elements, each representing an alphabetic symbol and printed linearly.

[0191] Figure 10 An example of a proprietary barcode / symbol system is shown, consisting of linearly printed miniature 1D / 2D patterns, each pattern representing a symbol of the alphabet.

[0192] Tags can be implemented in the following forms:

[0193] - Direct encoding using continuous inkjet, laser engraving, or any other technology that allows direct encoding;

[0194] - The tape is pre-encoded and can be later cut and pasted onto the article without guaranteeing registration.

[0195] The serialization method according to the present invention can be applied to every situation where registration is difficult due to various reasons (such as high speed of moving objects, lack of complex registration mechanisms, or mechanical impossibility of registration). Figure 11 As shown above, the security thread 9 incorporated into a banknote is a good example of how this serialization can be used. The serialization method disclosed in this invention will reliably mark this thread 10, regardless of any misalignment, as... Figure 12 As shown, and even for machine reading. This method allows for a reduction (to zero) in the probability of decryption errors, enabling proper authentication / identification. This method is suitable for any encoding or token that can be linearly arranged as a continuous string.

[0196] The subject matter disclosed above is to be considered illustrative rather than restrictive and is intended to provide a better understanding of the invention as defined by the independent claims.

Claims

1. A method for serialization of articles, comprising: encrypting a unique serial number of each article using an encryption key k to obtain a corresponding unique code, and marking the article with the corresponding unique code of each article, characterized in that each unique code has a length L and is included in a symbol string having a length L' marked on the corresponding article, wherein L' is greater than L, and wherein the symbol string further comprises at least a portion of a unique code obtained by encrypting a previous unique serial number and / or at least a portion of a unique code obtained by encrypting a next unique serial number, wherein the unique code corresponding to the article in the symbol string is concatenated with an end of the unique code obtained by encrypting the previous unique serial number before and / or with a beginning of the unique code obtained by encrypting the next unique serial number after.

2. The method of claim 1, wherein, The symbols in the symbol string comprise graphical symbols selected from human-readable characters and machine-readable symbols.

3. The method of claim 2, wherein, The symbols in the symbol string are selected from a set of glyphs.

4. The method according to claim 2, wherein the symbols in the symbol string are selected from alphabetic symbols, alphanumeric symbols or numeric symbols.

5. The method of claim 1, wherein, The unique codes are present in the symbol string with an offset, wherein L' is greater than or equal to (2L-1).

6. The method of claim 1, wherein, The unique codes are present in the symbol string with an offset, wherein L' is less than (2L-1).

7. The method of claim 5, wherein, The offset of the unique codes in the symbol string is noted by applying different alphabets to different positions of the symbols in the unique codes, or by applying a marker between consecutive unique codes, wherein the marker is selected from a gap, a special mark and a box.

8. The method of claim 1, wherein, Marking the symbol string on the article comprises direct marking or printing, applying a pre-printed label or laser engraving.

9. The method of claim 1, wherein, The encryption of the serial number of the article to obtain the unique code is performed by applying block encryption or block encryption combined with format preserving encryption, FPE.

10. The method of claim 2, wherein, The encryption of the serial number of the article to obtain the unique code is performed by stream encryption based on self-synchronizing feedback, wherein the symbols of the serial number are encrypted one by one in a stream cipher structure with format preserving encryption, FPE.

11. The method of claim 10, wherein, The minimum length L' of the symbol string marked on the article is equal to (L+K), K being a feedback length comprising a number of characters or at least one symbol outside the length L of the unique code.

12. A decryption method for recovering unique codes and corresponding serial numbers from a symbol string marked on an article according to the serialization method of any of the preceding claims, the decryption method comprising: reading a symbol string having a length L' marked on the article; decrypting, based on a decryption key k', the blocks of symbols having a length L having an offset from 0 to L-1 within the symbol string having a length L' read on the article, wherein L' is greater than L; for each serial number candidate n corresponding to a block having a length L, computing a previous serial number n-1 and a next serial number n+1; encrypting the serial number n-1 and the serial number n+1 with the encryption key k, respectively, to obtain a previous serial number candidate and a next serial number candidate, respectively; in case of a symbol string of length L' to the left of the offset position of the current attempt, comparing the symbols of the preceding sequence number candidate with the corresponding symbols of the symbol string symbol by symbol, and in case of a symbol string of length L' to the right of the offset + L of the current attempt, comparing the symbols of the next sequence number candidate with the corresponding symbols of the symbol string symbol by symbol, wherein in case of all compared symbols matching, the correct unique code and the corresponding correct sequence number n is recovered from the read symbol string; and in case of at least one symbol comparison failing for the offset, no sequence number corresponds to the offset.

13. A system for serialization of items, comprising: a memory and a processor, the memory being configured together with the processor to cause the system to encrypt sequence numbers of individual items using an encryption key k stored in the memory to obtain corresponding unique codes, and a marking device connected to the processor and adapted to mark unique codes received from the processor on items, characterized in that the system is configured to include individual unique codes of length L into symbol strings of length L', wherein L' is larger than L, and wherein the symbol strings further include at least a portion of a unique code obtained by encrypting a preceding unique sequence number and / or at least a portion of a unique code obtained by encrypting a following unique sequence number, and the system is configured to mark the symbol strings on corresponding items, wherein the unique code corresponding to the item is concatenated in the symbol string with an end of the unique code obtained by encrypting the preceding unique sequence number before and / or with a beginning of the unique code obtained by encrypting the following unique sequence number after.

14. The system of claim 13, wherein, the memory and the processor are configured to cause the system to apply block encryption or stream encryption based on self-synchronous feedback combined with format preserving encryption, FPE.

15. The system of claim 13, wherein, the memory and the processor are configured to cause the system to apply format preserving encryption, FPE, wherein the cryptograms of the sequence numbers are encrypted one by one in a stream cipher structure.

16. A system for recovering a unique code and a corresponding serial number from a string of symbols marked on an item by a system for serialization of items according to any one of claims 13 to 15, the system comprising a processing unit equipped with a memory unit and a reader, wherein, the reader is adapted to read symbol strings marked on items and to store the read symbol strings in the memory unit, and the processing unit is configured to cause the system to: decrypt symbol blocks of length L within the symbol string of length L' stored in the memory unit with offsets from 0 to L-1 based on a decryption key k' stored in the memory unit, wherein L' is larger than L; compute a preceding sequence number n-1 and a following sequence number n+1 for each sequence number candidate n corresponding to a block of length L; encrypt the sequence number n-1 and the sequence number n+1 with the encryption key k, respectively, and obtain a preceding sequence number candidate and a following sequence number candidate, respectively; in case of a symbol string of length L' to the left of the offset position of the current attempt, the symbols of the previous sequence number candidate are compared symbol by symbol with the corresponding symbols of this symbol string, and in case of a symbol string of length L' to the right of the offset + L start of the current attempt, the symbols of the next sequence number candidate are compared symbol by symbol with the corresponding symbols of this symbol string, wherein in case of a match of all compared symbols, the system is adapted to transmit a signal indicating that the correct unique code and the corresponding correct sequence number n have been recovered from the read symbol string; and in case of a failure of the at least one symbol comparison for the offset, no sequence number corresponds to the offset.

Citation Information

Patent Citations

  • Authentication system for use with pharmaceuticals

    WO2018204319A1

  • Method of coded marking of a small-size product, and marked product obtained according to said method

    CN101351812A

  • Electronic tag and system and method for securing electronic tag

    US20200082396A1