A low-cost passive sensing security terminal
By using the built-in ADC and RF signals in the passive sensing terminal to generate true random numbers, combined with the enhanced SM7 encryption algorithm, the problems of high cost, large power consumption and poor security of passive sensing terminals are solved, and a passive sensing terminal with low overhead and high security are realized.
Patent Information
- Application Number
- CN202411451185.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-17
- Publication Date
- 2025-08-15
- Estimated Expiration
- 2044-10-17
AI Technical Summary
The cost, power consumption and volume of the existing passive sensing terminals to generate true random numbers is high, and the existing encryption algorithms have security risks, especially in Internet of Things applications, pseudo-random numbers are prone to the problem of unrecognized label collisions.
Using the ADC and RF signals provided by the passive sensing terminal as entropy sources, combined with sensing circuits and RF circuits, a compatible true random number generator is realized, reducing system cost and power consumption, and using an enhanced SM7 encryption algorithm based on true random numbers to improve security performance.
It realizes the generation of true random number with low overhead, reduces the cost and power consumption of passive sensing terminals, improves the security of encryption algorithms, solves the problem of label collision recognition difficulties caused by pseudo-random numbers, and enhances the security performance of passive sensing terminals.
Smart Images

Figure CN119420467B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of Internet of Things, and in particular relates to a technology for generating true random numbers. Background Art
[0002] With the widespread development of the Internet of Things (IoT), wireless passive sensor networks based on RFID technology have attracted widespread attention due to their advantages such as low power consumption, low cost, and miniaturization. However, as IoT applications continue to expand, especially in areas such as tobacco, alcohol, and tea, there is a growing concern about product authenticity. Traditional passive sensor terminal encryption algorithms often use pseudo-random numbers to encrypt data, posing security risks.
[0003] The existing passive sensor terminal architecture is as follows Figure 1 As shown, the antenna is used to receive radio frequency signals; the matching module is used for impedance matching between the antenna and subsequent circuits to achieve the maximum transmission function of the antenna receiving power; the power divider distributes the radio frequency signal received by the antenna to the rectifier circuit for energy collection and to the demodulation circuit to achieve signal demodulation function; the energy collection and management module realizes the boosting, energy storage and power supply management functions; the sensor circuit realizes the information perception function, which is the basic function of the passive sensor terminal; the processor adopts a low-power and low-cost MCU, which mainly realizes the wireless communication protocol, sensor information collection, pseudo-random number generation, encryption algorithm and other functions; the modulation circuit adopts backscattering technology to realize the passive terminal data transmission function with near zero power consumption.
[0004] Existing passive sensor terminals often use pseudo-random numbers. However, some high-security application scenarios require the generation of true random numbers and data encryption (using existing encryption algorithms). Traditional methods for generating true random numbers are shown below (A) to (D), including: (A) a noise comparison method based on thermal noise; (B) a method based on clock jitter; (C) a residual recycling method based on ADC (analog-to-digital conversion), also known as chaotic mapping; and (D) a method based on quantum effects.
[0005] (A) Method based on thermal noise comparison
[0006] Thermal noise is the most common white noise, which is caused by electronic It is caused by thermal shock, which is the result of temperature change and the basis of other noises. The circuit structure of the true random number generator based on thermal noise is as follows Figure 2 shown.
[0007] (B) Clock jitter-based method
[0008] The clock jitter-based method mainly uses a low-frequency clock to sample the output of a high-frequency oscillator. The most commonly used method is to use a D flip-flop. The low-frequency clock is used as the input clock of the D flip-flop, and the high-frequency oscillator is used as the input data of the D flip-flop. Its structure is as follows: Figure 3shown.
[0009] (C) Chaotic Circuit-Based Methods
[0010] A chaotic system refers to a deterministic system with irregular motion, uncertainty, non-repeatability, unpredictability, and extreme sensitivity to initial conditions. Chaos is an inherent characteristic of nonlinear dynamic systems and a common phenomenon in nonlinear systems. Chaotic systems can be implemented through computer systems or analog circuits. Analog circuit chaotic systems are often implemented based on ADCs. The true random number generator structure based on ADC and DAC residuals is as follows: Figure 4 shown.
[0011] (D) Methods based on quantum effects
[0012] The structure of the true random number generator based on quantum effects is as follows: Figure 5 As shown, a single photon is detected at the two output ends of a balanced beam splitter (with the same transmittance and reflectance), and a true random number can be obtained after the detected photon information is digitized.
