Label authentication method and device, electronic equipment and storage medium
By using the secure tag authentication identifier and secure inventory waveform generated by the tag management network element in the passive IoT system, and combining the superposition and recovery method of inventory information and tag information, the problem of low security of tag authentication and authorization in the passive IoT system is solved, and the secure transmission and authentication of tag information is realized.
Patent Information
- Application Number
- CN202410005782.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-02
- Publication Date
- 2026-01-20
- Estimated Expiration
- 2044-01-02
AI Technical Summary
Passive IoT systems suffer from low authentication and authorization security for tags, and static keys and static authentication identifiers cannot effectively guarantee data security.
By generating inventory information, using the security tag authentication identifiers periodically generated by the tag management network element, and combining the security inventory waveform and inventory instructions, inventory information is generated. After the tag authentication is passed, the identifier information is superimposed on a specific part of the inventory information, and the identifier information is restored for authentication, ensuring that only legitimate devices can parse the tag information.
This improves the authentication and authorization security of tags in passive IoT systems, prevents unauthorized devices from obtaining tag information, and ensures the security of tag information reception and transmission.
Smart Images

Figure CN118827115B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of passive Internet of Things, and in particular to a label authentication and authorization method and device, an electronic device, and a storage medium. BACKGROUND
[0002] In a conventional passive Internet of Things system, a blank carrier, i.e., a periodic sinusoidal wave, is used to excite a passive label. In this system, label data can be obtained by an illegal reader, and even if a legal reading and writing device completes label excitation, the label information can be received and parsed by all nearby reading and writing devices, which does not guarantee security. In the existing authentication and authorization method of the passive Internet of Things system, a static key and a static authentication identifier are used to check the identity of a reading and writing device, and the label data is encrypted, but the security is improved to a limited extent. Therefore, the existing technical problem is that the authentication and authorization security of the label in the passive Internet of Things system is low. SUMMARY
[0003] The label authentication and authorization method and device, the electronic device, and the storage medium provided by the embodiments of the present application can improve the authentication and authorization security of the label in the passive Internet of Things system.
[0004] The technical solution of the present application is implemented as follows:
[0005] The label authentication and authorization method provided by the embodiments of the present application comprises the following steps.
[0006] Form inventory information based on the obtained authentication identifier for the label;
[0007] Send the inventory information to the label and receive inventory feedback information sent by the label; wherein the inventory feedback information is formed by superimposing the identifier information corresponding to the label in a specific part of the inventory information based on the fact that the label passes the authentication of the first inventory node based on the inventory information.
[0008] Restore the identifier information based on the inventory information to the inventory feedback information, and send the identifier information to a label management network element for authentication.
[0009] In the above solution, the inventory information is formed based on the obtained authentication identifier for the label, comprising:
[0010] Receive the authentication identifier sent by the first network node; wherein the authentication identifier is a secure label authentication identifier for the label formed by the label management network element based on a preset rule periodically;
[0011] Form secure inventory waveform information based on the authentication identifier;
[0012] The inventory information is composed based on the authentication identifier, the inventory instruction and the secure inventory waveform information.
[0013] In the scheme, the identification information includes a tag identifier and an updated tag identifier; and the identification information is obtained by recovering the inventory feedback information based on the inventory information, including:
[0014] The cancel carrier for the inventory feedback information is generated based on the secure inventory waveform information;
[0015] The tag identifier of the tag and the updated tag identifier are recovered from the inventory feedback information based on the cancel carrier; and the updated tag identifier is formed based on the preset rule for the tag identifier in a period when the tag is synchronized with the tag management network element.
[0016] In the scheme, before the inventory information is formed based on the obtained authentication identifier for the tag, the method further includes:
[0017] The second network node receives an inventory instruction; and the inventory instruction includes inventory user identity information.
[0018] The second network node sends the inventory instruction to the tag management network element.
[0019] The tag management network element determines an inventory strategy based on the inventory user identity information, and sends the inventory strategy and a secure tag authentication identifier for the tag to the first network node.
[0020] In the scheme, after the tag management network element determines an inventory strategy based on the inventory user identity information, and sends the inventory strategy and a secure tag authentication identifier for the tag to the first network node, the method further includes:
[0021] If the inventory strategy represents a non-multi-station joint receiving strategy, the first network node determines the first inventory node based on the inventory strategy, and sends the authentication identifier to the first inventory node.
[0022] In the scheme, after the tag management network element determines an inventory strategy based on the inventory user identity information, and sends the inventory strategy and a secure tag authentication identifier for the tag to the first network node, the method further includes:
[0023] If the inventory strategy represents a multi-station joint receiving strategy, the first network node determines the first inventory node based on the inventory strategy, and sends the authentication identifier and second inventory node information to the first inventory node.
[0024] send the authentication identifier to the corresponding second inventory node based on the second inventory node information.
[0025] In the above solution, after the tag management network element determines the inventory strategy based on the inventory user identity information and sends the inventory strategy and the security tag authentication identifier for the tag to the first network node, the method further comprises:
[0026] If the inventory strategy represents a multi-site joint reception strategy, the first network node determines the first inventory node and the second inventory node based on the inventory strategy, and sends the authentication identifier to the first inventory node and the second inventory node.
[0027] In the above solution, the method further comprises:
[0028] The second inventory node forms auxiliary station security inventory waveform information based on the authentication identifier;
[0029] The second inventory node receives the inventory feedback information, and generates auxiliary station cancellation carrier for the inventory feedback information based on the auxiliary station security inventory waveform;
[0030] The second inventory node recovers the inventory feedback information based on the auxiliary station cancellation carrier to obtain the tag identifier of the tag, and updates the tag identifier.
[0031] In the above solution, the method further comprises:
[0032] The tag management network element inversely solves the updated tag identifier based on a preset rule to obtain a pre-update tag identifier;
[0033] The tag management network element compares the pre-update tag identifier with the stored tag identifier, and determines an authentication and authorization result based on the comparison result.
[0034] Embodiments of the present application also provide a tag authentication and authorization method, applied to a tag, comprising:
[0035] Receiving inventory information sent by a first inventory node, and authenticating the first inventory node based on the inventory information to obtain an authentication result;
[0036] If the authentication result represents that the first inventory node is authenticated, superimposing identifier information in a specific part of the inventory information to form inventory feedback information;
[0037] Sending the inventory feedback information to the first inventory node; the first inventory node recovers the identifier information based on the inventory information to obtain the identifier information, and sends the identifier information to a tag management network element for authentication.
[0038] In the above solution, the receiving the inventory information sent by the first inventory node and the obtaining the authentication result based on the inventory information and the authentication of the first inventory node comprise:
[0039] receiving the inventory information sent by the first inventory node; wherein the inventory information comprises an authentication identifier, an inventory instruction and secure inventory waveform information;
[0040] matching the demapping result of the authentication identifier with a tag identifier to determine the authentication result; wherein the tag identifier is periodically formed based on a preset rule.
[0041] In the above solution, the superimposing the identification information in the specific part of the inventory information to form the inventory feedback information comprises:
[0042] forming an updated tag identifier based on a preset rule;
[0043] superimposing the tag identifier and the updated tag identifier in the secure inventory waveform, and forming the inventory feedback information by using the superimposed secure inventory waveform.
[0044] In the above solution, if the authentication result indicates that the first inventory node is authenticated, after the superimposing the identification information in the specific part of the inventory information to form the inventory feedback information, the method further comprises:
[0045] sending the inventory feedback information to a second inventory node; the second inventory node recovers the identification information based on the inventory information and the identification information is sent to a tag management network element for authentication.
[0046] The embodiment of the present application further provides a tag authentication and authorization device, which is applied to a first inventory node and comprises:
[0047] an information forming unit configured to form inventory information based on an obtained authentication identifier for a tag;
[0048] a transceiving unit configured to send the inventory information to the tag and receive inventory feedback information sent by the tag; wherein the inventory feedback information is formed by superimposing identification information corresponding to the tag in a specific part of the inventory information based on the authentication of the first inventory node passing by the tag based on the inventory information.
[0049] a recovery unit configured to recover the identification information based on the inventory feedback information and send the identification information to a tag management network element for authentication.
[0050] The embodiment of the present application further provides a label authentication and authorization device, which is applied to a label and comprises the following parts:
[0051] a receiving authentication unit, configured to receive inventory information sent by a first inventory node and perform authentication on the first inventory node based on the inventory information to obtain an authentication result;
[0052] an information superimposing unit, configured to superimpose identification information in a specific part of the inventory information to form inventory feedback information if the authentication result indicates that the first inventory node passes the authentication;
[0053] a sending unit, configured to send the inventory feedback information to the first inventory node; the first inventory node recovers the identification information from the inventory feedback information based on the inventory information and sends the identification information to a label management network element for authentication.
