RFID data encryption and decryption system based on soft shield mode
Through the RFID data encryption and decryption system based on the soft shield method, the dual encryption mechanism of network layer and application layer is adopted to solve the security problem in RFID data transmission, realize the secure transmission and integrity protection of data, avoid information leakage, and do not affect the performance of the reader.
Patent Information
- Application Number
- CN202211643107.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-20
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2042-12-20
AI Technical Summary
The existing RFID radio frequency technology does not encrypt data packets in wireless communications, making them vulnerable to eavesdropping, interception, tampering and forgery, leading to information leakage and insufficient security.
The RFID data encryption and decryption system based on the soft shield method is adopted, including the reader, soft shield module, IoT gateway, trusted platform and business system. It adopts a dual encryption mechanism of network layer and application layer. The soft shield module provides key management, identity authentication and secure channel establishment. Combined with the trusted platform to issue certificates and the cipher machine to generate keys, data encryption and decryption protection is achieved.
The security of RFID data transmission is achieved, ensuring the integrity and privacy of data during transmission, avoiding information leakage, and no hardware modification is required. It is only implemented through software, maintaining the recognition distance and recognition rate of the reader.
Smart Images

Figure CN116011475B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of RFID data security transmission, in particular to an RFID data encryption and decryption system based on a soft shield mode. BACKGROUND
[0002] RFID radio frequency technology has the remarkable features of passive, non-contact, fast real-time reading, and is widely used in data acquisition, warehousing, logistics fields. Using wireless signals for non-contact two-way information transmission, while being convenient and flexible, it increases the risk of information being stolen. Generally, the data packets transmitted by wireless communication are not encrypted and processed, and it is easy to occur problems such as eavesdropping, interception, tampering, forgery, and sender denial. In the process of data packet transmission, information is easily leaked, causing incalculable losses. How to use an RFID data encryption means to improve the security of RFID radio frequency tag wireless data communication has become an important direction of current research. SUMMARY
[0003] The present application relates to the field of RFID data security transmission, in particular to an RFID data encryption and decryption system based on a soft shield mode.
[0004] To achieve the above object, the application adopts the following technical scheme:
[0005] An RFID data encryption and decryption system based on a soft shield mode, comprising a reader, a soft shield module, an Internet of Things gateway, a trusted platform, and a business system.
[0006] The reader is a terminal device for obtaining data from a radio frequency tag and writing data to the radio frequency tag.
[0007] The soft shield module is a password service software module developed for the operating system of the reader device, and is deployed on a soft shield MCU inside the reader, providing key management, identity authentication, secure channel establishment, and password service functions for the device.
[0008] The Internet of Things gateway is used for unified access to the front-end reader and obtaining the state information of the device.
[0009] The RFID data encryption and decryption system adopts a network layer and application layer double encryption mechanism, specifically:
[0010] The reader device installed with the soft shield module first completes network layer identity authentication with the Internet of Things gateway based on an IPSec VPN mechanism, and establishes a secure communication tunnel, so as to realize network layer access control and data transmission protection of the reader device; meanwhile, the reader calls a trusted platform and a business system to perform application layer identity authentication, the soft shield module provides a digital signature and a symmetric encryption and decryption algorithm interface for application calling, and the application layer program can call the cryptographic algorithm interface provided by the soft shield module to encrypt and protect the key data field.
[0011] As a further technical solution of the application, the reader is composed of a radio frequency module, an antenna module, a radio frequency MCU, a soft shield MCU, a serial communication module, a network communication module and a power module; the radio frequency MCU is used to control the radio frequency module to complete reading and writing of the radio frequency tag, to communicate through a network port and a serial port and to control other peripheral devices; the soft shield MCU is used to integrate a soft shield module program, to run a protocol stack and to realize data encryption processing.
[0012] As a further technical solution of the application, the Internet of Things gateway is deployed on a system network boundary, only allows data communication between a reader terminal device authenticated based on a digital certificate and a business system, and adopts a national commercial cryptographic algorithm to establish a secure communication tunnel with the terminal device based on an IPSec VPN mechanism.
