Mutual authentication and handover authentication method between radio frequency source and device in backscatter communication
By utilizing the physical layer authentication method of identity key and session key in the backscatter communication system, combined with the channel impulse response and received signal strength, a low-computational authentication scheme is designed to solve the mutual authentication problem between the backscatter device and the RF source, enhance the security and robustness of the system, and resist various attacks.
Patent Information
- Application Number
- CN202411343908.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-25
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2044-09-25
AI Technical Summary
Backscatter communication systems lack an effective mutual authentication mechanism between RF sources and devices, and existing technologies cannot effectively defend against eavesdropping and co-location attacks, especially in low computing power and complex scenarios.
By utilizing the identity key and session key of the backscatter device, combining the channel impulse response and received signal strength for physical layer authentication, a low-computation authentication method is designed, and random signal power and encryption strategies are adopted to defend against various attacks.
It achieves high-accuracy and high-robust mutual authentication on low-computing-power devices, enhances the security and stability of the system, and can effectively resist eavesdropping, active and co-location attacks to ensure communication security.
Smart Images

Figure CN119110288B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of backscatter communications, and in particular relates to a mutual authentication and switching authentication method between a radio frequency source and equipment in backscatter communications. Background Art
[0002] Backscatter Communication (BC) is an important technology that relies on passive devices for information transmission and is a key component of the passive Internet of Things (IoT). Through energy harvesting and low-power design, it enables data collection and transmission without the need for an external power source or built-in battery, demonstrating great potential. Specifically, a backscatter device (BD) uses a received radio frequency signal or other environmental signal as a carrier. By changing the impedance of the device's antenna, the carrier signal is backscattered to the receiver at varying amplitudes, phases, or frequencies. The core advantage of this process lies in its ultra-low power consumption and low cost, making backscatter communication an ideal technology for implementing large-scale, distributed IoT devices.
[0003] Backscatter devices typically have a simple design structure, consisting primarily of a backscatter modulation module, an information receiving module, an energy harvesting module, and possibly other functional modules (such as sensors). Because of their simple structure, backscatter devices have a low manufacturing cost, but this also means that the energy and computing power of the device are limited. Such devices are generally unable to perform high-power or complex computing tasks, such as advanced cryptographic calculations. However, the low power consumption characteristics of backscatter devices enable them to be widely used in extreme environments or scenarios where regular maintenance is difficult, such as in the IoT field of smart agriculture and wearable devices. By applying backscatter communication technology, devices in these scenarios can operate for a long time without the need for frequent battery replacement, reducing maintenance costs and greatly improving system reliability.
[0004] While backscatter communication systems offer many advantages, their broadcast nature and open wireless channels also pose a variety of potential security threats. First, backscatter communication is susceptible to passive attacks, such as eavesdropping and traffic analysis. Wireless passive eavesdropping is a common threat type in backscatter communication systems. Because eavesdroppers do not actively transmit signals during attacks, these attacks are highly concealed and difficult to detect. By analyzing traffic patterns in reflected signals, eavesdroppers can potentially obtain device identity information or confidential data, thereby threatening system confidentiality. This not only compromises device identity privacy but also paves the way for more serious active attacks. Active attacks can leverage stolen identity information to forge device identities, illegally infiltrate the system, and carry out a series of subsequent attacks, such as man-in-the-middle attacks, malicious data injection, and core data theft. These attacks pose a serious threat to the overall security of the backscatter communication system, potentially leading to system failure or data loss. Therefore, ensuring the security of the backscatter communication system, particularly protecting it from eavesdropping and identity forgery attacks, is a critical prerequisite for reliable communication.
[0005] To address these security challenges, authentication technology has become an indispensable component of backscatter communication systems. The core task of authentication technology is to verify the legal identity of the device requesting access to the system, thereby establishing the first line of defense for the system. Physical layer security authentication technology is a method that uses physical layer channel characteristics to identify or locate the signal source. Compared with traditional cryptography-based authentication technologies, physical layer security authentication has a unique advantage: it relies on the device's inherent physical layer channel characteristics, which do not require additional calculations and are difficult to copy or forge. Therefore, physical layer security authentication can serve as a powerful supplement to cryptography-based identity authentication technologies. By verifying whether the received signal comes from a legitimate device, it provides strong protection for the secure communication of the backscatter communication system.
[0006] Currently, existing physical layer authentication schemes for backscatter communication systems can be divided into three categories according to the authentication objectives: authentication of the device, authentication of the RF source, and mutual authentication between the RF source and the device.
[0007] Device authentication is one of the most important research issues in backscatter communication systems. In backscatter communication, the radio frequency source (RFS), also known as the access point (AP), is an active device that can perform complex cryptographic operations or extract physical layer channel characteristics to authenticate other devices. Some such schemes leverage various physical layer characteristics to implement physical layer security authentication that can resist identity forgery attacks, but these schemes do not support device-to-RF source authentication.
[0008] Authentication of RF sources is complex for backscatter devices because they cannot measure channels or perform cryptographic operations. Therefore, physical layer authentication or cryptographic authentication cannot be used to authenticate the RF source. While some such schemes can support RF source authentication by the backscatter device, they cannot support mutual authentication between the RF source and the device.
[0009] Existing solutions that support mutual authentication between devices and RF sources require backscatter devices to measure signal strength, but this has certain limitations on application scenarios and cannot defend against eavesdropping and co-location attacks.
[0010] That is to say, although existing technologies have made some progress in the field of backscatter communication, they still have some significant shortcomings and limitations. Specifically, current technologies face the following major problems:
[0011] 1) Lack of universal mutual authentication methods: Backscatter devices, due to their simple design and limited computing power, struggle to support complex computational tasks. This makes it difficult to effectively authenticate RF sources using cryptographic methods in existing technologies. Furthermore, backscatter devices are unable to extract channel characteristics, making physical layer authentication methods ineffective. This limitation results in a lack of effective mutual authentication mechanisms between devices and RF sources in practical applications, increasing the risk of system attacks.
[0012] 2) Insufficient robustness: Existing technologies usually assume that the attacker launches the attack from a position more than half a wavelength away from the legitimate device to ensure that the attacker cannot obtain channel information that is highly correlated with the legitimate channel. However, this assumption ignores the threats of eavesdropping attacks and co-location attacks. Eavesdropping attackers can obtain sensitive information by passively monitoring the communication signals between the device and the RF source, thereby laying the foundation for subsequent active attacks (such as signal forgery, identity impersonation, etc.). Co-location attacks are more direct. When the attacker is close to the legitimate device, it is easier to obtain highly correlated channel information, thereby forging legitimate signals. These attacks may pose a serious threat to the system in actual application scenarios, but existing technologies have not yet fully considered and addressed these issues. Summary of the Invention
[0013] In order to solve the above problems existing in the prior art, the present invention provides a mutual authentication and switching authentication method between a radio frequency source and a device in backscatter communication.