[0054] The embodiment of the present application further provides an electronic device, which comprises a memory and a processor, the memory stores a computer program capable of running on the processor, and the processor executes the steps in the first inventory node side method.
[0055] The embodiment of the present application further provides an electronic device, which comprises a memory and a processor, the memory stores a computer program capable of running on the processor, and the processor executes the steps in the label side method.
[0056] The embodiment of the present application further provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the steps in the first inventory node side method.
[0057] The embodiment of the present application further provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the steps in the label side method.
[0058] In the embodiment of the present application, based on the acquired authentication identifier for the tag, inventory information is formed; the inventory information is sent to the tag, and inventory feedback information sent by the tag is received; wherein the inventory feedback information is formed by the tag based on the inventory information, after the first inventory node is authenticated, in a specific part of the inventory information, superimposing the identifier information corresponding to the tag; based on the inventory information, the identifier information is recovered from the inventory feedback information, and the identifier information is sent to the tag management network element for authentication. In this way, only after the tag authenticates the first inventory node based on the inventory information, the first inventory node will send the inventory feedback information, since it is difficult for the attacker to obtain the current time authentication identifier, the instructions sent by the attacker will not be authenticated, and then the tag will not respond to the instructions from the attacker, ensuring the safety of the received information of the tag. And since the inventory feedback information is formed by superimposing the identifier information in the specific part of the inventory information, only the corresponding inventory information can be used to recover the identifier information from the inventory feedback information, and other devices without inventory information cannot recover the inventory feedback information, and cannot obtain the information sent by the tag, ensuring the safety of the sent information of the tag, and further improving the authentication and authorization security of the tag in the passive Internet of Things system. BRIEF DESCRIPTION OF DRAWINGS
[0059] Figure 1 An optional flowchart of a tag authentication and authorization method provided by the embodiment of the present application is provided.
[0060] Figure 2 An optional flowchart of a tag authentication and authorization method provided by the embodiment of the present application is provided.
[0061] Figure 3 An optional effect diagram of a tag authentication and authorization method provided by the embodiment of the present application is provided.
[0062] Figure 4 An optional flowchart of a tag authentication and authorization method provided by the embodiment of the present application is provided.
[0063] Figure 5 An optional flowchart of a tag authentication and authorization method provided by the embodiment of the present application is provided.
[0064] Figure 6 An optional flowchart of a tag authentication and authorization method provided by the embodiment of the present application is provided.
[0065] Figure 7 An optional flowchart of a tag authentication and authorization method provided by the embodiment of the present application is provided.
[0066] Figure 8 An optional flowchart of a tag authentication and authorization method provided by the embodiment of the present application is provided.
[0067] Figure 9 An optional flowchart of the tag authentication and authorization method provided by the embodiment of the present application is shown in FIG. 1;
[0068] Figure 10 An optional flowchart of the tag authentication and authorization method provided by the embodiment of the present application is shown in FIG. 1;
[0069] Figure 11 An optional flowchart of the tag authentication and authorization method provided by the embodiment of the present application is shown in FIG. 1;
[0070] Figure 12 An optional flowchart of the tag authentication and authorization method provided by the embodiment of the present application is shown in FIG. 1;
[0071] Figure 13 An optional flowchart of the tag authentication and authorization method provided by the embodiment of the present application is shown in FIG. 1;
[0072] Figure 14 An optional flowchart of the tag authentication and authorization method provided by the embodiment of the present application is shown in FIG. 1;
[0073] Figure 15 An optional flowchart of the tag authentication and authorization method provided by the embodiment of the present application is shown in FIG. 1;
[0074] Figure 16 An optional flowchart of the tag authentication and authorization method provided by the embodiment of the present application is shown in FIG. 1;
[0075] Figure 17 An optional flowchart of the tag authentication and authorization method provided by the embodiment of the present application is shown in FIG. 1; Figure 1 ;
[0076] Figure 18 An optional flowchart of the tag authentication and authorization method provided by the embodiment of the present application is shown in FIG. 1; Figure 1 ;
[0077] Figure 19 An optional flowchart of the tag authentication and authorization method provided by the embodiment of the present application is shown in FIG. 1; Figure 2 ;
[0078] Figure 20 An optional flowchart of the tag authentication and authorization method provided by the embodiment of the present application is shown in FIG. 1; Figure 2 . DETAILED DESCRIPTION
[0079] In order to make the purpose, technical solutions and advantages of the present application clearer, the technical solutions of the present application are further described in detail below in combination with the drawings and embodiments, and the described embodiments should not be regarded as limiting the present application, and all other embodiments obtained by those skilled in the art without making creative efforts fall within the scope of protection of the present application.
[0080] In the following description, reference is made to "some embodiments", which describe a subset of all possible embodiments, but it is understood that "some embodiments" can be the same subset or different subsets as each other and can be combined with each other as long as there is no conflict.
[0081] If there is a similar description of "first / second" in the application file, the following description is added: In the following description, the terms "first\second\third" referred to only distinguish similar objects, and do not represent a specific order of the objects. It can be understood that "first\second\third" can be interchanged in a specific order or sequence as long as it is allowed, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein.
[0082] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the present application belongs. The terms used herein are only for the purpose of describing the embodiments of the present application and are not intended to limit the present application.
[0083] The present application provides a label authentication and authorization method, please refer to Figure 1 , an optional flowchart of the label authentication and authorization method provided by the embodiments of the present application will be described with reference to Figure 1 The steps shown will be described.
[0084] S101, based on the acquired authentication identifier for the label, form the inventory information.
[0085] In the embodiments of the present application, the first inventory node acquires the authentication identifier for the label at the current time from the first network node. Based on the authentication identifier, a waveform (security inventory waveform) that is different from a blank periodic sine wave is formed, and the security inventory waveform and the authentication identifier, inventory instruction are combined to obtain the inventory information.
[0086] In the embodiments of the present application, the first inventory node periodically acquires the authentication identifier for the label from the first network node, so the first inventory node will also periodically form the corresponding inventory information, and authenticate and authorize the label based on the inventory information in each period. Among them, the authentication identifier sent by the first network node is a security label authentication identifier formed by the label management network element based on a preset rule for the label periodically. The preset rule can be a preset algorithm or program for generating an identifier string.
[0087] The first inventory node can be a Radio Access Network (RAN) base station. The first network node can be an Access and Mobility Management Function (AMF) node.
[0088] In the embodiments of the present application, for a tag, initial authentication is completed when it first enters the network, and a tag authentication identifier is obtained. In a subsequent inventory / read process, when a user initiates a kind of tag management service (for example, starting a secure inventory), the tag management network element will retrieve the tag authentication identifiers of all the secure tags of the user according to the user identity information, intercept the authentication identifier in the tag authentication identifier through the first network node, and issue the corresponding information and the formulated inventory mode to the corresponding first inventory node. The first inventory node generates an air interface authentication identifier, a secure inventory waveform, and the like according to the authentication identifier issued by the first network node, performs secure inventory on the tag, and sends the "air interface authentication identifier + normal inventory instruction + secure inventory waveform" (inventory information). The secure inventory waveform is a waveform that is different from a blank periodic sine wave and is formed based on the authentication identifier, and only the base station (the first inventory node) has the ability to demodulate the tag information on the secure inventory waveform.
[0089] S102, sending the inventory information to the tag and receiving inventory feedback information sent by the tag; wherein the inventory feedback information is formed by superimposing the identifier information corresponding to the tag in a specific part of the inventory information based on the fact that the tag passes the authentication of the first inventory node based on the inventory information.
[0090] In the embodiments of the present application, the first inventory node sends the inventory information to the tag. The tag receives the inventory information and authenticates the inventory information using the locally formed tag identifier. If the tag passes the authentication of the first inventory node based on the inventory information, the tag superimposes the local identifier information into the secure inventory waveform in the inventory information, forms the inventory feedback information using the superimposed secure inventory waveform, and sends the inventory feedback information to the first inventory node.
[0091] The tag forms the local tag identifier based on the preset rule and the period of the tag management network element.
[0092] In the embodiments of the present application, the tag can superimpose and modulate its own information on the secure inventory waveform after confirming that the identity of the first inventory node is legal and the grouping is correct based on the air interface authentication identifier in the inventory information. The own information can include the tag identifier and the updated tag authentication identifier (the update rule needs to be known by both the tag management network element and the tag).
[0093] S103, recover the identification information based on the inventory information and the inventory feedback information, and send the identification information to a tag management network element for authentication.