[0013] The voltage amplitude of thermal noise is very small and requires a high-gain amplifier before it can be quantified by an ADC, or a very wide ADC, which is both costly and power-hungry. Furthermore, the amplifier's limited bandwidth reduces the randomness of the thermal noise. The entropy source circuit of a true random number generator based on clock jitter is composed of inverters, requiring a large number of inverter resources to increase the system's randomness, resulting in high power consumption and cost. True random number generators based on quantum effects require equipment that can generate and measure quantum effects, making them unsuitable for passive sensor terminals. Furthermore, all of the above methods require specialized true random number generation circuits, which are expensive and unsuitable for low-cost passive sensor terminals. Summary of the Invention
[0014] To address the high cost, power consumption, volume, and complexity of generating true random numbers in existing passive sensor terminals, the present invention proposes a low-overhead passive sensing security terminal for the first time based on the passive sensor terminal's inherent ADC (converts the analog signal output by the sensor) and radio frequency signals. The terminal is powered by radio frequency energy harvesting and uses its own sensor output signals and radio frequency signals to realize the entropy source of true random numbers. This eliminates the need to design a specialized circuit structure, thereby reducing the cost, power consumption, volume, and design complexity of the passive sensing security terminal.
[0015] The technical solution adopted by the present invention is: a low-overhead passive sensing security terminal, including: an antenna, a matching module, a power splitter, a rectifier circuit, an energy collection and management module, a sensing circuit, a processor, a modulation circuit, and a demodulation circuit;
[0016] The RF signal received by the antenna enters the power splitter after passing through the matching module;
[0017] The power divider divides the input RF signal into two paths, one of which is input to the rectifier circuit and the other is input to the demodulation circuit;
[0018] The output end of the rectifier circuit is connected to the energy collection and management module;
[0019] The energy collection and management module provides power for the demodulation circuit, sensor circuit, and processor respectively;
[0020] The processor includes an ADC, a true random number controller, an encryption module, and a memory; the sensing circuit is connected to the processor to provide a sensing entropy source; the demodulation circuit is connected to the processor to provide a radio frequency entropy source; the ADC samples the sensing entropy source and the radio frequency entropy source, and then processes the true random number controller to generate a true random number, and stores the true random number in the memory; the encryption module performs data encryption based on the true random number stored in the memory;
[0021] The modulation circuit is connected to the processor and is used to modulate the modulation signal transmitted from the processor and then transmit it to the antenna for transmission.
[0022] The demodulation circuit comprises a detector, a low-pass filter and a comparator which are connected in sequence; and a radio frequency entropy source is provided through the output of the detector.
[0023] Beneficial effects of the present invention: A low-overhead passive sensing security terminal design method proposed in the present invention can be used to solve the problems of high cost, high power consumption, and large size of passive sensing terminals. A compatible true random number generator is realized by using the ADC, sensing circuit, and radio frequency circuit of the passive sensing tag. An enhanced SM7 encryption algorithm implementation method based on true random numbers is also proposed, which can be used to improve the security performance of such encryption algorithms. In addition, the present invention can be used to improve the recognition performance of ultra-high frequency RFID anti-collision algorithms, mainly to solve the problem that massive tags implemented using pseudo-random numbers are prone to output the same random number sequence, resulting in continuous collisions and inability to be recognized. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] Figure 1 It is an existing passive sensor terminal architecture.
[0025] Figure 2 It is a true random number generator structure based on thermal noise.
[0026] Figure 3 It is a true random number generator structure based on clock jitter.
[0027] Figure 4 This is a true random number generator circuit structure based on ADC and DAC residuals.
[0028] Figure 5It is a true random number generator structure based on quantum effects.
[0029] Figure 6 It is a low-overhead passive sensing security terminal architecture.
[0030] Figure 7 A true random number generator architecture for compatibility.
[0031] Figure 8 The present invention provides a compatible true random number generator workflow based on RF signal and ADC residual.
[0032] Figure 9 This is the overall architecture diagram of the SM7 algorithm.
[0033] Figure 10 This is the flow chart of the enhanced SM7 encryption algorithm based on true random numbers. DETAILED DESCRIPTION
[0034] To facilitate those skilled in the art to understand the technical content of the present invention, the present invention is further explained below with reference to the accompanying drawings.