[0014] The technical problem to be solved by the present invention is achieved through the following technical solutions:
[0015] The present invention provides a method for mutual authentication and switching authentication between a radio frequency source and a device in backscatter communication, comprising:
[0016] During the mutual authentication phase, the RF source uses the identity key s of the backscatter device k and session key s i , and the session information x to be sent i , by randomly adjusting the signal transmission power, generating the current round of RF source signal and sending it to the backscattering device; the identity key s k The backscatter device is generated by the server when registering with the server, and the identity key s k Sent by the server to the RF source, when the backscatter device is a device that has not been mutually authenticated with any RF source, the RF source is the RF source closest to the backscatter device as determined by the server; the session key s i The radio frequency source is based on the identity key s k Random generation;
[0017] The backscattering device calculates the received current round of radio frequency source signal y i (l+1) and the reference signal y of the RF source r The normalized cosine similarity between them is calculated, and the legitimacy of the radio frequency source is verified based on the normalized result obtained, and if it is legal, the identity key s is used to verify the legitimacy of the radio frequency source. k and the information to be sent x b Generate the encrypted current round scattering signal x bs (l+1) is sent to the RF source; the reference signal y of the RF source r It is obtained by the backscatter device through interaction with the radio frequency source before the mutual authentication stage;
[0018] The RF source receives the channel impulse response h of the last round of scattered signals. i,k (l) 2 , the channel impulse response h to the received current round of scattered signal i,k (l+1) 2 Verification is performed by using the reflection coefficient α of the backscatter device and the randomly adjusted signal transmission power used to generate the current round of RF source signal to verify the signal power of the received current round of scattering signal, and the legitimacy of the backscatter device is determined based on the verification result to complete mutual authentication; wherein, the random numbers used to generate different rounds of RF source signals are different; the reflection coefficient α, and the channel impulse response of the received previous round of scattering signal when the current round of scattering signal is the first round of scattering signal in the authentication phase, are all obtained through interaction with the backscatter device before the mutual authentication phase.
[0019] Compared with the prior art, the present invention has the following beneficial effects:
[0020] 1) Low computing requirements and high versatility: The authentication scheme of the present invention fully considers the limited computing power of the backscatter device and designs a simple and effective calculation method so that the backscatter device can authenticate the radio frequency source. This design reduces the requirements for the computing power of the device, ensures that the scheme can run smoothly on low-power and resource-constrained devices, and improves the versatility of the scheme. In contrast, existing schemes that support mutual authentication between devices and radio frequency sources require more complex computing resources, which limits their application in low-energy devices. The low-threshold computing design of the authentication scheme of the present invention makes the authentication scheme of the present invention more suitable for promotion and application in large-scale, multi-scenario IoT deployments.
[0021] 2) High-accuracy authentication mechanism: The authentication scheme of the present invention uses the channel impulse response (CIR) and received signal strength (RSS) as fingerprints of the physical layer to authenticate the legitimacy of the device. The CIR and RSS are inherent characteristics of the physical layer and are difficult to forge or tamper with, thus providing a reliable means of identity verification for backscatter devices. In addition, to further defend against replay attacks, the present invention also adopts a strategy of randomly adjusting the power of the excitation signal, making it difficult for an attacker to bypass authentication by simply replaying the signal even if they can capture a legitimate signal, thus achieving accurate authentication of the backscatter device. In addition, the present invention also uses a method of detecting the signal composition pattern to authenticate the RF source. This process not only confirms the legitimacy of the RF source, but also protects the content of the transmitted signal through encryption, preventing eavesdroppers from stealing sensitive information. This significantly enhances the system's ability to resist eavesdropping attacks, active attacks, and co-location attacks, ensures the security of the signal transmission process, reduces the risk of attack, makes the authentication process more reliable, and can significantly improve the accuracy of authentication. Compared with existing solutions that support mutual authentication between devices and radio frequency sources, which may have the risk of misjudgment and missed judgment, the authentication solution of the present invention can more effectively identify legitimate devices and radio frequency sources, reduce the error rate in the authentication process, and thus improve the overall security and stability of the system.
[0022] 3) Highly robust security protection: The authentication scheme of the present invention can not only resist a variety of active attacks such as identity forgery, replay, relay attacks, signal forgery, etc., but also effectively defend against eavesdropping and co-location attacks through key encryption. This all-round security protection design enables the system to maintain a high degree of robustness in the face of various complex attacks, ensuring the security and integrity of communications. Compared with existing solutions that support mutual authentication between devices and radio frequency sources, which have deficiencies in defending against eavesdropping and co-location attacks, the authentication scheme of the present invention further enhances the system's anti-attack capabilities through multi-level protection measures, ensuring the reliable operation of the system.
[0023] In summary, the authentication scheme of the present invention has shown obvious advantages in reducing the computing burden of devices, improving authentication accuracy, and enhancing security protection capabilities. It not only adapts to the needs of device diversity and scenario complexity in current backscatter communication systems, but also provides a more secure and reliable solution for future large-scale Internet of Things deployments.
[0024] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] Figure 1 is an architecture diagram of a backscatter communication system provided by an embodiment of the present invention;
[0026] Figure 2 This is a flow chart of a method for mutual authentication and handover authentication between a radio frequency source and a device in backscatter communication provided by an embodiment of the present invention;
[0027] Figure 3 The present invention provides a schematic diagram of the process of the registration phase, the authentication phase and the switching authentication phase in the mutual authentication and switching authentication method between the radio frequency source and the device in the backscatter communication provided by the embodiment of the present invention. DETAILED DESCRIPTION
[0028] The present invention will be further described in detail below with reference to specific examples, but the embodiments of the present invention are not limited thereto.
[0029] The present invention provides a mutual authentication and switching authentication method between a radio frequency source and a device in backscatter communication. The method is applied to a backscatter communication system including three entities such as Figure 1 The following figure shows the server, RF source, and backscatter device. The server is static and trustworthy, acting as the controller of the system. It controls the RF sources to transmit signals that stimulate communication in the backscatter devices. Multiple RF sources are evenly distributed throughout the system, with adjacent RF sources' coverage areas contiguous but non-overlapping. This allows mobile backscatter communication devices to receive signals from different RF sources within the system to support device communication. The RF source in the device's coverage area is defined as the source RF source, while the RF source into which the device enters after long-distance movement is defined as the destination RF source. RF sources are semi-trusted and follow the protocol, sending signals to specific backscatter devices in response to server instructions for feedback. Backscatter devices are distributed within the RF source's coverage area and communicate with them via backscatter.