[0094] In the embodiment, the first inventory node takes the security inventory waveform in the pre-formed inventory information as prior information, demodulates and recovers the inventory feedback information to obtain the identification information superimposed by the tag in the inventory feedback information. The first inventory node sends the recovered identification information to the tag management network element for authentication. Since the tag management network element forms the security tag authentication identification for the tag based on the preset rule in the cycle of the tag, the tag management network element can inversely solve the identification information based on the preset rule, that is, obtain the security tag authentication identification formed by the tag management network element for the tag in the last cycle. The tag management network element can match the security tag authentication identification obtained by the inverse solution with the security tag authentication identification stored in the last cycle. If the matching is successful, it is determined that the tag authentication and authorization is passed. If the matching is not successful, it is determined that the tag authentication and authorization is not passed.
[0095] In the embodiment, the first inventory node takes the security inventory waveform as prior information, recovers the identification information of the tag and reports it to the tag management network element (different base stations use different security inventory waveforms to stimulate the tag, the security inventory waveform is updated periodically, and only the base station that can legally receive the tag information has the correct security inventory waveform). The tag management network element checks whether the updated tag authentication identification conforms to the update rule, that is, the tag is legal, then updates the stored tag authentication identification, and reports the tag information to the user.
[0096] The tag management network element can be a core network element (Tag Management Function, TMF) for managing the identity of a cellular passive Internet of Things tag.
[0097] In the embodiment of the present application, based on the obtained authentication identifier for the tag, inventory information is formed; the inventory information is sent to the tag, and inventory feedback information sent by the tag is received; wherein the inventory feedback information is formed by superimposing the identifier information corresponding to the tag in a specific part of the inventory information based on the inventory information after the first inventory node is authenticated by the tag; the identifier information is obtained by restoring the inventory feedback information based on the inventory information, and is sent to the tag management network element for authentication. In this way, the inventory feedback information will only be sent to the first inventory node after the tag authenticates the first inventory node based on the inventory information. Since it is difficult for an attacker to obtain the current moment authentication identifier, the instructions sent by the attacker will not be authenticated, and thus the tag will not respond to the instructions from the attacker, ensuring the safety of the received information of the tag. Moreover, since the inventory feedback information is formed by superimposing the identifier information in the specific part of the inventory information, only the corresponding inventory information can be used to restore the identifier information from the inventory feedback information, and other devices without inventory information cannot restore the inventory feedback information, and thus cannot obtain the information sent by the tag, ensuring the safety of the sent information of the tag, and further improving the authentication and authorization security of the tag in the passive Internet of Things system.
[0098] In some embodiments, referring to Figure 2 , Figure 2 An optional flowchart of a tag authentication and authorization method provided by the embodiment of the present application is shown in Figure 1 S101 shown can also be implemented by S1011 to S1013, which will be described in combination with each step.
[0099] S1011, receiving an authentication identifier sent by a first network node; wherein the authentication identifier belongs to a security tag authentication identifier for the tag formed periodically by the tag management network element based on a preset rule.
[0100] In the embodiment of the present application, the first inventory node receives the authentication identifier sent by the AMF node. Wherein the authentication identifier belongs to a security tag authentication identifier for the tag formed periodically by the tag management network element based on a preset rule. Wherein the authentication identifier can be the first N characters in the security tag authentication identifier. N is an integer greater than 1.
[0101] In the embodiment of the present application, after the initial authentication of the tag for network authentication is successful, the network (such as the tag management network element) sends the first security tag authentication identifier to the tag. The security tag authentication identifier of each tag can be unique at this moment, or a group of tags use the same security tag authentication identifier. The first network node extracts the common part of the security tag authentication identifier in a group of tags, generates an authentication identifier, and sends it to the base station which needs to initiate a random access inventory process according to the request of the base station. For example, in combination with Figure 3, if the common part of the tag authentication identifier of a group of tags is "10110" Figure 3 The middle box 1, because the number of tags in the group is large, the common part is further analyzed, combined with the access capability of the base station, and it is identified that four identifier prefixes "1011000", "1011001", "1011010", and "1011011" can be used (the middle box 2) to perform mapping of the authentication identifier. Figure 3
[0102] S1012, forming a secure inventory waveform information based on the authentication identifier.
[0103] In the embodiment of the application, the first inventory node forms a secure inventory waveform information based on the authentication identifier. The secure inventory waveform is a waveform generated by the base station according to the air interface authentication identifier, which is different from the blank periodic sine wave. The waveform itself carries information, and the tag superimposes its own information on the waveform. After the composite signal is received, only when the receiver is prepared with the secure inventory waveform generation method, the tag signal can be recovered jointly. Therefore, the secure inventory waveform can encrypt the information transmitted by the tag.
[0104] S1013, forming the inventory information based on the authentication identifier, the inventory instruction, and the secure inventory waveform information.
[0105] In the embodiment of the application, the first inventory node can form the inventory information based on the authentication identifier, the inventory instruction, and the secure inventory waveform information. The first inventory node can periodically update the secure inventory waveform used for inventory according to the authentication identifier periodically issued by the tag management network element through the first network node, so as to prevent the eavesdropper from learning the waveform.
[0106] For example, in combination with Figure 4 The authentication identifier in the inventory information is used to confirm the legitimacy of the first inventory node and the correct grouping of the tags. The inventory instruction is a broadcast instruction of the first inventory node, which is used to activate the tags.
[0107] The embodiment of the application provides a special waveform-based authentication and authorization method for cellular passive Internet of Things tags. That is, the tag management network element obtains a tag authentication identifier according to user demand, generates an air interface authentication identifier in cooperation with the AMF, and specifies an inventory strategy. The read-write device uses the inventory signaling format of "the air interface authentication identifier of the first inventory node this time + the regular inventory instruction + the generated secure inventory waveform" for a period to perform secure inventory on the tags according to the indication of the core network. The embodiment of the application also provides a periodic update method for the air interface secure inventory waveform. That is, the read-write device obtains the air interface authentication identifier from the core network, generates the secure inventory waveform according to the air interface authentication identifier, uses the secure inventory waveform as the backscattering excitation carrier for communication with the tags, and periodically updates the used secure inventory waveform according to the update frequency of the air interface authentication identifier of the core network.
[0108] In the embodiment of the present application, the authentication identifier sent by the first network node is received; wherein the authentication identifier is a security tag authentication identifier for the tag formed by the tag management network element based on the preset rule periodically, and the inventory information is formed based on the authentication identifier and the inventory instruction to authenticate the tag. Since the authentication identifier is formed periodically, the authentication identifier changes every period of time, and after an attacker intercepts an authentication identifier, the authentication identifier intercepted is often invalid. Therefore, the authentication process of the inventory information obtained by using the periodically formed authentication identifier to authenticate the tag will not reduce the security of the authentication even if it is intercepted by the attacker, thereby improving the security of the tag authentication.
[0109] In some embodiments, referring to Figure 2 , Figure 2 An optional flowchart of a tag authentication and authorization method provided by the embodiment of the present application is shown in Figure 1 The S103 shown can be implemented through S1031 to S1032, which will be described in combination with each step.
[0110] S1031, generating a cancellation carrier wave for the inventory feedback information based on the security inventory waveform information.
[0111] In the embodiment of the present application, the security inventory waveform in the inventory information of the first inventory node generates a cancellation carrier wave for the inventory feedback information. Since the inventory feedback information is formed based on the identification information superimposed on the security inventory waveform, the security inventory waveform and the waveform of the inventory feedback information are associated, and then the first inventory node can form a cancellation carrier wave for recovery for the inventory feedback information.
[0112] S1032, recovering the inventory feedback information based on the cancellation carrier wave to obtain the tag identifier of the tag and the updated tag identifier; wherein the updated tag identifier is formed for the tag identifier based on the preset rule periodically by the tag synchronously with the tag management network element.
[0113] In the embodiment of the present application, the first inventory node can recover the inventory feedback information based on the cancellation carrier wave to obtain the tag identifier superimposed in the security inventory waveform and the updated tag identifier. The updated tag identifier is formed based on the preset rule periodically by the tag synchronously with the tag management network element.
[0114] In the embodiment of the present application, the label authentication and authorization method based on a specific waveform is proposed. The air interface authentication identifier is generated based on the self-authentication identifier obtained when the label initially accesses the network, and the label completes the authentication to the network. The label information is encrypted and transmitted based on the specific carrier to stimulate the label. The network verifies the updated authentication identifier of the label, and completes the authentication of the label to the network.
[0115] In the embodiment of the present application, the cancellation carrier for the inventory feedback information is generated based on the security inventory waveform information, the label identifier of the label is obtained based on the cancellation carrier, and the updated label identifier is obtained. The updated label identifier is formed based on the preset rule by the label synchronously in the label management network element. In this way, only the node with the corresponding security inventory waveform information can recover the inventory feedback information in the authentication process of the inventory feedback information. Even if other eavesdroppers intercept the inventory feedback information, they cannot recover it, thereby ensuring the security of the label authentication.