[0013] As a further technical solution of the application, the trusted platform comprises a trusted computing module, a CA server and a cryptographic machine.
[0014] The trusted computing module can issue data certificates for the reader terminal device, the Internet of Things gateway device and the business system in the system by calling the cryptographic machine and the CA server, and can provide a matching certificate and key management capability; through service interface customization development, the trusted computing module can provide function service calling interfaces such as identity authentication, data encryption and decryption and data integrity check based on cryptographic technology for each business system.
[0015] The CA server is used to issue data certificates for the reader device, the Internet of Things gateway and the business system.
[0016] The cryptographic machine is used to generate a private key and a public key according to an encryption algorithm.
[0017] As a further technical solution of the application, the business system is used to gather and collect decrypted data, and provide device management, target identity recognition, target track tracking and target basic information management functions for users; the target includes any article, equipment and personnel equipped with a radio frequency tag.
[0018] As a further technical solution of the application, the specific working process of the RFID data encryption and decryption system comprises the following steps:
[0019] Step 1: when used for the first time, the soft shield module in the recognizer uses the built-in certificate to negotiate with the Internet of Things gateway to establish a secure communication tunnel;
[0020] Step 2: after the tunnel is established, the soft shield module registers with the trusted platform, and the information includes: the recognizer terminal fingerprint, the terminal IP, the soft shield version and the soft shield serial number;
[0021] Step 3: after registration is completed, the soft shield module initiates a certificate application to the trusted platform;
[0022] Step 4: after the certificate application is passed, the trusted platform issues a certificate and transmits it to the soft shield module;
[0023] Step 5: after the soft shield module receives the certificate, it restarts the soft shield and saves the certificate;
[0024] Step 6: the soft shield module uses the updated certificate to negotiate with the Internet of Things gateway to establish a secure communication tunnel;
[0025] Step 7: after the tunnel is established, the soft shield module authenticates with the trusted platform, and after the authentication is passed, the tunnel is allowed to be used for business; otherwise, the tunnel is prohibited for business use, and periodic authentication is performed until the authentication is successful;
[0026] Step 8: after the recognizer obtains the tag data, the radio frequency MCU transmits the data to the soft shield MCU through the serial port, and the integrated soft shield module realizes RFID data encryption by using a commercial secret algorithm;
[0027] Step 9: the soft shield module transmits the ciphertext data through the network port communication module, and the Internet of Things gateway receives the ciphertext data and decrypts it using the key generated by the trusted platform;
[0028] Step 10: the plaintext after decryption is transmitted to the business system for data analysis, processing and display.
[0029] The beneficial effects of the present application are:
[0030] 1. The present application is based on soft shield mode RFID data encryption and decryption. After the soft shield program is developed and written to the recognizer, no encryption hardware needs to be added to the recognizer device, and the encryption is realized conveniently and quickly through a software method;
[0031] 2. The present application increases a soft shield MCU on the hardware composition of the recognizer to ensure that the data encryption runs independently and does not occupy the original radio frequency MCU space and performance, so that the data security protection is realized under the condition that the recognition distance and recognition rate of the recognizer itself are not reduced;
[0032] 3. The present application adopts a network layer and application layer double encryption mechanism, and through the cooperation of front-end and back-end data encryption, the safety in the whole data transmission and use process is ensured. BRIEF DESCRIPTION OF DRAWINGS
[0033] Figure 1 The schematic diagram of the hardware composition of the reader of the present application;
[0034] Figure 2 The flow chart of the channel encryption realized by the soft shield module of the present application;
[0035] Figure 3 The block diagram of the software composition of the soft shield module of the present application;
[0036] Figure 4 The flow chart of the establishment of the secure communication tunnel of the present application;
[0037] Figure 5 The schematic diagram of the message encapsulation format of the present application;
[0038] Figure 6 The hardware composition diagram of the Internet of Things gateway of the present application;
[0039] Figure 7 The architecture diagram of the trusted computing module of the present application. DETAILED DESCRIPTION
[0040] In order to further illustrate the technical means and effects taken by the present application to achieve the predetermined purposes, the specific embodiments, structures, features and effects of the present application are described in detail below in combination with the drawings and preferred embodiments.