[0030] Assuming secure communication between the server and each RF source, they can mutually authenticate and encrypt communications through complex cryptographic techniques, making it impossible for attackers to decrypt the information. In this system, RF sources and backscatter devices communicate using time division duplex (TDD) mode, with communication rounds represented by L = [1, 2, …, 1, …]. In each round of communication, the uplink and downlink channels satisfy reciprocity, and within related rounds, the channels exhibit high correlation.
[0031] Assume that the adversary has strong capabilities and can launch the following attacks:
[0032] 1) Eavesdropping attack: An attacker passively monitors the channel between the backscatter device and the RF source to perform an eavesdropping attack. The attacker intercepts the original signal between the backscatter device and the RF source and analyzes the channel status, traffic flow, and other information.
[0033] 2) Active attack: The attacker maintains a certain distance from the backscatter device or RF source (greater than half the wavelength of the signal between the backscatter device and the RF source) and attempts to pass authentication by actively injecting signals into the channel between the backscatter device and the RF source. The attacker can attempt to deceive the backscatter device or RF source through identity forgery, replay, relaying, and signal forgery. The attacker launches an identity forgery attack by modifying their identity, transmitting false messages and deceiving the recipient, thereby disguising themselves as a legitimate backscatter device or RF source. The attacker can also use eavesdropping attacks to intercept the signals between the backscatter device and the RF source and launch a replay attack by retransmitting signals from previous communication rounds, or directly forward the signals from the current round to the recipient to launch a relay attack. In addition, the attacker can analyze the signals in multiple rounds of communication and forge signals to launch signal forgery attacks.
[0034] 3) Co-location attack: An attacker approaches a legitimate backscatter device and launches an attack, aiming to deceive the RF source. Because close proximity between the attacker and the RF source makes it easily detected, we only consider scenarios where the attacker is co-located close to the backscatter device. In this scenario, the attacker can use highly correlated channels to launch identity forgery, replay, relay, and signal spoofing attacks against the RF source.
[0035] In order to solve the technical problems in the background technology, the present invention designs a method for mutual authentication and handover authentication between a radio frequency source and a device in backscatter communication. The method can include three stages:
[0036] 1) Registration phase: The device registers on the server side. After the server starts the location prediction model based on the device's location information, it helps the device negotiate a key with the RF source in the device's coverage area. The device and RF source use the negotiated key to initialize authentication during the registration phase.
[0037] 2) Authentication phase: The RF source and the device communicate normally, and the received signal is used to determine whether the signal source is a legitimate device.
[0038] 3) Handover authentication phase: After a long-distance mobile device moves from a source RF source to a destination RF source, the destination RF source determines whether the device is legitimate through a server and generates a new key. The device confirms the signal source through the received signal to complete the handover authentication.
[0039] The following describes in detail the method for mutual authentication and handover authentication between a radio frequency source and a device in backscatter communication provided by the present invention.
[0040] Figure 2 FIG is a flow chart of a mutual authentication and switching authentication method between a radio frequency source and a device in backscatter communication provided by an embodiment of the present invention, such as Figure 2 As shown, the method includes:
[0041] S101, in the mutual authentication phase, the RF source uses the identity key s of the backscattering device k and session key s i , and the session information x to be sent i , by randomly adjusting the signal transmission power, the current round of RF source signal is generated and sent to the backscattering device; the identity key s k The identity key s is generated by the server when the backscatter device registers with the server. k It is sent by the server to the RF source during the registration phase of the backscatter device. When the backscatter device is a device that has not yet mutually authenticated with any RF source, the RF source is the RF source closest to the backscatter device as determined by the server; the session key s i During the registration phase, the RF source uses the identity key s k Randomly generated.
[0042] S102, the backscattering device calculates the received current round of radio frequency source signal y i (l+1) and the reference signal y of the RF source r The normalized cosine similarity between them is used to verify the legitimacy of the RF source based on the normalized result, and if it is legal, the session key s is used to verify the legitimacy of the RF source. i and the information to be sent x b Generate the encrypted current round scattering signal x bs (l+1) is sent to the RF source; the reference signal y of the RF sourcer It is obtained by the backscatter device through communication interaction with the RF source during the registration phase.
[0043] S103, the RF source receives the channel impulse response h of the last round of scattered signals. i,k (l) 2 , the channel impulse response h to the received current round of scattered signal i,k (l+1) 2 Verification is performed by using the reflection coefficient α of the backscatter device and the randomly adjusted signal transmission power used to generate the current round of RF source signals to verify the signal power of the received current round of scattering signals. The legitimacy of the backscatter device is determined based on the verification result, and mutual authentication is completed. Among them, the random numbers used to generate different rounds of RF source signals are different. The reflection coefficient α and the channel impulse response of the previous round of scattering signals received when the current round of scattering signals is the first round of scattering signals in the authentication phase are all obtained during the registration phase through communication interaction between the RF source and the backscattering device.
[0044] Here, the above steps S101 to S103 belong to the backscattering device BD k AP with RF source i The mutual authentication phase between Figure 3 As shown, before the mutual authentication phase, the backscatter device BD k Steps to register with the server, and when the backscatter device BD k If the device has not yet performed mutual authentication with any RF source, the backscatter device BD before the mutual authentication phase k AP with RF source i The interactive steps include the following steps:
[0045] S01, Backscatter Device BD k By reflecting the environmental signal, the server sends its own identity information b k signal.
[0046] S02, the server uses the backscatter device BD k The signal sent to the backscatter device BD k Perform positioning and determine the distance from the backscatter device BD based on the positioning results k The nearest radio source AP i , and according to the second random number r k and backscatter device BD k Identity information sent b k Generate identity keys k and secretly returns it to the backscatter device BD k , the identity information B k and identity key sk Secretly sent to the RF source AP i .
[0047] Specifically, the backscatter device BD k The identity information b can be transmitted by reflecting the baseband signal transmitted by the server k Send to the server. The server receives the identity information b k Then, first, for the backscatter device BD k Generate identity keys k =f(b k ,r k ), where function f() represents a hash function, r k ∈(0,1]; Then, the backscattering device BD is detected based on the received signal strength RSS and arrival angle AoA k For positioning, assuming the server's position is L = (x0, y0), the backscatter device BD k The position is L0=(x k ,y k ), then x k =x0+dsinAoA,y k =y0+dcosAoA, where the server and the backscatter device BD k The distance between P is the power of the received signal. After the server locates the device, it starts the existing path prediction model and calculates the path prediction value based on the backscatter device BD. k Position L0 helps backscatter device BD k Determine the closest radio source AP i , the server will backscatter device BD k Identity informationb k and keys k The beamforming technology is used to secretly send the signal to the device BD. k , secretly sent to the RF source AP through cryptographic technology i , to prevent eavesdroppers from obtaining key information in this step.