[0116] In some embodiments, referring to Figure 5 , Figure 5 An optional flowchart of the label authentication and authorization method provided in the embodiment of the present application is shown. Figure 1 Before S101 shown, S201 to S203 can be included, which will be described in combination with each step.
[0117] S201, the second network node receives an inventory instruction; wherein the inventory instruction includes inventory user identity information.
[0118] In the embodiment of the present application, the second network node receives the inventory instruction sent by the user. The inventory instruction includes user identity information. The user can be an application layer function (Application Function, AF) network element. The second network node can be a network exposure function (Network Exposure Function, NEF) network element. The inventory user identity information can be the website or identification information of the AF network element.
[0119] S202, the second network node sends the inventory instruction to the label management network element.
[0120] In the embodiment of the present application, the second network node sends the inventory instruction to the label management network element.
[0121] S203, the label management network element determines the inventory strategy based on the inventory user identity information, and sends the inventory strategy and the security label authentication identifier for the label to the first network node.
[0122] In this embodiment, the tag management network element determines the storage policy corresponding to the user based on the user's identity information, and sends the storage policy and the security tag authentication identifier formed by the tag management network element for the user's tag to the first network node.
[0123] In this embodiment, the inventory management strategy includes: multi-site joint reception and non-multi-site joint reception. Multi-site joint reception indicates that the first network node sends the authentication identifier to multiple inventory stations (including the first inventory node and the second inventory node). Non-multi-site joint reception indicates that the first network node sends the current day's authentication identifier to a single first inventory node. A user can have multiple tags, and the tag management network element can send the security tag authentication identifiers corresponding to each of these multiple tags to the first network node. The first network node forms an authentication identifier corresponding to each tag based on the multiple security tag authentication identifiers.
[0124] In this embodiment, the tag management network element determines the inventory strategy based on the user identity information and sends the inventory strategy and the security tag authentication identifier for the tag to the first network node. In this way, the first network node can extract the authentication identifier from the security tag authentication identifier based on the inventory strategy and send it to the corresponding first inventory node and / or second inventory node. This provides the first inventory node and / or second inventory node with the authentication identifier, enabling them to form corresponding security inventory waveform information to effectively recover the inventory feedback information from the tag. When the first inventory node experiences high computational pressure, the second inventory node can also perform the recovery, thereby improving the tag authentication efficiency of the entire wireless IoT system.
[0125] In some embodiments, see Figure 6 , Figure 6 This is a schematic diagram of an optional flowchart of the tag authentication and authorization method provided in an embodiment of this application. Figure 5 S204 may be included after S203 shown, and will be explained in conjunction with each step.
[0126] S204. If the inventory strategy represents a non-multi-site joint reception strategy, then the first network node determines the first inventory node based on the inventory strategy and sends the authentication identifier to the first inventory node.
[0127] In this embodiment of the application, the multi-disk storage strategy is characterized as a non-multi-station joint reception strategy. In this case, the first network node determines the preset first disk storage node and sends the authentication identifier determined in the security label authentication identifier to the first disk storage node.
[0128] If the first network node receives multiple security label authentication identifiers, it extracts the common part of the multiple security label authentication identifiers as the authentication identifier and sends it to the first disk storage node.
[0129] In the embodiment of the present application, if the inventory strategy represents a non-multi-station joint receiving strategy, the first network node determines a first inventory node based on the inventory strategy, and sends the authentication identifier to the first inventory node. In this way, the first network node can send the authentication identifier to the corresponding first inventory node for the first inventory node to form inventory information and send it to the tag for authentication. After the tag is authenticated and the inventory feedback information is fed back, the security inventory waveform information formed based on the authentication identifier can be used to recover the inventory feedback information, preventing the tag from being incorrectly authenticated by an attacker and an eavesdropper during the authentication process, and ensuring the authentication security of the tag.
[0130] In some embodiments, referring to Figure 7 , Figure 7 An optional flowchart of a tag authentication and authorization method provided by the embodiment of the present application is shown in Figure 6 Steps S201 to S203 shown in the figure can also be implemented by steps 1 to 12, which will be described in combination with the steps.
[0131] 1. Start the security inventory mode.
[0132] 2. Transfer user instructions and user identity information.
[0133] For the core network, the tag authentication identifier only needs to be sent to one base station (e.g., RAN1), which confirms its role as a “transmit-receive integrated” base station according to the indication of the core network. The user node starts the security inventory mode, and the NEF transfers the user instructions and identity information to the TMF.
[0134] 3. Tag authentication identifier and joint inventory indication.
[0135] The TMF verifies the user identity, specifies the inventory strategy, and forwards the inventory strategy (non-multi-station joint receiving) and the security tag authentication identifier involved to the AMF.
[0136] 4. Air interface authentication identifier and inventory role indication.
[0137] The AMF generates an air interface authentication identifier based on the security tag authentication identifier and sends it, and at the same time, indicates the base station inventory role (first inventory node).
[0138] 5. Security inventory waveform generation.
[0139] 6. Normal inventory instruction and air interface authentication identifier A + security inventory waveform.
[0140] The first inventory node generates a secure inventory waveform based on the air interface authentication identifier and generates a specific inventory signaling format, namely, an inventory signaling format using "the first inventory node's air interface authentication identifier for this operation + the regular inventory instruction + the generated secure inventory waveform" (e.g., ...). Figure 1 As shown in the figure, a cycle is used to safely inventory the tags.
[0141] 7. Verify the air interface authentication identifier.
[0142] 8. Superimpose modulation information onto the safe storage waveform.
[0143] After verifying the air interface authentication identifier of the tag and confirming the legitimacy of the base station and the correctness of the packet, the tag modulates its own information on the securely stored waveform. The own information may include the tag identifier and the updated tag authentication identifier (the update rule must be known to both the network and the tag).
[0144] 9. Recover the signal according to the waveform generation scheme.
[0145] 10. Reporting of label information.
[0146] Only the first storage node has the correct security storage waveform, and can generate a cancel carrier based on the security storage waveform, recover the tag information, and report the information to the TMF.
[0147] 11. Verify update rules & update tag authentication identifier.
[0148] 12. Reporting of label information.
[0149] Based on the "updated tag authentication identifier" and the preset authentication identifier update rules, TMF obtains the "previous tag authentication identifier". It then verifies whether the "previous tag authentication identifier" is consistent with the identifier it stores. If they are consistent, the tag is considered valid, and the TMF updates the identifier it stores to the "updated tag identifier" and reports the tag information to the user.
[0150] In some embodiments, see Figure 8 , Figure 8 This is a schematic diagram of an optional flowchart of the tag authentication and authorization method provided in an embodiment of this application. Figure 5 S203 shown may be followed by S205 to S206, which will be explained in conjunction with each step.
[0151] S205. If the inventory strategy represents a multi-station joint reception strategy, then the first network node determines the first inventory node based on the inventory strategy and sends the authentication identifier and the second inventory node information to the first inventory node.
[0152] In this embodiment of the application, if the inventory strategy is characterized as a multi-station joint reception strategy, the first network node determines a preset first inventory node based on the first inventory node, and sends the authentication identifier determined in the security label authentication identifier and the preset second inventory node information to the first inventory node.
[0153] The second disk storage node information may include the address information and identification information of the second disk storage node.
[0154] S206. Based on the information of the second storage node, send the authentication identifier to the corresponding second storage node.
[0155] In this embodiment of the application, the first storage node sends the authentication identifier to the corresponding second storage node based on the information of the second storage node.
[0156] In this embodiment, if the identity of the second storage node is indicated by the first storage node, the AMF sends the role of the second storage node to the first storage node, and the first storage node forwards the authentication identifier to the second storage node, thus confirming the second storage node as the second storage node. Only the tag information needs to be received and restored.
[0157] In this embodiment, under the multi-station joint reception strategy, the first network node determines the first storage node based on the storage strategy and sends the authentication identifier and the second storage node information to the first storage node. The second storage node is then determined by the first storage node. Thus, when the first storage node faces significant computational pressure, the second storage node can perform tag authentication, improving the tag authentication efficiency in the wireless IoT system.
[0158] In some embodiments, see Figure 9 , Figure 9 This is a schematic diagram of an optional flowchart of the tag authentication and authorization method provided in an embodiment of this application. Figure 5 S203 shown may be followed by S207 to S210, which will be explained in conjunction with each step.
[0159] S207. If the inventory strategy represents a multi-station joint reception strategy, then the first network node determines the first inventory node and the second inventory node based on the inventory strategy, and sends the authentication identifier to the first inventory node and the second inventory node.