[0035] The low-cost passive sensing security terminal architecture proposed by the present invention is as follows Figure 6 As shown, the antenna receives the radio frequency signal; the matching module is used for impedance matching between the antenna and the subsequent circuit to realize the maximum transmission function of the antenna receiving power; the power divider distributes the radio frequency signal received by the antenna to the rectifier circuit for energy collection and to the demodulation circuit to realize the signal demodulation function; the energy collection and management module realizes the energy storage and power supply management function; the energy storage capacitor is used to store the energy collected by the energy collection and management module, and supply power to the subsequent modules through the energy collection and management circuit; the sensor circuit realizes the information perception function, which is the basic function of the passive sensing security terminal; the processor can adopt a low-power and low-cost MCU, which mainly realizes the wireless communication protocol, sensor information collection, true random number generation, enhanced encryption algorithm and other functions; the modulation circuit adopts backscattering technology to realize the passive terminal data transmission function with near zero power consumption; the true random number generator uses the existing resources of the sensor terminal to generate true random numbers; the enhanced SM7 encryption algorithm uses the generated true random numbers to improve the S transform in the encryption algorithm, thereby improving the security performance of the SM7 encryption algorithm.
[0036] The compatible true random number generator architecture proposed by the present invention is as follows Figure 7As shown, the system includes an entropy source and a processor. The entropy source includes a sensor entropy source and a radio frequency entropy source. The sensor entropy source is composed of a sensor circuit, and the radio frequency entropy source is derived from the detection output of the radio frequency transceiver circuit. The processor has a built-in ADC, which is mainly used for analog-to-digital conversion of passive sensor terminals to realize sensor data acquisition. The true random number controller uses the built-in ADC to sample the sensor entropy source and the radio frequency entropy source. The true random number controller then post-processes the sample to generate true random numbers and stores them in memory. The true random numbers in the memory can be used to further iteratively improve the randomness of the cyclic shift bits during post-processing, thereby iteratively improving the true randomness of the system.
[0037] The workflow of the compatible true random number generator based on RF signal and ADC residual is as follows: Figure 8 shown.
[0038] The compatible true random number generator based on RF signal and ADC residual works as follows:
[0039] 1. First, according to the actual application requirements, set the initial values of the variables required in the system, such as the total number of true random numbers RN required all , the number of times RN a 16-bit true random number is generated times = 0, total number of runs k = 0, total number of true random numbers generated RN sum = 0, and by setting Power to high, power the sensing circuit and sample the RF entropy source voltage to generate D RF0 , with D RF0 To offset the address, a random number is read from the memory to generate an initial random delay time t0, and the delay time t0 is 0. Initially, the random number in the memory is 0.
[0040] 2. Then use ADC to convert the sensor entropy source voltage to obtain the ADC output digital signal D affected by thermal noise sensor , judge D sensor Is it greater than the high threshold D HT Is the sum less than the lower threshold D LT , used to control whether the power is high or low, thereby controlling the charging or discharging of the sensing circuit, so that the output voltage of the sensing entropy source changes continuously. HT With D LT Explanation of the value: For example, if the power supply voltage is 2V and the corresponding ADC bit width is 8 bits, then the maximum value of the ADC output is FF, and the maximum threshold value that can be set is F0; the minimum threshold value is 0F.
[0041] 3. Further use ADC to convert the RF entropy source voltage to output digital signal by For the offset address, read a random number in the memory to generate a random delay time and delay time.
[0042] 4. Further For the offset address, read a random number in the memory to generate the cyclic shift number SBS k , D sensor Circular right shift SBS k bit Then use The lowest 4 bits generate a 4-bit true random number and set RN times =RN times +1, RN sum =RN sum +4, k=k+1.
[0043] 5. Further concatenate the 4-bit true random number with the 4-bit true random number generated in the previous iteration. If the number of true random numbers generated is RN times =4, the generated 16-bit true random number is stored in the memory and RN is set times =0.
[0044] 6. Determine the total number of true random numbers RN generated sum Whether it meets the needs, if RN sum ≥RN all , then the process of generating true random numbers ends, and all generated true random numbers are sent to the enhanced SM7 encryption algorithm, otherwise continue to step 2.
[0045] Implementation method of enhanced SM7 encryption algorithm based on true random numbers
[0046] In wireless passive RFID systems, there are multiple air interface protocol standards, among which ISO / IEC 18000-6C is currently the most widely used RFID air interface protocol. ISO / IEC 18000 uses technologies such as password authentication, access control, and transmission masking to protect tag information. However, these security measures are weak and cannot effectively protect the wireless communications of IoT sensor tags. These measures are prone to risks such as tag cloning or counterfeiting, personal privacy leakage, and information tampering.
[0047] In view of the security issues of ISO / IEC 18000, my country has proposed the GB / T 29768 protocol, which adds a two-way authentication mechanism and SM7 encryption algorithm to improve the security performance of wireless communication of passive terminals. SM7 is a commercial encryption algorithm specially designed for electronic tags and approved by the State Cryptography Administration. The overall structure of the original SM7 algorithm is as follows: Figure 9As shown, encryption or decryption function is selected according to application needs. SM7 encryption and decryption requires generating 16 sub-keys and implementing 16 F functions. The F function requires multiple S transformations, where S1, S2, S3 and S4 represent sub-transformations of S.