[0048] S03, RF source AP i According to the identity key s k Randomly generate session key s i , and according to the identity key s k and session key s i By randomly adjusting the signal transmission power, the initial RF source signal is generated and sent to the backscattering device BD k .
[0049] Specifically, the radio frequency source AP i Received equipment BDk Identity informationb k and identity key s k Then, first use the random number r i Generate and Device BD k Session key in, stands for XOR operation; secondly, the radio source AP i Using identity keys k and session key s i Generated signal (i.e., initial RF source signal, also called baseband signal) Send to device BD k , where P i RF source AP i The maximum signal transmission power (i.e., maximum transmission power), ρ t and ρ i For two different power parameters and satisfy
[0050] S04, Backscatter Device BD k The received initial RF source signal is used as the RF source AP i The reference signal y r And save it for subsequent use in the radio source AP i Authentication, and uses the reflection coefficient α to reflect the received initial RF source signal to the RF source AP i ; Among them, the backscatter device BD k Reflected to the RF source AP i The initial RF source signal is used as the initial scattered signal.
[0051] Specifically, equipment BD k The signal received at (i.e. the initial RF source signal received) y i,k =h i,k x i,k +ω k , where h i,k Indicates device BD k AP with RF source i CIR between k Indicates device BD k Noise at the equipment BD k This signal y i,k As a radio source AP i The reference signal y r And save it for use in subsequent sessions to check the radio source AP i After that, the device BD k The signal y i,k Reflected to the RF source AP i .
[0052] S05, RF source AP i Extract the reflection coefficient α and the RF source AP from the received initial scattered signal i BD with backscatter device k The channel impulse response between the two channels is saved for subsequent backscattering of the device BD. k certification.
[0053] Specifically, the radio frequency source AP i The signal received at (i.e. the initial scattered signal received) Where α is the device BD k The reflection coefficient, I k =αh k,i ω k BD for the device k Due to the interference caused by the reflected signal, ω i It is a radio frequency source AP i The noise at . According to the channel reciprocity, h i,k =h k,i , RF source AP i From the signal y k,i Extract channel features And use this feature as device BD k Fingerprint, used for device BD in subsequent sessions k certification.
[0054] In some embodiments, the above S101 is implemented by the following steps:
[0055] S1011, RF source AP i Use the first random number r to adjust its maximum transmission power P i , get the adjusted maximum transmission power
[0056] S1012: According to the session information to be sent x i , session key s i , the first power parameter ρ t and the adjusted maximum transmission power Generate the first signal portion
[0057] S1013, according to the identity key s k , the second power parameter ρ i and the adjusted maximum transmission power Generate the second signal portion
[0058] S1014: According to the first signal part With the second signal part Generate the current round of RF source signal and send it to the backscatter device BD k .
[0059] For example, the mutual authentication phase between the RF source and the backscatter device can continue to refer to the above Figure 3 For example, the expression of the current round of RF source signal is as follows:
[0060]
[0061] Among them, x i (l+1) represents the current round of RF source signal, l+1 represents the current round, l represents the previous round, and r∈(0,1] is the RF source AP i A randomly selected random number, P i Indicates the radio source AP i The maximum transmission power.
[0062] In some embodiments, in the above S102, the backscatter device BD k The current round of RF source signal y received i (l+1) can be expressed as: Among them, h i,k (l+1) is the backscatter device BP k AP with RF source i The CIR of the current round between k Backscatter device BD k The noise at the RF source AP i The current round RF source signal y i (l+1) and RF source AP i The reference signal y r The cosine similarity e between i It can be expressed as:
[0063]
[0064] In this formula, y i Represents the above y i (l+1),y r ·y i represents y r with y i Convolution of |y i | means y i The norm of |y r |Similarly. Since the radio source AP i Possess the identity key s negotiated during the registration phase k and session key s i , so if the received signal y iFrom the RF source AP i ,y i With the reference signal y r Normalized cosine similarity between |e i | Close to 1, if the received signal comes from an unknown identity key s k and session key s i The normalized cosine similarity result of the attacker is close to 0. Therefore, the device BD k The cosine similarity normalization result can be used to determine the RF source AP using an appropriate threshold. i Whether it is legal.
[0065] In some embodiments, the step of “verifying the legitimacy of the radio frequency source based on the obtained normalization result” in S102 can be implemented by the following steps:
[0066] S1021, when the normalized result e i Greater than or equal to the preset normalization threshold δ i When the radio source is AP i Legal. For example, the normalization threshold δ is preset i Greater than or equal to 0.5 and less than or equal to 1.
[0067] S1022, when the normalized result e i Less than the preset normalization threshold δ i When the radio source is AP i Illegal.
[0068] In some embodiments, in the above S102, "according to the identity key s when legal" k and the information to be sent x b Generate the encrypted current round scattering signal x bs (l+1) is sent to the radio frequency source” can be realized as follows: using the identity key to send the information x b The encryption code is: And use the backscattering method to bs (l+1) is sent to the radio frequency source AP i .
[0069] In some embodiments, in the above S103, “the RF source receives the channel impulse response h of the last round of scattered signals” i,k (l) 2 , the channel impulse response h to the received current round of scattered signal i,k (l+1) 2Verification is performed by using the reflection coefficient α of the backscattering device and the randomly adjusted signal transmission power used to generate the current round of RF source signals to verify the signal power of the received current round of scattered signals. The legitimacy of the backscattering device is determined based on the verification results. This can be achieved by the following steps:
[0070] S1031, RF source AP i Calculate the channel impulse response h of the last round of scattered signal received i,k (l) 2 The channel impulse response h of the received current round of scattered signal i,k (l+1) 2 The distance d(l) between them.
[0071] Since the same channel has high correlation during the correlation time, the CIR during the correlation time can be expressed using a first-order Gauss-Markov process as:
[0072]
[0073] Where a is the channel correlation coefficient, which can be measured using the Yule-Walker equation and the Crame-Rao lower bound, and η is the noise. Therefore, the RF source AP in adjacent communication rounds i Measured from the same device BD k The CIR satisfies the following formula:
[0074]
[0075] in, Indicates that due to device BD k Therefore, the radio frequency source AP between adjacent communication rounds i The distance d(l) between the measured CIRs can be expressed as: Therefore, the radio frequency source AP i Available threshold δ k The relationship between the size of the backscatter device BD and the distance d(l) k the legitimacy of.