[0160] In this embodiment, if the inventory strategy is characterized as a multi-station joint reception strategy, the first network node determines a preset first inventory node and a second inventory node based on the inventory strategy. The first network node sends the authentication identifier determined in the security label authentication identifier to the first inventory node and the second inventory node.
[0161] In the embodiments of the present application, if the identity of the second inventory node is indicated by the AMF, the AMF indicates that the base station B is the second inventory node, and only needs to perform receiving and restoring of the tag information.
[0162] S208, the second inventory node forms auxiliary station security inventory waveform information based on the authentication identifier.
[0163] In the embodiments of the present application, the second inventory node forms auxiliary station security inventory waveform information on the side of the second inventory node based on the authentication identifier.
[0164] The auxiliary station security inventory waveform information is the same as the security inventory waveform information on the side of the first inventory node.
[0165] S209, the second inventory node receives the inventory feedback information, and generates auxiliary station cancellation carrier waves for the inventory feedback information based on the auxiliary station security inventory waveform.
[0166] In the embodiments of the present application, when the inventory strategy is a multi-station joint receiving strategy, the tag may send the inventory feedback information to the second inventory node. The second inventory node receives the inventory feedback information, and forms corresponding auxiliary station cancellation carrier waves for the inventory feedback information using the auxiliary station security inventory waveform information.
[0167] S210, the second inventory node restores the tag identifier and the updated tag identifier of the tag based on the auxiliary station cancellation carrier waves and the inventory feedback information.
[0168] In the embodiments of the present application, the second inventory node restores the tag identifier and the updated tag identifier of the tag based on the auxiliary station cancellation carrier waves and the inventory feedback information. The second inventory node sends the restored tag identifier and the updated tag identifier to the tag management network element for authentication by the tag management network element.
[0169] In the embodiments of the present application, when the multi-station joint receiving strategy is used, the tag may send the inventory feedback waveform to the second inventory node for restoration in specific cases. In this way, when the calculation pressure of the first inventory node is high, the authentication of the tag can be performed by the second inventory node, thereby improving the authentication efficiency of the tag in the wireless Internet of Things system.
[0170] In some embodiments, referring to Figure 10 , Figure 10 An optional flowchart of a tag authentication and authorization method provided in the embodiments of the present application is shown in Figure 8 and Figure 9 The steps shown in the above figures can also be implemented by steps 13 to 24, which will be described in conjunction with the steps.
[0171] 13, start the security inventory mode.
[0172] 14、Transmitting user instruction & user identity information.
[0173] For the core network, the label authentication temporary identifier needs to be sent to the first inventory node (such as RAN1) sending the inventory signaling and a plurality of second inventory node base stations (such as RAN2) jointly receiving, RAN1 confirms its role as a "transmit-receive separation" master station according to the indication of the core network, and RAN2 confirms its role as a "transmit-receive separation" slave station according to the indication of the core network. The user starts the security inventory mode, and the NEF transmits the user instruction and identity information to the TMF.
[0174] 15、Label authentication identifier & joint inventory indication.
[0175] The TMF verifies the user identity, specifies the inventory strategy, and forwards the inventory strategy (multi-station joint receiving) and the security label authentication identifier involved to the AMF.
[0176] 16、Air interface authentication identifier & inventory role indication (A).
[0177] The AMF generates an air interface authentication identifier according to the security label authentication identifier and sends it to RAN1, and at the same time, indicates that the base station RAN1 is the first inventory node and needs to send signaling.
[0178] 17a、Air interface authentication identifier & inventory role indication (B).
[0179] If the identity of the second inventory node is indicated by the first inventory node, the AMF sends the role of the base station RAN2 to the base station RAN1, and the base station RAN1 forwards the information to the base station RAN2, determines that the base station RAN2 is the second inventory node, and only needs to receive and restore the label information.
[0180] 17b、Air interface authentication identifier & inventory role indication (B).
[0181] If the identity of the second inventory node is indicated by the AMF, the AMF indicates that the base station RAN2 is the second inventory node and only needs to receive and restore the label information.
[0182] 18、Security inventory waveform and interaction identifier generation.
[0183] 19、Regular inventory instruction & air interface authentication identifier + security inventory waveform.
[0184] The first inventory node generates a security inventory waveform according to the air interface authentication identifier, and generates a specific inventory signaling format, that is, uses the inventory signaling format of "the air interface authentication identifier of the first inventory node this time + regular inventory instruction + the generated security inventory waveform" for a period to perform security inventory on the label.
[0185] 20. Superimposing the modulation information on the security disk storage waveform.
[0186] 21. Recovering the signal according to the waveform generation scheme.
[0187] 22. Reporting the tag information.
[0188] After the tag verification air interface authentication identifier confirms that the base station identity is legal and the packet is correct, the tag superimposes its own information on the security disk storage waveform. The tag information can be received by the second disk storage node or the first disk storage node. The main station and the auxiliary station have correct security disk storage waveforms and can generate the cancellation carrier according to the security disk storage waveform, recover the tag information and report the information to the TMF.
[0189] 23. Verifying the update rule and updating the tag authentication identifier.
[0190] 24. Reporting the tag information.
[0191] The TMF obtains the "updated tag authentication identifier" and the preset authentication identifier update rule, and obtains the "updated tag authentication identifier". The "updated tag authentication identifier" is verified whether it is consistent with the stored identifier. If it is consistent, it is considered that the tag is legal, the stored identifier is updated to the "updated tag identifier", and the tag information is reported to the user.
[0192] In some embodiments, referring to Figure 11 , Figure 11 An optional flowchart of the tag authentication and authorization method provided in the embodiments of the present application is shown in Figure 2 After S1032 shown in the figure, S301 to S302 can be included, which will be described in combination with each step.
[0193] S301, the tag management network element inversely solves the updated tag identifier based on a preset rule to obtain an updated tag identifier.
[0194] In the embodiments of the present application, the tag management network element inversely solves the updated tag identifier based on a preset rule to obtain an updated tag identifier.
[0195] The updated identifier is obtained by processing the updated tag identifier based on the preset rule.
[0196] S302, the tag management network element compares the updated tag identifier with the stored tag identifier, and determines the authentication and authorization result based on the comparison result.
[0197] In the embodiment of the present application, the label management network element and the label form the security label authentication identifier for the label based on the preset rule in the same period, so the label management network element only needs to compare the label identifier before updating with the security label authentication identifier calculated in the last period, and determine the authentication and authorization result of the label based on the comparison result.
[0198] In the embodiment of the present application, the label management network element inversely solves the label identifier after updating based on the preset rule, and obtains the label identifier before updating; wherein the label identifier after updating is obtained by processing the label identifier before updating based on the preset rule. Since the preset rules on both sides of the label management network element and the label are the same, the label identifiers calculated by them are also based on periodic synchronization, and then this feature can be used to inversely solve the label identifier after updating, to verify whether the label identifier in the inventory feedback information and the label identifier after updating conform to the preset rule, and then determine the authentication and authorization result of the label.
[0199] In some embodiments, referring to Figure 12 , Figure 12 An optional flowchart of the label authentication and authorization method provided by the embodiment of the present application will be described in combination with each step.
[0200] S401, receiving the inventory information sent by the first inventory node, and authenticating the first inventory node based on the inventory information to obtain an authentication result.
[0201] In the embodiment of the present application, the label receives the inventory information sent by the first inventory node, and authenticates the first inventory node based on the inventory information to obtain an authentication result.
[0202] S402, if the authentication result represents that the first inventory node is authenticated, superimposing the identification information in a specific part of the inventory information to form inventory feedback information.
[0203] In the embodiment of the present application, if the authentication result represents that the first inventory node is authenticated, the label superimposes the identification information in the security inventory waveform of the inventory information, and forms the inventory feedback information based on the superimposed security inventory waveform.
[0204] S403, sending the inventory feedback information to the first inventory node; the first inventory node restores the identification information based on the inventory information, and sends the identification information to the label management network element for authentication.
[0205] In the embodiment of the present application, the label sends the inventory feedback information to the first inventory node. The first inventory node restores the identification information based on the inventory information, and sends the identification information to the label management network element for authentication.
[0206] In this way, the inventory feedback information is sent to the first inventory node only after the tag authenticates the first inventory node based on the inventory information. Since it is difficult for an attacker to obtain the authentication identifier at the current time, the instruction sent by the attacker will not be authenticated, and thus the tag will not respond to the instruction from the attacker, ensuring the safety of the received information of the tag. Moreover, since the inventory feedback information is formed by superimposing the identifier information in a specific part of the inventory information, the identifier information can be obtained only by using the corresponding inventory information. Other devices without the inventory information cannot restore the inventory feedback information, and thus cannot obtain the information sent by the tag, ensuring the safety of the sent information of the tag, and further improving the authentication and authorization safety of the tag in the passive Internet of Things system.