[0048] By performing a simple logical operation on the input data and a 16-bit true random number before the S-transform, the randomness of the S-transform output data can be improved, thereby enhancing the security performance of the SM7 encryption algorithm. The tag generates a true random number that is directly used to change the S-transform. The data collector can read the data at this address at any time for encryption and decryption operations. Each time the data collector reads, the tag regenerates a new true random number for encryption and decryption. The data collector can control the read rate to control the rate at which the tag generates true random numbers.
[0049] The overall architecture of the enhanced SM7 encryption algorithm based on true random numbers is as follows: Figure 10 As shown by Figure 10 As can be seen, the enhanced SM7 encryption algorithm is more secure than the original SM7 encryption algorithm and is fully compatible with the original SM7 encryption algorithm (when sampling logical OR operations, the all-zero true random number is compatible with the original encryption algorithm). In addition, users can select different logical operations based on different application scenarios, thereby generating completely different encrypted data with the same data, key, and true random number.
[0050] Those skilled in the art will appreciate that the embodiments described herein are intended to aid the reader in understanding the principles of the present invention, and it should be understood that the scope of the present invention is not limited to such specific descriptions and embodiments. Various modifications and variations are readily apparent to those skilled in the art. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention are intended to be included within the scope of the claims.
Claims
1. A low-cost passive sensing security terminal, characterized in that: include: Antenna, matching module, power divider, rectifier circuit, energy collection and management module, sensor circuit, processor, modulation circuit, demodulation circuit; The RF signal received by the antenna enters the power splitter after passing through the matching module; The power divider divides the input RF signal into two paths, one of which is input to the rectifier circuit and the other is input to the demodulation circuit; The output end of the rectifier circuit is connected to the energy collection and management module; The energy collection and management module provides power for the demodulation circuit, sensor circuit, and processor respectively; The processor includes an ADC, a true random number controller, an encryption module, and a memory; a sensing circuit is connected to the processor to provide a sensing entropy source; a demodulation circuit is connected to the processor to provide a radio frequency entropy source, and the demodulation circuit includes a detector, a low-pass filter, and a comparator connected in sequence; the radio frequency entropy source is provided by the output of the detector; specifically, the ADC samples the sensing entropy source and the radio frequency entropy source, and then processes them through the true random number controller to generate a true random number, and the true random number is stored in the memory; The encryption module performs data encryption based on the true random number stored in the memory; The modulation circuit is connected to the processor and is used to modulate the modulation signal transmitted from the processor and then transmit it to the antenna for transmission.
2. A low-cost passive sensing security terminal according to claim 1, characterized in that: The process of generating true random numbers is: A1. First, according to the actual application requirements, set the initial values of the variables required in the system, including: the total number of true random numbers RN all , the number of times RN a 16-bit true random number is generated times = 0, total number of runs k = 0, total number of true random numbers generated RN sum =0, and by setting Power to high, power the sensing circuit, and use ADC to sample the RF entropy source voltage to obtain the ADC output digital signal D RF0 , with D RF0 For the offset address, a random number is read from the memory to generate the initial random delay time t0, and the delay time t0 is used; A2. Use ADC to sample the sensor entropy source voltage and obtain the ADC output digital signal D affected by thermal noise. sensor , if D sensor is greater than the high threshold, the sensor circuit is controlled to discharge; if D sensor If the value is less than the lower threshold, the sensor circuit is controlled to charge; otherwise, step A3 is executed; A3. Use ADC to sample the RF entropy source voltage and obtain the ADC output digital signal by For the offset address, read a random number in the memory to generate a random delay time and delay time; A4. For the offset address, read a random number in the memory to generate the cyclic shift number SBS k , D sensor Circular right shift SBS k bit Then use The lowest 4 bits generate a 4-bit true random number and set RN times =RN times +1, RN sum =RN sum +4, k=k+1; A5. Concatenate the 4-bit true random number with the previously generated true random number. If the number of true random numbers generated is RN times =4, the generated 16-bit true random number is stored in the memory and RN is set times =0, then go to step A6; otherwise, return to step A2; A6、If RN sum ≥RN all , then the process of generating true random numbers ends, and all generated true random numbers are sent to the encryption module, otherwise continue to step A2.
3. A low-cost passive sensing security terminal according to claim 2, characterized in that: The encryption module specifically adopts the enhanced SM7 encryption algorithm.