[0041] REFERENCE Figures 1-7 In order to improve the security deficiency of the prior art, the present application provides an RFID data encryption and decryption system based on a soft shield mode, which adopts a network layer and application layer double encryption mechanism to ensure the security of RFID data transmission and application in the entire system.
[0042] The RFID data encryption and decryption system based on a soft shield mode provided by the present application comprises a reader, a soft shield module, an Internet of Things gateway, a trusted platform and a business system.
[0043] The reader is a terminal device for obtaining data from a radio frequency tag and writing data to the radio frequency tag;
[0044] The soft shield module is a password service software module developed for the operating system of the reader device, which is deployed on a soft shield MCU inside the reader and provides functions such as key management, identity authentication, secure channel establishment and password service for the device;
[0045] The Internet of Things gateway is used for unified access to the front-end reader and obtaining the state information of the device.
[0046] The trusted platform includes a trusted computing module, a CA server and a cryptomachine; the trusted computing module can issue data certificates for the reader terminal device, the Internet of Things gateway device and the business system in the system by calling the cryptomachine, the CA system and other cryptographic infrastructures, and can provide matching certificate and key management capabilities; the CA server is used for issuing data certificates for the reader device, the Internet of Things gateway and the business system; and the cryptomachine is used for generating private keys and public keys according to encryption algorithms;
[0047] The business system is used for receiving data sent by the reader and displaying business-level function applications.
[0048] The working process of the RFID data encryption and decryption system includes
[0049] Step 1: When used for the first time, the soft shield module in the reader uses the built-in certificate to negotiate with the Internet of Things gateway to establish a secure communication tunnel;
[0050] Step 2: After the tunnel is established, the soft shield module registers with the trusted platform, and the information includes the reader terminal fingerprint, the terminal IP, the soft shield version, the soft shield serial number and the like;
[0051] Step 3: After the registration is completed, the soft shield module initiates a certificate application to the trusted platform;
[0052] Step 4: After the certificate application is passed, the trusted platform issues a certificate and transmits it to the soft shield module;
[0053] Step 5: After the soft shield module receives the certificate, it restarts the soft shield and saves the certificate;
[0054] Step 6: The soft shield module uses the updated certificate to negotiate with the Internet of Things gateway to establish a secure communication tunnel;
[0055] Step 7: After the tunnel is established, the soft shield module authenticates with the trusted platform, and after the authentication is passed, the business is allowed to use the tunnel; otherwise, the business is prohibited from using the tunnel, and the periodic authentication is performed until the authentication is successful;
[0056] Step 8: After the reader obtains the tag data, the radio frequency MCU transmits the data to the soft shield MCU through the serial port, and the integrated soft shield module realizes RFID data encryption by using the commercial secret algorithm;
[0057] Step 9: The soft shield module transmits the ciphertext data through the network port communication module, and the Internet of Things gateway receives the ciphertext data and decrypts it by using the key generated by the trusted platform;
[0058] Step 10: The plaintext after decryption is transmitted to the business system, and the business system performs data analysis and processing and display.
[0059] The reader is composed of a radio frequency module, an antenna module, a radio frequency MCU, a soft shield MCU, a serial communication module, a network communication module and a power module; wherein the radio frequency MCU is used to control the radio frequency module to complete the reading and writing of the radio frequency tag, to communicate through a network port, a serial port and other peripheral devices and to control; the soft shield MCU is mainly used to integrate the soft shield module program, to run the protocol stack and to realize the data encryption processing.
[0060] The soft shield module can automatically encrypt the network data sent by the reader device in the network layer communication, and realizes the identity authentication with the business system and the encryption and decryption mechanism of the key data field through the module calling the interface of the reader radio frequency module in the application layer, so that the reader can perform the bidirectional identity authentication with the Internet of Things gateway through the soft shield module, establish a secure channel and provide encryption protection for business communication.