[0207] In some embodiments, referring to Figure 13 , Figure 13 An optional flowchart of a tag authentication and authorization method provided in the embodiments of the present application is shown in Figure 12 The S401 to S402 shown can also be implemented by S4011 to S4022, which will be described in combination with each step.
[0208] S4011, receiving the inventory information sent by the first inventory node; wherein the inventory information comprises an authentication identifier, an inventory instruction and safety inventory waveform information.
[0209] In the embodiments of the present application, the tag receives the inventory information sent by the first inventory node, wherein the inventory information comprises an authentication identifier, an inventory instruction and safety inventory waveform information.
[0210] S4012, matching the authentication identifier with a tag identifier based on the demapping result of the authentication identifier to determine the authentication result; wherein the tag identifier is formed periodically based on a preset rule.
[0211] In the embodiments of the present application, the safety tag authentication identifier and the tag identifier formed in the same period are the same string, and the authentication identifier is part of the safety tag authentication identifier. As long as the first inventory node sends the inventory information to the correct tag, the authentication identifier and the tag identifier have a certain mapping relationship. By using this feature, the tag can determine the authentication result of the first inventory node. If the matching is successful, it is determined that the authentication is passed, otherwise, the authentication is not passed.
[0212] S4021, if the authentication result indicates that the first inventory node is authenticated, an updated tag identifier is formed based on a preset rule.
[0213] In the embodiments of the present application, if the authentication is passed, the tag forms an updated tag identifier based on a preset rule in the next period.
[0214] S4022, superimpose the tag identity and the updated tag identity in the security inventory waveform, and form the inventory feedback information by using the superimposed security inventory waveform.
[0215] In the embodiment of the present application, the tag superimposes the tag identity and the updated tag identity in the security inventory waveform, and forms the inventory feedback information by using the superimposed security inventory waveform. The inventory feedback information is sent to the first inventory node.
[0216] The present application combines the tag group random number generation with the air interface authentication identity generation, completes the dynamic two-way authentication, reduces the power consumption of the tag due to supporting the two-way authentication, and is different from the traditional security protection mechanism in which the tag encrypts data based on a key. In the present application, a specific inventory waveform is generated by the base station and is periodically updated. After verifying the legality of the base station, the tag can use the specific waveform to backscatter its own data, thereby ensuring the transmission security and greatly reducing the power consumption of the tag for data encryption.
[0217] In some embodiments, referring to Figure 14 , Figure 14 An optional flowchart of the tag authentication and authorization method provided in the embodiment of the present application is shown in Figure 12 S402 shown in the figure can further include S404, which will be described in combination with each step.
[0218] S404, sending the inventory feedback information to a second inventory node; the second inventory node recovers the identity information from the inventory feedback information based on the inventory information, and sends the identity information to a tag management network element for authentication.
[0219] In some embodiments, if the strategy of the security inventory this time is a multi-station joint receiving strategy, the tag can send the inventory feedback information to a second inventory node. The second inventory node recovers the identity information from the inventory feedback information based on the inventory information, and sends the identity information to a tag management network element for authentication.
[0220] The embodiment of the present application provides a method for issuing security inventory mechanism related parameters in combination with a plurality of inventory modes, i.e., when the system is in a single station self-generation and self-reception mode, the security inventory mechanism related parameters only need to be issued to the first inventory node; when the system is in a single multi-station joint reception mode, the security inventory mechanism related parameters need to be issued to the first inventory node and the second inventory node, and the roles of the reading and writing devices need to be specified.
[0221] In some embodiments, referring to Figure 15 , Figure 15 An optional flowchart of the tag authentication and authorization method provided in the embodiment of the present application is shown inFigure 12 S401 to S403 shown are also implemented through steps 25 to 34, which will be described in combination with the steps.
[0222] 25, normal inventory instruction & air interface authentication identifier A + waveform; 26, check air interface authentication identifier A pass.
[0223] The tag authentication identifier obtained during initial authentication of the tag is stored in the tag itself memory and a legal read-write device (such as TMF). The read-write device generates a specific inventory signaling format according to the tag authentication identifier, that is, uses the inventory signaling format of "the air interface authentication identifier A of the first inventory node this time + normal inventory instruction + the generated secure inventory waveform". 2a, authentication of the tag to the network: only when the tag checks that the air interface authentication identifier passes and the packet is correct, the tag will respond, that is, the tag 1 will respond to the 1a instruction from the RAN, but will not respond to the 1b instruction from the attacker; the tag 2 remains silent.
[0224] 27, normal inventory instruction & air interface authentication identifier A + waveform A; 28, not belonging to the air interface authentication identifier A packet.
[0225] The RAN sends the normal inventory instruction & air interface authentication identifier A + waveform to the tag 2. Since the identifier information of the tag 2 does not match the air interface authentication identifier, it is determined that the tag 2 does not belong to the air interface authentication identifier A packet.
[0226] 29, normal inventory instruction & air interface authentication identifier B + waveform B; 30, check air interface authentication identifier B not pass.
[0227] The attacker sends the normal inventory instruction & air interface authentication identifier B + waveform B to the tag 1. The tag 1 authenticates the normal inventory instruction & air interface authentication identifier B + waveform B, and does not pass the authentication, so it does not feedback information to the attacker.
[0228] 31, superimpose modulation information on the waveform A; 32, recover the signal according to the waveform generation scheme.
[0229] The tag 1 uses the waveform A as a carrier to send its own information. The legal read-write device RAN generates a cancellation carrier according to the waveform A to recover the tag 1 information. Network authentication of the tag: the legal read-write device RAN reports the parsed tag information to the core network TMF. The network updates the "pre-update tag authentication identifier" according to the preset authentication identifier update rule, checks whether the "pre-update tag authentication identifier" is consistent with the identifier stored by itself, and if so, considers the tag to be legal, updates the identifier stored by itself to "post-update tag identifier", and reports the tag information to the user.
[0230] 33, superimpose modulation information on the waveform A; 34, unable to recover the signal.
[0231] The tag 1 superimposes modulation information on the waveform A, and is eavesdropped by an eavesdropper during transmission to the RAN. The eavesdropper cannot quickly copy the waveform A, and thus cannot generate a cancellation carrier to eavesdrop the tag 1 information.
[0232] In some embodiments, referring to Figure 16 , Figure 16 An interaction schematic diagram of the tag authentication and authorization method provided in the embodiments of the present application will be described in combination with the steps.
[0233] S501, the first inventory node forms inventory information based on the acquired authentication identifier for the tag.
[0234] In the embodiments of the present application, the implementation process of S501 can refer to S101, which will not be described one by one here.
[0235] S502, the first inventory node sends the inventory information to the tag and receives inventory feedback information sent by the tag; wherein the inventory feedback information is formed by superimposing identifier information corresponding to the tag in a specific part of the inventory information based on the first inventory node passing the authentication of the tag based on the inventory information.
[0236] In the embodiments of the present application, the implementation process of S502 can refer to S102, which will not be described one by one here.
[0237] S503, the first inventory node restores the identifier information based on the inventory information on the inventory feedback information, and sends the identifier information to the tag management network element for authentication.
[0238] In the embodiments of the present application, the implementation process of S503 can refer to S103, which will not be described one by one here.
[0239] Referring to Figure 17 , Figure 17 The structure schematic diagram of the tag authentication and authorization device provided in the embodiments of the present application Figure 1 .
[0240] The embodiments of the present application also provide a tag authentication and authorization device 600 applied to a first inventory node, comprising: an information forming unit 601, a transceiver unit 602 and a recovery unit 603.
[0241] The information forming unit 601 is configured to form inventory information based on the acquired authentication identifier for the tag.
[0242] The transceiver unit 602 is configured to send the inventory information to the tag and receive inventory feedback information sent by the tag; wherein the inventory feedback information is formed by superimposing identification information corresponding to the tag in a specific part of the inventory information based on the inventory information after the tag passes the authentication of the first inventory node;
[0243] The recovery unit 603 is configured to recover the identification information from the inventory feedback information based on the inventory information, and send the identification information to the tag management network element for authentication.
[0244] In the embodiment of the present application, the information forming unit 601 in the tag authentication and authorization device 600 is configured to receive an authentication identifier sent by the first network node; wherein the authentication identifier is a secure tag authentication identifier for the tag formed by the tag management network element based on a preset rule periodically; form secure inventory waveform information based on the authentication identifier; and form the inventory information based on the authentication identifier, an inventory instruction and the secure inventory waveform information.
[0245] In the embodiment of the present application, the identification information includes a tag identifier and an updated tag identifier; the recovery unit 603 in the tag authentication and authorization device 600 is configured to generate a cancellation carrier wave for the inventory feedback information based on the secure inventory waveform information; recover the inventory feedback information to obtain the tag identifier and the updated tag identifier of the tag based on the cancellation carrier wave; wherein the updated tag identifier is formed based on the preset rule for the tag identifier by the tag synchronously with the period of the tag management network element.