[0076] S1032, RF source AP i According to the backscatter device BD k The reflection coefficient α, and the randomly adjusted signal transmission power used to generate the current round of RF source signal Calculate the signal power and use the calculated signal power Compare with the signal power of the received current round scattered signal.
[0077] In the current round of communication, due to the radio frequency source AP i By size The signal power of the transmitted signal is thus k Under legal circumstances, the RF source AP i The size of the received backscattered signal should also be Therefore, the backscatter device BD can be determined by whether the calculated signal power is the same as the received signal power. k the legitimacy of.
[0078] S1033, when the calculated distance d(l) is less than or equal to the preset distance threshold δ k , and when the calculated signal power is the same as the signal power of the received previous round of scattered signal, it indicates that the backscattering device BD k legitimate.
[0079] S1034: When the calculated distance d(l) is greater than the preset distance threshold δ k , and / or, when the calculated signal power is different from the signal power of the received previous round of scattered signals, it indicates that the backscattering device BD k Illegal.
[0080] Through the above two verification steps, the RF source AP i The channel characteristics can be verified by Device BD k Perform authentication. i Determine the backscatter device BD k After legalization, you can use the backscatter device BD k Send and receive data to be sent.
[0081] It should be noted that during the registration phase and when communicating with the backscatter device BD k During the authentication phase, in each round of communication, the radio source AP i The random numbers used each time are randomly generated.
[0082] In actual applications, the backscatter device may move from the coverage of one RF source (source RF source) to the coverage of another RF source (destination RF source) during long-distance movement. In this case, the destination RF source does not store any information about the device before receiving the switching authentication signal from the backscatter device, and therefore cannot immediately determine whether the device is a legitimate device when the switching authentication signal arrives. As for the backscatter device, due to its limited capabilities, it is also difficult to distinguish whether the received signal comes from different RF sources. Therefore, current technology is difficult to cope with the switching authentication problem in this scenario. To address this problem, the present invention also designs a specific authentication mechanism, so that the backscatter device can smoothly complete the authentication switch between different RF sources when moving over long distances, thereby ensuring the continuity and security of communication. Specifically, in combination with the above Figure 3 The handover authentication phase in the embodiment further includes the following steps after S101 and before S102:
[0083] S201, backscatter device BD k Calculate the received current round RF source signal y i (l+1) and the reference signal y of the RF source r The cosine similarity e between (l+1) , and the received RF source signal y i (l) and the reference signal y of the RF source r The cosine similarity e between (l) When the absolute value of the similarity difference between the two is less than the preset difference threshold δ, it indicates that the backscattering device BD k Currently still in the radio source AP i coverage range, no switching authentication is required; when the similarity difference is greater than or equal to the preset difference threshold δ, it indicates that the backscatter device BD k Moved to the target radio source AP j coverage, you need to switch authentication.
[0084] S202, when switching authentication, backscatter device BD k Your own identity information k Sent to the target radio source AP j .
[0085] S203, target radio source AP j The identity information b k Send to the server.
[0086] When moving equipment BD over long distances k When the cosine similarity between the received signal and the reference signal decreases, the degree of decrease in the adjacent round exceeds the threshold device BD kIt can be realized that this result may be that it has moved to the destination radio source AP j In the coverage area, therefore, the device BD k Start the handover authentication phase. Device BD k The identity information b k Using environmental signals j Backscattered to the destination radio source AP j , RF source AP j Receive identity information b k After that, the identity information b k Send to the server.
[0087] S204: The server sends a signal to the target radio source AP. j Authentication is performed and the identity key s is sent after the authentication is passed k Secretly sent to the target radio source AP j .
[0088] The server can authenticate the RF source AP through a cryptographic algorithm j And confirm the RF source AP through path prediction j Device BD in the overlay domain k After the authentication is passed, the server will send the identity key s k Secretly sent to the target radio source AP j .
[0089] S205, backscatter device BD k and the target radio source AP j Communicate with each other to make the target radio source AP j Backscatter device BD k Generate a new session key s j And obtain the reflection coefficient α, target RF source AP j BD with backscatter device k The channel impulse response between the backscatter device BD k Store the target radio source AP j The reference signal y′ r .
[0090] Specifically, the radio frequency source AP j Using a randomly selected random number r j Generate a new session key Then, the radio source AP j Using identity keys k and session key s j Generate a signal And send it to the device BD k . Equipment BD kThe radio frequency source AP can be detected by recalculating the absolute value of the cosine similarity difference and comparing the recalculated absolute value with the preset difference threshold. j After the authentication is passed, the reference signal y of the RF source stored in itself is sent to r Update to the target radio source AP j The reference signal y′ r And backscatter the signal. RF source AP j Received equipment BD k The reflected signal is extracted and saved in device BD k Channel characteristics Used for subsequent mutual authentication. Specifically, device BD k Get the target radio source AP j The reference signal y′ r , and RF source AP j Get device BD k Channel characteristics The principle is the same as that of S03 to S05 above, and will not be repeated here.
[0091] S206, target radio source AP j BD with backscatter device k Based on the data obtained in mutual communication, the mutual authentication phase is entered to complete mutual authentication.
[0092] Specifically, the target radio source AP j and backscatter device BD k The specific principle of the mutual authentication phase is related to the RF source AP i and backscatter device BD k The principle of the mutual authentication phase is the same as that of the Authentication Phase and will not be repeated here.
[0093] Clearly, the handover authentication solution provided by the present invention can address the need for seamless handover between different RF sources for long-distance mobile devices. The server plays a key role in the process of a device moving from a source RF source to a target RF source. By supporting key negotiation and key updates, the device can quickly complete authentication and continue secure communication after entering the coverage area of the new RF source. This solution not only ensures the communication security between the device and the target RF source during the handover process, but also ensures that subsequent communication processes can continue to use the updated key for encrypted transmission, further improving the security of the overall system.
[0094] In summary, the present invention mainly solves the following key technical problems:
[0095] First, the present invention solves the problem of mutual authentication between backscatter devices and radio frequency sources. In a backscatter communication system, the radio frequency source typically has strong computing power and can authenticate other devices through upper-layer authentication schemes based on cryptography or physical layer authentication schemes based on physical channels. However, due to its simple design, backscatter devices cannot support complex cryptographic operations and cannot even measure channel parameters, which makes mutual authentication between the device and the radio frequency source extremely difficult. Existing technologies have failed to effectively solve this problem. However, the present invention, by utilizing the unique characteristics of physical layer signals, enables the backscatter device to effectively authenticate with the radio frequency source, thereby improving the overall security of the system.