[0061] The soft shield module is designed in a layered architecture, including the control layer basic function and the business layer management function. The software composition block diagram of the module is as shown in Figure 3
[0062] The control layer mainly includes three function modules, and the function description is as follows:
[0063] Secure communication tunnel establishment: successfully establishing a secure communication tunnel with the Internet of Things gateway, collecting the hardware CPU usage rate, memory usage rate and other data of the terminal device and sending them to the trusted platform;
[0064] Secure message packaging: responsible for the security encryption and decryption of business data, decrypting the IPSec message of the network ciphertext and sending it to the kernel, and encrypting the response report of the kernel and sending it to the network in the form of IPSec message;
[0065] Password operation: responsible for providing data encryption and decryption, message signature and verification, digital envelope packaging and unpacking and other password operation functions based on commercial password algorithms;
[0066] The business layer mainly includes five function modules, and the function description is as follows:
[0067] Certificate management: generating a P10 certificate request file based on the SM2 algorithm according to the request information; importing the device encryption certificate, device signature certificate, root certificate and decryption private key issued by the certificate authentication system into the device;
[0068] Key management: responsible for the whole life cycle management of the generation, use, backup, recovery and destruction of the internal key of the device;
[0069] Strategy configuration: responsible for the strategy configuration related to the security communication of the access terminal, such as the security communication tunnel, protocol white list and access control;
[0070] Access authentication: responsible for trusted two-way identity authentication with the access terminal based on digital certificate and digital signature;
[0071] State reporting: responsible for reporting terminal authentication information, device running state and other information to the designated monitoring server platform in real time, such as a trusted platform.
[0072] The Internet of Things gateway adopts a domestic hardware platform based on a Loongson 3A3000 processor, ensuring the self-controllability of the hardware platform. The hardware platform is composed of a mainboard, a CPU and a chipset, memory, a network controller, storage, a power supply, a password card, an intelligent password key, key security storage and the like.
[0073] The trusted computing module mainly consists of five layers, including a display layer, a control layer, a business layer, a data layer and a database.
[0074] Display layer: displayed using an html page and accessed using a browser, different managers can realize the browsing and querying operation of system related functions and resources by logging in.
[0075] Control layer: the control layer communicates with the display layer, all requests of the page are forwarded to the business layer through the control layer, and the business layer completes the specific operation to finally complete the rendering of data. The control layer plays a role of connecting the upper and lower layers in the system.
[0076] Business layer: all business functions of the trusted platform are completed through the business layer, including interaction with external systems, and the business layer is a core component of the system. The business layer adopts modular design, and different functions are divided into different business modules. The business layer provides functions including system initialization, password machine management, key management, terminal management, gateway management, soft shield management, business system management, perception type gateway management, system management, monitoring and early warning, user management and password operation. The modules are independent of each other, which minimizes the coupling of the system and enhances the expansibility and maintainability of the system.
[0077] Data layer: operation on databases, caches, configuration files and the like, realizing data addition, deletion, modification and inquiry, and feeding back the operation results to the business layer.
[0078] Database: stores all persistent information of the trusted platform, including user information, key data, terminal information, business system information, physical network access gateway information and system configuration information. The system adopts a Mysql database, and the database has dual hot standby and single point failure automatic switching.
[0079] The above merely describes the preferred embodiments of the present application, and is not intended to limit the present application in any form. Although the present application has been disclosed with the preferred embodiments as above, it is not intended to limit the present application. Any person skilled in the art can make some changes or modifications to the above disclosed technical content to obtain equivalent embodiments with equivalent changes, as long as the changes or modifications do not deviate from the technical solution of the present application. Any modification, change, equivalent change and modification of the above embodiments made according to the technical essence of the present application still belong to the scope of the technical solution of the present application.
