An RFID electronic tag data issuing system and method
By generating tag keys using a cryptographic machine and combining key dispersion factors, upper-computer transmission and tag reader decryption, and dual integrity verification, the problem of data leakage and tampering during the issuance of RFID electronic tag data is solved, achieving high-security and integrity data writing.
Patent Information
- Application Number
- CN202411473938.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-22
- Publication Date
- 2026-02-27
- Estimated Expiration
- 2044-10-22
AI Technical Summary
Existing RFID electronic tags are at risk of data leakage and illegal tampering during the data issuance process, especially during key data transmission and writing, where existing technologies cannot guarantee data security and integrity.
A cryptographic machine is used to generate the tag issuance key and generate the tag key ciphertext based on the key dispersion factor. The key ciphertext and data information are transmitted to the tag reader via a host computer. When the tag reader meets the preset rules, it decrypts and writes the data into the tag key area. The tag issuance module and the verification module perform dual integrity verification to ensure the security and integrity of the data.
It effectively prevents the leakage of key data during transmission and ensures that the data cannot be illegally tampered with after writing through double integrity verification, thus guaranteeing the high security of RFID electronic tags and the security of personalized data issuance.
Smart Images

Figure CN119443136B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of radio frequency identification technology, and in particular to an RFID electronic tag data issuing system and method. BACKGROUND
[0002] RFID is the abbreviation of Radio Frequency Identification. RFID electronic tags store electronic identification codes and other application information in chips as carriers and can communicate wirelessly through RFID readers. At present, RFID electronic tags have been applied in shopping, logistics and other fields, providing great convenience for life and work. In the actual use of tags, there are many needs to write personalized data into tags, and some application fields of tags have high requirements for the security of tags. In the prior art, the security protection of tag data is usually performed by issuing data to tag readers and then writing the data into electronic tags. Therefore, key data can be easily intercepted in the production link through a computer port monitoring tool, causing leakage, and there is a risk of illegal tampering with the data. SUMMARY
[0003] Therefore, the present application provides an RFID electronic tag data issuing system and method, which can prevent the data stored in the electronic tag from being illegally tampered with, and ensure the security of writing high-security electronic tag key data and issuing personalized data.
[0004] According to an aspect of the present application, an RFID electronic tag data issuing system is provided, which comprises a password machine, an upper computer, a tag reader / writer, a target RFID electronic tag, a tag issuing module, and a tag verification module.
[0005] The password machine is configured to generate a tag key ciphertext based on a tag issuing key in the password machine and a key dispersion factor transmitted by a password machine interface.
[0006] The upper computer is configured to obtain corresponding issuing data information from a preset database based on a tag issuing requirement, and transmit the tag key ciphertext, the issuing data information, and a preconfigured write instruction to the tag reader / writer through a serial port.
[0007] The tag reader / writer is configured to, when the write instruction meets a preset first rule, decrypt the tag key ciphertext based on a preconfigured decryption key to obtain a decryption result, write the decryption result into a tag key area of the RFID electronic tag, and based on a preset second rule corresponding to the write instruction, write the issuing data information into a user area of the RFID electronic tag after the security authentication of the decryption result is passed, to obtain a target RFID electronic tag after data writing.
[0008] The host computer is further configured to, after receiving the data writing completion instruction, call a label issuing station interface and a label inspection station interface, and transmit the issued data information and the decryption result written in the target RFID electronic tag to a label issuing module and a label inspection module;
[0009] The label issuing module is configured to perform a first integrity inspection on the issued data information and the decryption result written in the target RFID electronic tag based on a label issuing inspection library.
[0010] The label inspection module is configured to perform a second integrity inspection on the issued data information and the decryption result written in the target RFID electronic tag based on a label inspection inspection library, and determine an issuing result based on the first integrity inspection and the second integrity inspection.