[0096] Secondly, the present invention also solves the problem of switching authentication between different RF sources for backscatter devices that move over long distances. In actual applications, the backscatter device may move from the coverage of one RF source (source RF source) to the coverage of another RF source (destination RF source) during long-distance movement. In this case, the destination RF source does not store any information about the device before receiving the switching authentication signal from the backscatter device, and therefore cannot immediately determine whether the device is a legitimate device when the switching authentication signal arrives. For the backscatter device, due to its limited capabilities, it is also difficult to distinguish whether the received signal comes from different RF sources. Therefore, current technology is difficult to cope with the switching authentication problem in this scenario. The present invention designs a specific authentication mechanism so that the device can smoothly complete authentication switching between different RF sources when moving over long distances, thereby ensuring the continuity and security of communication.
[0097] Furthermore, the present invention specifically addresses the robustness of the authentication process. Current physical layer authentication schemes based on physical layer features typically assume that the distance between the adversary and the legitimate device is greater than half a wavelength of the signal. This prevents the adversary from observing a high correlation between the channel and the legitimate device, thereby preventing the adversary from forging physical layer features that would allow authentication. However, in practical applications, adversaries can flexibly choose their attack methods, and the success rate of attacks is significantly increased when the adversary is in close proximity to the device. Therefore, defending against co-location attacks has become a pressing issue. To address such attacks, the present invention designs a highly robust authentication scheme that ensures authentication reliability even when the adversary is in close proximity, effectively defending against co-location attacks. Furthermore, the present invention also considers the issue of defending against eavesdropping attackers. Existing authentication schemes generally fail to adequately address eavesdropping attacks because eavesdropping attacks are concealed and difficult to detect, often serving as a prelude to more serious active attacks (such as identity forgery, replay, relay, and signal forgery). Attackers eavesdrop and analyze the signal characteristics between the device and the RF source, using this information to forge signals and launch attacks. Therefore, in order to ensure the high robustness of the authentication scheme, the present invention pays special attention to the defense against eavesdropping attacks during the design process, so that the system can effectively respond to eavesdropping attacks, further improving the overall security.
[0098] In summary, the present invention solves the problems of mutual authentication between devices and radio frequency sources in backscatter communication systems, switching authentication of long-distance mobile devices, and robustness of the authentication process. This solution effectively improves the security of the backscatter communication system. With the increasing expansion of Internet of Things applications, it is crucial to ensure the security and reliability of communication equipment in various complex environments. The proposal of the present invention not only fills the gap in the existing technology in terms of technology, but also provides a solid foundation for the further development of backscatter communication technology. In the future, with the further development of Internet of Things technology, the application scenarios of backscatter communication systems will become more diversified and complex. Therefore, it is necessary to continue to explore and improve the physical layer-based security authentication mechanism to cope with the increasing security challenges and ensure the security and reliability of the backscatter communication system in different application scenarios.
[0099] The present invention also provides a medical information system, comprising: an implantable medical device as a backscattering device, a hospital management end as a server, and different department medical devices as different radio frequency sources, wherein the backscattering device and the radio frequency source use the above-mentioned method for mutual authentication; wherein, before each mutual authentication, the hospital management end is used to use the department medical device currently to be used as the department medical device that currently needs to be mutually authenticated with the implantable medical device according to the patient's treatment plan, and the implantable medical device is used to measure the patient's clinical data or to control the release of drugs and, after mutual authentication with the corresponding department medical device, sends the measured clinical data to the department medical device or controls the release of drugs according to the control instructions of the department medical device. Accordingly, the medical device is used to treat the patient or assist the doctor in treating the patient; when the implantable medical device needs to register and mutually authenticate with the next department medical device, the hospital management end is also used to verify the implantable medical device and, after the verification is passed, secretly sends the identity key of the implantable medical device to the next department medical device, so that the next department medical device and the implantable medical device can be mutually authenticated.
[0100] Specifically, embedded medical devices can act as sensors to measure clinical data such as a patient's blood pressure and heart rate, and provide feedback to hospital medical equipment to assist doctors in making clinical decisions. They can also act as medication controllers, controlling the timing and concentration of drug release under the control of external medical equipment to aid patient recovery. Because medical devices are closely linked to patients' private data and can impact treatment outcomes and even their lives, protecting the communication security between implantable medical devices and external medical equipment is crucial for protecting patients' lives.
[0101] In the field of implantable medical devices, the solution proposed in this invention involves the registration phase, the authentication phase, and the switching authentication phase, which can provide all-round security protection for the implantable medical device system. The registration phase can protect against unregistered implantable medical devices from entering the system; the authentication phase supports mutual authentication between the implantable medical device and external devices, preventing the theft of private information in the implantable medical device and preventing the external device from receiving false information; the implantable medical device moves with the human body, and if the patient requires joint treatment in different departments, the switching authentication phase can support the implantable medical device to switch authentication between external devices in different departments, ensuring secure communication between the implantable medical device and external devices in different departments.
[0102] For example, the operation process of this implementation case includes three parts:
[0103] 1) Registration phase: The implantable medical device is registered with the hospital management end, which generates an identity key for the implantable medical device. Since the departments required to treat the patient can be determined by the treatment plan, the hospital management end does not need to perform path prediction analysis on the implantable medical device. After the identity key is generated, the medical device in the department where the patient first receives treatment serves as the source RF source of the implantable medical device. The hospital management end transmits the identity key to the medical device serving as the source RF source using a cryptographic encryption method. The medical device generates a session key based on the identity key, and uses the identity key and session key to generate a reference signal and send it to the registered implantable medical device. The physical layer characteristics of the device's reflected signal are recorded to complete the registration.
[0104] 2) Authentication phase: The implantable medical device formally communicates with the medical device serving as the source RF source to obtain patient health information or perform treatment. In each round of communication, both the implantable medical device and the medical device verify the received signal and authenticate the sender of the signal.
[0105] 3) Switching authentication phase: When a patient completes treatment in the current department and goes to the next department for treatment, the hospital management end verifies the patient through the patient's identity information and registration information, thereby verifying the implanted medical device. The hospital management end then sends the identity key of the implanted medical device to the medical device in the department waiting for treatment using a password encryption method. The medical device acts as the destination RF source and performs switching authentication with the implanted medical device. The medical device, acting as the destination RF source, generates a new session key based on the identity key, and uses the identity key and the new session key to generate a reference signal and send it to the registered implanted medical device. The physical layer characteristics of the device's reflected signal are recorded to complete the switching authentication. After switching authentication, the implanted medical device and the medical device, acting as the destination RF source, can formally communicate.