Claims
1. An RFID data encryption and decryption system based on a soft shield method, characterized in that: Including readers, soft shield modules, IoT gateways, trusted platforms and business systems; The reader is a terminal device used to obtain data from and write data to radio frequency tags; The soft shield module is a cryptographic service software module customized and developed for the reader device operating system. The module is deployed on the soft shield MCU inside the reader and provides key management, identity authentication, secure channel establishment and cryptographic service functions for the device; The IoT gateway is used to uniformly access the front-end reader and obtain the status information of the device; The RFID data encryption and decryption system adopts a dual encryption mechanism at the network layer and the application layer, specifically: The reader device equipped with the SoftShield module first completes network-layer identity authentication with the IoT gateway based on the IPSec VPN mechanism and establishes a secure communication tunnel to implement network-layer access control and data transmission protection for the reader device. At the same time, the reader calls the trusted platform and business system to perform application-layer identity authentication. The SoftShield module provides digital signatures and symmetric encryption and decryption algorithm interfaces for application calls. Application-layer programs can call the cryptographic algorithm interfaces provided by the SoftShield module to encrypt and protect key data fields. The specific workflow of the RFID data encryption and decryption system includes: Step 1: During initial use, the soft shield module in the fixed reader uses the built-in certificate to negotiate with the IoT gateway to establish a secure communication tunnel. Step 2: After the tunnel is established, the soft shield module registers with the trusted platform. The information includes: reader terminal fingerprint, terminal IP, soft shield version and soft shield serial number; Step 3: After registration is completed, the SoftShield module initiates a certificate request to the trusted platform; Step 4: After the certificate application is approved, the trusted platform issues the certificate and transmits it to the soft shield module; Step 5: After the soft shield module receives the certificate, it restarts the soft shield and saves the certificate; Step 6: The SoftShield module uses the updated certificate to negotiate with the IoT gateway to establish a secure communication tunnel; Step 7: After the tunnel is established, the soft shield module authenticates the trusted platform. If the authentication is successful, the service is allowed to use the tunnel; otherwise, the service is prohibited from using the tunnel and periodic authentication is performed until the authentication is successful. Step 8: After the reader obtains the tag data, the RF MCU transmits the data to the soft shield MCU through the serial port. The integrated soft shield module uses the national commercial encryption algorithm to implement RFID data encryption; Step 9: The soft shield module transmits the encrypted data through the network port communication module. After receiving the encrypted data, the IoT gateway decrypts it using the key generated by the trusted platform. Step 10: The decrypted plaintext is transmitted to the business system, which performs data analysis, processing and display.
2. The RFID data encryption and decryption system based on the soft shield method according to claim 1 is characterized in that: The reader consists of a radio frequency module, an antenna module, a radio frequency MCU, a soft shield MCU, a serial port communication module, a network port communication module and a power module; the radio frequency MCU is used to control the radio frequency module to complete the reading and writing of radio frequency tags, communicate through the network port and serial port, and control other peripheral devices; the soft shield MCU is used to integrate the soft shield module program, run the protocol stack, and realize data encryption processing.
3. The RFID data encryption and decryption system based on the soft shield method according to claim 1 is characterized in that: The IoT gateway is deployed on the system network boundary and only allows data communication between the reader terminal device and the business system after identity authentication based on digital certificates. It adopts the national commercial encryption algorithm and can establish a secure communication tunnel with the terminal device based on the IPSec VPN mechanism.
4. The RFID data encryption and decryption system based on the soft shield method according to claim 1 is characterized in that: The trusted platform includes a trusted computing module, a CA server, and a cryptographic machine; The trusted computing module can issue data certificates for reader terminals, IoT gateway devices, and business systems in the system by calling cryptographic machines and CA servers, and provide supporting certificate and key management capabilities. Through customized development of service interfaces, we can provide functional service call interfaces for identity authentication, data encryption and decryption, and data integrity verification based on cryptographic technology for each business system; The CA server is used to issue data certificates for reader devices, IoT gateways, and business systems; The cipher machine is used to generate a private key and a public key according to an encryption algorithm.
5. The RFID data encryption and decryption system based on the soft shield method according to claim 1 is characterized in that: The business system is used to aggregate and collect decrypted data and provide users with equipment management, target identity recognition, target trajectory tracking, and target basic information management functions; the targets include any items, equipment, and personnel equipped with radio frequency tags.
Citation Information
Patent Citations
Structure of electronic book reader system with encryption function
CN102456276A
Encryption and decryption method and system based on software and hardware collaboration
CN113722726A