[0011] According to another aspect of the present application, the present application further provides an RFID electronic tag data issuing method, which comprises:
[0012] The RFID electronic tag data issuing method comprises:
[0013] The cryptographic machine generates a label key ciphertext based on a label issuing key in the cryptographic machine and a key dispersion factor transmitted by the cryptographic machine interface;
[0014] The host computer acquires corresponding issuing data information from a preset database based on a label issuing requirement, and transmits the label key ciphertext, the issuing data information, and a preconfigured write instruction to the label reader / writer through a serial port;
[0015] The label reader / writer decrypts the label key ciphertext based on a preconfigured decryption key to obtain a decryption result when the write instruction meets a preset first rule, writes the decryption result into a label key area of the RFID electronic tag, and writes the issuing data information into a user area of the RFID electronic tag based on a preset second rule corresponding to the write instruction after the security authentication of the decryption result is passed, to obtain a target RFID electronic tag after data writing.
[0016] The host computer is further configured to, after receiving the data writing completion instruction, call a label issuing station interface and a label inspection station interface, and transmit the issued data information and the decryption result written in the target RFID electronic tag to a label issuing module and a label inspection module;
[0017] The label issuing module is configured to perform a first integrity inspection on the issued data information and the decryption result written in the target RFID electronic tag based on a label issuing inspection library.
[0018] The label inspection module performs a second integrity inspection on the issued data information and the decryption result in the target RFID electronic tag after writing based on a label inspection inspection library, and determines an issuing result based on the first integrity inspection and the second integrity inspection.
[0019] The technical scheme of the embodiment of the present application uses the cryptographic machine to generate a label issuing key, generates a label key ciphertext based on the label issuing key and a key dispersion factor, and can prevent leakage in the key transmission process. The host computer is used to obtain issuing data information from a preset database and obtain the label key ciphertext, and sends the label key ciphertext, the issuing data information and a write instruction to the label reader / writer. The label reader / writer is used to decrypt the label key ciphertext based on a decryption key to write the label key region when the write instruction meets a preset first rule, and write the issuing data information to the user region based on a preset second rule after security authentication, so that the key data of the electronic tag cannot be easily cracked even if it is intercepted by a port monitoring tool. The first integrity inspection is performed by the label issuing module, the second integrity inspection is performed by the label inspection module, and the issuing result is determined based on the first integrity inspection and the second integrity inspection, so that the data stored in the electronic tag cannot be illegally tampered with, and the security of the high-security electronic tag key data writing and personalized data issuing is ensured.
[0020] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS
[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the embodiment description. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can also be obtained by those skilled in the art without creative labor.
[0022] Figure 1 A structural schematic diagram of an RFID electronic tag data issuing system provided by an embodiment of the present application is shown in the figure.
[0023] Figure 2 A structural schematic diagram of another RFID electronic tag data issuing system provided by an embodiment of the present application is shown in the figure.
[0024] Figure 3 A structural schematic diagram of still another RFID electronic tag data issuing system provided by an embodiment of the present application is shown in the figure.
[0025] Figure 4A flowchart of a tag key issuing process of an RFID electronic tag is provided for an embodiment of the present application.
[0026] Figure 5 A flowchart of an RFID electronic tag data issuing method is provided for an embodiment of the present application. DETAILED DESCRIPTION
[0027] In order to make the personnel in the technical field better understand the present application scheme, the technical scheme in the embodiments of the present application will be described clearly and completely below in combination with the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by the person of ordinary skill in the art without making creative labor should belong to the protection scope of the present application.
[0028] It should be noted that the terms “first”, “second” and the like in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or a chronological sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms “include” and “have” and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0029] In an embodiment, Figure 1 A structural diagram of an RFID electronic tag data issuing system is provided for an embodiment of the present application, and the present embodiment can be applied to the case of writing and issuing data to the RFID electronic tag.
[0030] As Figure 1 shown, the RFID electronic tag data issuing system in the present embodiment includes the following specific steps:
[0031] The RFID electronic tag data issuing system includes a password machine 110, a host computer 120, a tag reader / writer 130, a target RFID electronic tag 140, a tag issuing module 150, and a tag verification module 160.
[0032] The password machine 110 is configured to generate a tag key ciphertext based on a tag issuing key in the password machine and a key dispersion factor transmitted by the password machine interface.