[0106] The present invention also provides an intelligent drug management system, comprising: a drug tag as a backscattering device, a pharmaceutical factory management device as a server for producing drugs with drug tags, and devices of different operators or users who need to purchase or count drugs as different radio frequency sources; the backscattering device and the radio frequency source are registered and mutually authenticated using the above-mentioned method; the process of mutual authentication between the drug tag and a device is the process of counting drugs or the process of buying and selling management; when a pharmaceutical factory or operator or user currently holds drugs, and a purchaser or counter needs to purchase or count drugs from the pharmaceutical factory or operator or user currently holding the drugs, the pharmaceutical factory or operator or user currently holding the drugs secretly sends the identity key of the drug tag of the drug to the device of the purchaser or counter through its own device, so that the device of the purchaser or counter and the drug tag carried by the drug are mutually authenticated to realize the purchase management or counting of drugs.
[0107] Backscatter communication devices can be attached to medications as tags, helping pharmaceutical manufacturers, distributors, hospitals, and pharmacies implement intelligent drug management. This allows for full traceability throughout the entire drug production and distribution process, preventing the circulation of counterfeit drugs and protecting the rights and interests of pharmaceutical manufacturers, hospitals, pharmacies, and their customers. It also prevents malicious third parties from accessing information on drug labels and counterfeiting them.
[0108] The proposed solution, applied in the field of intelligent drug management devices, involves registration, authentication, and handover authentication phases, providing comprehensive security protection for intelligent drug management systems. The registration phase prevents unregistered drugs from entering the system; the authentication phase supports mutual authentication and identification between drugs and management devices; and the handover authentication phase allows drugs to be transferred and authenticated between scanning devices in pharmaceutical factories, hospitals, and pharmacies, ensuring traceability of the drug distribution process, as drugs can move during circulation. This method can also serve as proof of drug authenticity in the event of a dispute.
[0109] For example, the operation process of this implementation case includes three parts:
[0110] 1) Registration Phase: After the drug is manufactured, a backscatter tag is attached, and the pharmaceutical factory's management equipment generates an identity key for it. Since the drug's circulation can be determined through purchase records at hospitals or pharmacies, the pharmaceutical factory's management equipment does not need to perform path prediction analysis on the tag. After the identity key is generated, the management end of the drug purchaser (distributor, etc.) serves as the tag's source RF source. The pharmaceutical factory can send the identity key to the management end, which serves as the source RF source, through other confidential means. After the management end generates a session key, it uses the identity key and session key to generate a reference signal, sends it to the tag, and records the tag's characteristics, completing the registration.
[0111] 2) Authentication phase: The tag device formally communicates with the management end device as the source RF source for management such as drug inventory or purchase and sale. In each round of communication, the tag device and the management end as the source RF source verify the received signal and authenticate the sender of the signal.
[0112] 3) Handover Authentication: After a drug transaction is completed, the distributor can provide the device's identity key and the corresponding drug to the buyer through the purchase record. The buyer's management terminal then uses the tag device's identity key to generate a new session key. It then uses this combination to generate a reference signal and sends it to the tag device. The physical layer characteristics of the device's reflected signal are recorded to complete handover authentication. After handover authentication, the tag device and the buyer's management terminal can formally communicate for drug inventory or sales.
[0113] It should be noted that the terms "first" and "second" are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the number of technical features indicated. Therefore, features defined as "first" or "second" may explicitly or implicitly include one or more features. In the description of the present invention, "plurality" means two or more, unless otherwise specifically defined.
[0114] In the description of this specification, the reference terms "one embodiment," "some embodiments," "example," "specific example," or "some examples" mean that the specific features or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features or characteristics described can be combined in any suitable manner in any one or more embodiments or examples. In addition, those skilled in the art can combine and combine different embodiments or examples described in this specification.
[0115] In the specification, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple situations. Certain measures are recorded in different embodiments, but this does not mean that these measures cannot be combined to produce good results.
[0116] The above is a further detailed description of the present invention in conjunction with specific preferred embodiments, and the specific implementation of the present invention should not be considered to be limited to these descriptions. For those skilled in the art of the present invention, without departing from the concept of the present invention, several simple deductions or substitutions can be made, which should be considered to fall within the scope of protection of the present invention.
Claims
1. A method for mutual authentication and handover authentication between a radio frequency source and a device in backscatter communication, characterized in that: include: During the mutual authentication phase, the RF source uses the identity key of the backscatter device and session key , and session information to be sent , by randomly adjusting the signal transmission power, generating the current round of RF source signal and sending it to the backscattering device; the identity key The backscatter device is generated by the server when registering with the server, and the identity key Sent by the server to the RF source, when the backscatter device is a device that has not been mutually authenticated with any RF source, the RF source is the RF source closest to the backscatter device as determined by the server; the session key The radio frequency source is based on the identity key Random generation; The backscattering device calculates the received current round of RF source signal The reference signal with the RF source The normalized cosine similarity between the two is used to verify the legitimacy of the radio frequency source based on the normalized result obtained, and if it is legal, the identity key is used to verify the legitimacy of the radio frequency source. and messages to be sent Generate encrypted current round scattering signal Sent to the RF source; a reference signal of the RF source It is obtained by the backscatter device through interaction with the radio frequency source before the mutual authentication stage; The RF source receives the channel impulse response of the last round of scattered signals. , the channel impulse response to the received current round of scattered signal To verify, the reflection coefficient of the backscattering device is used and the randomly adjusted signal transmission power used to generate the current round of RF source signal, verify the signal power of the received current round of scattered signal, determine the legitimacy of the backscattering device according to the verification result, and complete mutual authentication; wherein the random numbers used to generate different rounds of RF source signals are different; the reflection coefficient , and when the current round of scattered signals is the first round of scattered signals in the authentication phase, the channel impulse response of the received previous round of scattered signals is obtained through interaction with the backscattering device before the mutual authentication phase, Indicates the current round, Indicates the previous round.
2. The mutual authentication and handover authentication method between a radio frequency source and a device in backscatter communication according to claim 1, characterized in that: The RF source utilizes the identity key of the backscatter device and session key , and session information to be sent , by randomly adjusting the signal transmission power, generating the current round of RF source signal and sending it to the backscattering device, including: The radio frequency source uses the first random number to adjust its own maximum transmission power to obtain an adjusted maximum transmission power; According to the session information to be sent , the session key , the first power parameter and the adjusted maximum transmission power, generating a first signal part; According to the identity key , the second power parameter and the adjusted maximum transmission power, generating a second signal portion; The current round radio frequency source signal is generated according to the first signal part and the second signal part and sent to the backscattering device.