[0246] In the embodiment of the present application, the second network node receives an inventory instruction; wherein the inventory instruction includes inventory user identity information; the second network node sends the inventory instruction to the tag management network element; the tag management network element determines an inventory strategy based on the inventory user identity information, and sends the inventory strategy and a secure tag authentication identifier for the tag to the first network node.
[0247] In the embodiment of the present application, if the inventory strategy represents a non-multi-station joint reception strategy, the first network node determines the first inventory node based on the inventory strategy, and sends the authentication identifier to the first inventory node.
[0248] In the embodiment of the present application, if the inventory strategy represents a multi-station joint reception strategy, the first network node determines the first inventory node based on the inventory strategy, and sends the authentication identifier and second inventory node information to the first inventory node.
[0249] send the authentication identifier to the corresponding second inventory node based on the second inventory node information.
[0250] In the embodiments of the present application, if the inventory strategy represents a multi-site joint receiving strategy, the first network node determines the first inventory node and the second inventory node based on the inventory strategy, and sends the authentication identifier to the first inventory node and the second inventory node.
[0251] In the embodiments of the present application, the second inventory node forms auxiliary station security inventory waveform information based on the authentication identifier;
[0252] The second inventory node receives the inventory feedback information, and generates an auxiliary station cancellation carrier wave for the inventory feedback information based on the auxiliary station security inventory waveform.
[0253] The second inventory node recovers the tag identifier of the tag based on the auxiliary station cancellation carrier wave from the inventory feedback information, and updates the tag identifier.
[0254] In the embodiments of the present application, the tag management network element inversely solves the updated tag identifier based on a preset rule to obtain a pre-update tag identifier; and the tag management network element compares the pre-update tag identifier with the stored tag identifier, and determines an authentication and authorization result based on a comparison result.
[0255] It should be noted that, in the embodiments of the present application, if the above-mentioned tag authentication and authorization method is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solutions of the embodiments of the present application can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a plurality of instructions for causing a tag authentication and authorization device (which can be a personal computer, etc.) to execute all or part of the methods described in the embodiments of the present application. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a magnetic disk or an optical disk, and various storage medium that can store program codes. Thus, the embodiments of the present application are not limited to any specific hardware and software combination.
[0256] Correspondingly, the embodiments of the present application provide a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the steps in the first inventory node side method.
[0257] Correspondingly, this application provides an electronic device 700, including a first memory 702 and a first processor 701. The first memory 702 stores a computer program that can run on the first processor 701. When the first processor 701 executes the program, it implements the steps in the above method.
[0258] It should be noted that the descriptions of the storage medium and device embodiments above are similar to the descriptions of the method embodiments above, and have similar beneficial effects. For technical details not disclosed in the storage medium and device embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.
[0259] It should be noted that, Figure 18 A hardware entity illustration of an electronic device provided in the embodiments of this application. Figure 1 ,like Figure 18 As shown, the hardware entity of the electronic device 700 includes: a first processor 701 and a first memory 702, wherein;
[0260] The first processor 701 typically controls the overall operation of the electronic device 700.
[0261] The first memory 702 is configured to store instructions and applications executable by the first processor 701, and can also cache data to be processed or already processed by the first processor 701 and various modules in the electronic device 700 (e.g., image data, audio data, voice communication data and video communication data), which can be implemented by flash memory or random access memory (RAM).
[0262] See Figure 19 , Figure 19 Schematic diagram of the label authentication and authorization device provided in the embodiments of this application Figure 2 .
[0263] This application embodiment also provides a tag authentication and authorization device 800, applied to tags, including: a receiving authentication unit 801, an information overlay unit 802, and a sending unit 803.
[0264] The authentication receiving unit 801 is used to receive inventory information sent by the first inventory node, and to authenticate the first inventory node based on the inventory information to obtain an authentication result.
[0265] The information overlay unit 802 is used to overlay identification information into a specific part of the inventory information to form inventory feedback information if the authentication result indicates that the first inventory node has been authenticated.
[0266] The sending unit 803 is used to send the inventory feedback information to the first inventory node; the first inventory node recovers the identification information based on the inventory information from the inventory feedback information, and sends the identification information to the tag management network element for authentication.
[0267] In this embodiment of the application, the receiving authentication unit 801 in the tag authentication and authorization device 800 is used to receive the inventory information sent by the first inventory node; wherein, the inventory information includes: authentication identifier, inventory instruction and secure inventory waveform information; the authentication result is determined by matching the demapping result of the authentication identifier with the tag identifier; wherein, the tag identifier is formed periodically based on preset rules.
[0268] In this embodiment of the application, the information overlay unit 802 in the tag authentication and authorization device 800 is used to form an updated tag identifier based on a preset rule; the tag identifier and the updated tag identifier are overlaid on the security inventory waveform, and the inventory feedback information is formed by using the overlaid security inventory waveform.
[0269] In this embodiment of the application, the sending unit 803 in the tag authentication and authorization device 800 is used to send the inventory feedback information to the second inventory node; the second inventory node recovers the identification information based on the inventory information from the inventory feedback information, and sends the identification information to the tag management network element for authentication.
[0270] Correspondingly, embodiments of this application provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps in the tag-side method.
[0271] Correspondingly, this application provides an electronic device 900, including a second memory 902 and a second processor 901. The second memory 902 stores a computer program that can run on the second processor 901. When the second processor 901 executes the program, it implements the steps in the above method.
[0272] It should be noted that the descriptions of the storage medium and device embodiments above are similar to the descriptions of the method embodiments above, and have similar beneficial effects. For technical details not disclosed in the storage medium and device embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.
[0273] It should be noted that, Figure 20 A hardware entity illustration of an electronic device provided in the embodiments of this application. Figure 2 ,like Figure 20 As shown, the hardware entity of the electronic device 900 includes: a second processor 901 and a second memory 902, wherein;
[0274] The second processor 901 generally controls the overall operation of the electronic device 900.
[0275] The second memory 902 is configured to store instructions and applications executable by the second processor 901, and can also cache data (e.g., image data, audio data, voice communication data, and video communication data) to be processed by the second processor 901 and modules in the electronic device 900, and can be implemented by a FLASH or a Random Access Memory (RAM).
[0276] It should be understood that the term "one embodiment" or "an embodiment" as used throughout this specification means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the application. Therefore, the appearance of the phrase "in one embodiment" or "in an embodiment" in various places throughout the specification is not necessarily referring to the same embodiment. In addition, the particular features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. It should be understood that the size of the sequence of the above-mentioned processes does not mean the order of execution, and the execution order of the processes should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the application. The above-mentioned sequence number of the embodiments of the application is only for description, not representing the advantages or disadvantages of the embodiments.
[0277] It should be noted that, in this document, the terms "comprises", "comprising", or any other variation thereof, are intended to cover a non-exclusive inclusion, so that a process, method, article, or apparatus that comprises a list of elements does not only include those elements, but also includes other elements not expressly listed or inherent to such process, method, article, or apparatus. Without more limitations, the element defined by the statement "comprises a" does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element.
[0278] In several embodiments provided in the present application, it should be understood that the disclosed apparatus and method can be implemented in other ways. The above-described apparatus embodiment is only schematic. For example, the division of the units is only a logical function division, and actual implementation can have another division manner, such as: a plurality of units or components can be combined, or can be integrated into another system, or some features can be ignored, or not executed. In addition, the coupling or direct coupling or communication connection between the various components shown or discussed can be indirect coupling or communication connection through some interface, device or unit, which can be electrical, mechanical or other forms.
[0279] The units described as separate components above can or can not be physically separate, and the components displayed as units can or can not be physical units; they can be located in one place or distributed on multiple network units; and part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.
[0280] In addition, each functional unit in each embodiment of the present application can be integrated into one processing unit, or each unit can be a separate unit, or two or more units can be integrated into one unit; the integrated unit can be realized in the form of hardware or in the form of hardware plus software functional unit.
[0281] Those skilled in the art can understand that all or part of the steps of the above method embodiments can be completed by program instruction related hardware, and the foregoing program can be stored in a computer readable storage medium, and the program executes the steps including the above method embodiments when executed; and the foregoing storage medium includes mobile storage devices, read only memory (ROM), magnetic discs or optical discs and various storage medium capable of storing program codes.
[0282] Alternatively, the integrated units of the present application, if implemented in the form of software functional modules and sold or used as independent products, can also be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the embodiments of the present application can be embodied in the form of software products, and the computer software products are stored in a storage medium, including a number of instructions for making a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the methods described in the embodiments of the present application. The foregoing storage medium includes mobile storage devices, ROM, magnetic discs or optical discs and various storage medium capable of storing program codes.