3. The mutual authentication and handover authentication method between a radio frequency source and a device in backscatter communication according to claim 2, characterized in that: The expression of the current round RF source signal is as follows: ; in, represents the current round of RF source signal, represents the first random number, Indicates the maximum transmission power of the RF source.
4. The mutual authentication and handover authentication method between a radio frequency source and a device in backscatter communication according to claim 1, characterized in that: The verifying the legitimacy of the radio frequency source based on the obtained normalization result includes: When the normalization result is greater than or equal to a preset normalization threshold, it indicates that the radio frequency source is legal; the preset normalization threshold is greater than or equal to 0.5 and less than or equal to 1; When the normalization result is less than the preset normalization threshold, it indicates that the radio frequency source is illegal.
5. The mutual authentication and handover authentication method between a radio frequency source and a device in backscatter communication according to claim 1, characterized in that: The RF source receives the channel impulse response of the last round of scattered signals. , the channel impulse response to the received current round of scattered signal To verify, the reflection coefficient of the backscattering device is used and generating the randomly adjusted signal transmission power of the current round of RF source signal, and verifying the signal power of the received current round of scattered signal, including: The RF source calculates the channel impulse response of the last round of scattered signals received The channel impulse response of the received current round of scattered signal The distance between ; The radio frequency source is based on the reflection coefficient of the backscattering device , and for generating the randomly adjusted signal transmission power of the current round RF source signal, calculating the signal power, and comparing the calculated signal power with the signal power of the received current round scattered signal.
6. The mutual authentication and handover authentication method between a radio frequency source and a device in backscatter communication according to claim 5, characterized in that: Determining the legitimacy of the backscatter device according to the verification result includes: When the calculated distance When the calculated signal power is less than or equal to a preset distance threshold and the signal power of the received previous round of scattered signals is the same, it indicates that the backscattering device is legitimate; When the calculated distance When the calculated signal power is greater than a preset distance threshold, and / or the calculated signal power is different from the signal power of the received previous round of scattered signals, it indicates that the backscattering device is illegal.
7. The mutual authentication and handover authentication method between a radio frequency source and a device in backscatter communication according to claim 1, characterized in that: The step of registering the backscatter device with the server and, when the backscatter device is a device that has not yet been mutually authenticated with any radio frequency source, the step of interacting with the radio frequency source before the mutual authentication phase comprises the following steps: The backscatter device sends its own identity information to the server by reflecting the environmental signal signal; The server locates the backscatter device according to the signal sent by the backscatter device, determines the radio frequency source closest to the backscatter device according to the positioning result, and locates the backscatter device according to the second random number and the identity information. Generate the identity key And secretly return it to the backscatter device, and the identity information and the identity key secretly sending it to the radio frequency source; The radio frequency source is based on the identity key Randomly generate the session key , and according to the identity key and the session key , by randomly adjusting the signal transmission power, generating an initial radio frequency source signal and sending it to the backscattering device; The backscatter device uses the received initial RF source signal as the reference signal of the RF source And save it for subsequent authentication of the radio frequency source, and use the reflection coefficient Reflecting the received initial RF source signal to the RF source; wherein the initial RF source signal reflected by the backscattering device to the RF source is used as the initial scattered signal; The RF source extracts the reflection coefficient from the received initial scattered signal The channel impulse response between the radio frequency source and the backscatter device is obtained and stored for subsequent authentication of the backscatter device.
8. The mutual authentication and handover authentication method between a radio frequency source and a device in backscatter communication according to claim 1, characterized in that: The backscatter device calculates the current round of RF source signal received The reference signal with the RF source Before determining the normalized cosine similarity between the two, the method further comprises: The backscattering device calculates the received current round of RF source signal The reference signal with the RF source The cosine similarity between the two, and the last round of RF source signal received The reference signal with the RF source and an absolute value of the similarity difference between the cosine similarities between the two, and when the absolute value is less than a preset difference threshold, it indicates that the backscatter device is still in the coverage of the radio frequency source and does not need to switch authentication; when the absolute value is greater than or equal to the preset difference threshold, it indicates that the backscatter device has moved to the coverage of the target radio frequency source and needs to switch authentication; When switching authentication, the backscatter device sends its own identity information Sending to the target radio frequency source; The target radio frequency source transmits the identity information Sending to the server; The server authenticates the target radio frequency source and sends the identity key to the target radio frequency source after the authentication is passed. secretly sending it to the target radio frequency source; The backscatter device communicates with the target radio frequency source so that the target radio frequency source generates a new session key for the backscatter device and obtains the reflection coefficient , a channel impulse response between the target RF source and the backscatter device, and so that the backscatter device stores a reference signal of the target RF source; The target radio frequency source and the backscattering device enter the mutual authentication phase according to the data obtained in the mutual communication and complete the mutual authentication.
9. The mutual authentication and handover authentication method between a radio frequency source and a device in backscatter communication according to claim 1, characterized in that: The backscatter device is an implantable medical device, the server is a hospital management end, and different radio frequency sources are different department medical devices; wherein, before each mutual authentication, the hospital management end is used to use the department medical device currently needed as the department medical device that currently needs to be mutually authenticated with the implantable medical device according to the patient's treatment plan, and the implantable medical device is used to measure the patient's clinical data or to control the release of drugs and after mutual authentication with the corresponding department medical device, the measured clinical data is sent to the department medical device or the release of drugs is controlled according to the control instructions of the department medical device. Accordingly, the medical device is used to treat the patient or assist the doctor in treating the patient; when the implantable medical device needs to be mutually authenticated with the next department medical device, the hospital management end is also used to verify the implantable medical device and, after the verification is passed, secretly send the identity key of the implantable medical device to the next department medical device, so that the next department medical device and the implantable medical device can be mutually authenticated.
10. The mutual authentication and handover authentication method between a radio frequency source and a device in backscatter communication according to claim 1, characterized in that: The backscatter device is a drug tag, the server is a pharmaceutical factory management device for producing drugs with the drug tags, and different radio frequency sources are devices of different operators or users who need to purchase or count the drugs; wherein, the process of mutual authentication between the drug tag and a device is the process of counting the drugs or the process of buying and selling management; and, when a pharmaceutical factory or operator or user currently holds the drugs, and a purchaser or counter needs to purchase or count the drugs from the pharmaceutical factory or operator or user currently holding the drugs, the pharmaceutical factory or operator or user currently holding the drugs secretly sends the identity key of the drug tag of the drugs to the device of the purchaser or counter through its own device, so that the device of the purchaser or counter and the drug tag carried by the drugs are mutually authenticated to realize the purchase management or counting of the drugs.
Citation Information
Patent Citations
Device authentication in backscatter communication systems
CN117397269A
Safety identification method in radio frequency distinguishing system
CN1932835A