[0283] The above is only an embodiment of the present application, but the protection scope of the present application is not limited thereto, and any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A label authentication and authorization method, characterized in that, Applied to the first disk storage node, including: Receive an authentication identifier sent by the first network node; wherein, the authentication identifier is a security tag authentication identifier for tags that is periodically formed by the tag management network element based on preset rules; Based on the authentication identifier, secure inventory waveform information is generated; Inventory information is composed of the authentication identifier, inventory instruction, and secure inventory waveform information; The inventory information is sent to the tag, and the inventory feedback information sent by the tag is received; wherein, the inventory feedback information is formed by superimposing the tag's corresponding identification information on a specific part of the inventory information after the tag has authenticated the first inventory node based on the inventory information; Based on the security inventory waveform information, a cancellation carrier is generated for the inventory feedback information; The tag identifier and the updated tag identifier are obtained based on the disk feedback information obtained from the carrier cancellation recovery; wherein, the updated tag identifier is the period during which the tag is synchronized with the tag management network element, formed based on the preset rules for the tag identifier, and the identifier information is sent to the tag management network element for authentication; the identifier information includes: the tag identifier and the updated tag identifier.
2. The label authentication and authorization method according to claim 1, characterized in that, The method further includes: The second network node receives the inventory instruction; wherein the inventory instruction includes the user's identity information. The second network node sends the inventory instruction to the tag management network element; The tag management network element determines the inventory strategy based on the inventory user's identity information, and sends the inventory strategy and the security tag authentication identifier for the tag to the first network node.
3. The label authentication and authorization method according to claim 2, characterized in that, After the tag management network element determines the inventory strategy based on the inventory user identity information and sends the inventory strategy and the security tag authentication identifier for the tag to the first network node, the method further includes: If the inventory strategy represents a non-multi-site joint reception strategy, then the first network node determines the first inventory node based on the inventory strategy and sends the authentication identifier to the first inventory node.
4. The label authentication and authorization method according to claim 2, characterized in that, After the tag management network element determines the inventory strategy based on the inventory user identity information and sends the inventory strategy and the security tag authentication identifier for the tag to the first network node, the method further includes: If the inventory strategy represents a multi-station joint reception strategy, then the first network node determines the first inventory node based on the inventory strategy and sends the authentication identifier and the second inventory node information to the first inventory node. The authentication identifier is sent to the corresponding second inventory node based on the information of the second inventory node.
5. The label authentication and authorization method according to claim 2, characterized in that, After the tag management network element determines the inventory strategy based on the inventory user identity information and sends the inventory strategy and the security tag authentication identifier for the tag to the first network node, the method further includes: If the inventory strategy represents a multi-site joint reception strategy, then the first network node determines the first inventory node and the second inventory node based on the inventory strategy, and sends the authentication identifier to the first inventory node and the second inventory node.
6. The label authentication and authorization method according to claim 4 or 5, characterized in that, The method further includes: The second inventory node generates auxiliary station security inventory waveform information based on the authentication identifier; The second inventory node receives the inventory feedback information and generates an auxiliary station cancellation carrier based on the auxiliary station safety inventory waveform for the inventory feedback information; The second inventory node obtains the tag identifier and the updated tag identifier of the tag based on the inventory feedback information recovered by the auxiliary station cancel carrier.
7. The label authentication and authorization method according to claim 1, characterized in that, The method further includes: The tag management network element performs a reverse calculation on the updated tag identifier based on preset rules to obtain the original tag identifier; The tag management network element compares the tag identifier before the update with the stored tag identifier, and determines the authentication result based on the comparison result.
8. A label authentication and authorization method, characterized in that, Applied to labels, including: The system receives inventory information sent by a first inventory node and authenticates the first inventory node based on the inventory information to obtain an authentication result; wherein, the inventory information is an authentication identifier sent by a first network node to the first inventory node; secure inventory waveform information is formed based on the authentication identifier; inventory information is composed of the authentication identifier, inventory instructions, and the secure inventory waveform information; wherein, the authentication identifier is a secure tag authentication identifier for tags formed periodically based on preset rules by the tag management network element; If the authentication result indicates that the first inventory node has been authenticated, then the identification information is superimposed on a specific part of the inventory information to form inventory feedback information; The inventory feedback information is sent to the first inventory node; the first inventory node generates a cancellation carrier for the inventory feedback information based on the secure inventory waveform information; the inventory feedback information is recovered based on the cancellation carrier to obtain the tag identifier of the tag and the updated tag identifier; wherein, the updated tag identifier is formed based on the preset rules for the tag identifier during the period when the tag is synchronized with the tag management network element, and the identifier information is sent to the tag management network element for authentication; the identifier information includes: the tag identifier and the updated tag identifier.
9. The label authentication and authorization method according to claim 8, characterized in that, The step of receiving inventory information sent by the first inventory node and authenticating the first inventory node based on the inventory information to obtain an authentication result includes: The system receives the inventory information sent by the first inventory node; wherein the inventory information includes: authentication identifier, inventory instruction, and secure inventory waveform information. The authentication result is determined by matching the demapping result of the authentication identifier with the tag identifier; wherein the tag identifier is formed periodically based on preset rules.
10. The label authentication and authorization method according to claim 9, characterized in that, The process of overlaying identification information into a specific portion of the inventory information to form inventory feedback information includes: The updated label is generated based on preset rules; The label identifier and the updated label identifier are superimposed on the security inventory waveform, and the inventory feedback information is formed by using the superimposed security inventory waveform.
11. The label authentication and authorization method according to any one of claims 8 to 10, characterized in that, If the authentication result indicates that the first inventory node has passed authentication, then after overlaying identification information into a specific part of the inventory information to form inventory feedback information, the method further includes: The inventory feedback information is sent to the second inventory node; the second inventory node recovers the identification information based on the inventory information and sends the identification information to the tag management network element for authentication.
12. A label authentication and authorization device, characterized in that, Applied to the first disk storage node, including: An information forming unit is used to receive an authentication identifier sent by a first network node; wherein the authentication identifier is a security tag authentication identifier for a tag that is periodically formed by the tag management network element based on preset rules; secure inventory waveform information is formed based on the authentication identifier; and inventory information is composed based on the authentication identifier, the inventory instruction, and the secure inventory waveform information. The transceiver unit is used to send the inventory information to the tag and receive inventory feedback information sent by the tag; wherein the inventory feedback information is formed by superimposing the tag's corresponding identification information on a specific part of the inventory information after the tag has authenticated the first inventory node based on the inventory information; The recovery unit is configured to generate a cancellation carrier for the storage feedback information based on the security storage waveform information; recover the storage feedback information based on the cancellation carrier to obtain the tag identifier of the tag and the updated tag identifier; wherein, the updated tag identifier is formed based on the preset rules for the tag identifier during the period when the tag is synchronized with the tag management network element, and the identifier information is sent to the tag management network element for authentication; the identifier information includes: the tag identifier and the updated tag identifier.
13. A label authentication and authorization device, characterized in that, Applied to labels, including: The authentication receiving unit is configured to receive inventory information sent by a first inventory node, and authenticate the first inventory node based on the inventory information to obtain an authentication result; wherein, the inventory information is an authentication identifier sent by a first network node to the first inventory node; secure inventory waveform information is formed based on the authentication identifier; inventory information is composed of the authentication identifier, inventory instructions, and the secure inventory waveform information; wherein, the authentication identifier is a secure tag authentication identifier for tags formed periodically based on preset rules by the tag management network element; An information overlay unit is used to overlay identification information into a specific part of the inventory information to form inventory feedback information if the authentication result indicates that the first inventory node has been authenticated. A sending unit is configured to send the inventory feedback information to the first inventory node; the first inventory node generates a cancellation carrier for the inventory feedback information based on the secure inventory waveform information; recovers the inventory feedback information based on the cancellation carrier to obtain the tag identifier of the tag and the updated tag identifier; wherein, the updated tag identifier is formed based on the preset rules for the tag identifier during the period when the tag is synchronized with the tag management network element, and the identifier information is sent to the tag management network element for authentication; the identifier information includes: the tag identifier and the updated tag identifier.
14. An electronic device, characterized in that, The method includes a memory and a processor, the memory storing a computer program executable on the processor, the processor executing the computer program to implement the steps of the method according to any one of claims 1 to 7, or to implement the steps of the method according to any one of claims 8 to 11.
15. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 7, or the steps of the method according to any one of claims 8 to 11.
Citation Information
Patent Citations
an RFID tag counting method and system for intelligent containers
CN109544065A
Label identification method and device based on deep learning, electronic equipment and storage medium
CN114662510A