[0033] The host computer 120 is configured to acquire corresponding issuing data information from a preset database based on a label issuing demand, and transmit the label key ciphertext, the issuing data information and a preconfigured write instruction to the label reader / writer 130 through a serial port;
[0034] The label reader / writer 130 is configured to, when the write instruction meets a preset first rule, decrypt the label key ciphertext based on a preconfigured decryption key to obtain a decryption result, write the decryption result into a label key area of the RFID electronic label, and based on a preset second rule corresponding to the write instruction, write the issuing data information into a user area of the RFID electronic label after the security authentication of the decryption result is passed, to obtain a target RFID electronic label 140 after data writing.
[0035] The host computer 120 is further configured to, after receiving a data writing completion instruction, call a label issuing station interface and a label inspection station interface, and transmit the issuing data information and the decryption result written in the target RFID electronic label 140 to the label issuing module 150 and the label inspection module 160 for inspection.
[0036] The label issuing module 150 is configured to perform a first integrity inspection on the issuing data information and the decryption result written in the target RFID electronic label 140 based on a label issuing inspection library.
[0037] The label inspection module 160 is configured to perform a second integrity inspection on the issuing data information and the decryption result written in the target RFID electronic label 140 based on a label inspection inspection library, and determine an issuing result based on the first integrity inspection and the second integrity inspection.
[0038] The label issuing key can be understood as a label issuing key of the RFID electronic label generated by the cryptographic machine when receiving a key generation instruction, and the label issuing key includes an issuing root key and a protection key. The key dispersion factor is a dispersion factor generated based on a unique identification code of the RFID electronic label or a self-defined identification code accessed by a third-party software, and can be used to generate the label key ciphertext. The target RFID electronic label is a high-security RFID electronic label obtained after the issuing data information and the label key ciphertext are written.
[0039] In the embodiment, the password machine 110 is connected with the host computer 120 through TCP / IP protocol, and is used to generate a label issuing key randomly or according to a specified mode according to a label issuing instruction of the RFID electronic tag 110 issued by the host computer 120, and generate a label key ciphertext based on the label issuing key and a key dispersion factor. It can be understood that the host computer 120 calls a key derivation interface of the password machine, and the password machine 110 generates a label key KeyT by using a label issuing root key KeyR and a preconfigured key dispersion factor, encrypts KeyT by using a protection key KeyP to generate a label key ciphertext KeyTEnc, and then obtains the label key ciphertext KeyTEnc through the key derivation interface. Specifically, the process of generating the label key ciphertext based on the label issuing key and the preconfigured key dispersion factor can include: dispersing the root key in the label issuing key by using the preconfigured key dispersion factor to generate a label key, and encrypting the label key by using the protection key in the label issuing key to generate the label key ciphertext. It should be noted that the protection key corresponding to each RFID electronic tag is different, and in order to ensure security, the label issuing root key KeyR is dispersed by using the key dispersion factor to generate the label key KeyT.
[0040] In the embodiment, the preset database and the host computer 120 communicate through a preset WebService interface, wherein the preset WebService interface at least includes: an order number taking interface, a configuration information downloading interface, an issuing library downloading interface, a verification library downloading interface, a production state updating interface, and a label backtracking interface. Thus, the corresponding issuing data information can be obtained from the preset database based on the label issuing requirement of the RFID electronic tag, wherein the issuing data information at least includes: a DLL dependent library, order asset number data, individualized data, and device configuration information. The individualized data is the individualized data required to be written according to the user requirement. The DLL dependent library at least includes: a label issuing dependent library, a label issuing verification dependent library, and a label verification dependent library. The label issuing requirement can be customized and individualized according to the user requirement.
[0041] In the embodiment, the host computer 120 is connected with the password machine 110 and the tag reader / writer 130 respectively, and is used to obtain corresponding issuing data information from a preset database based on the issuing demand of the RFID electronic tag, and obtain the tag key ciphertext through the DLL library interface encapsulated by the password machine 110, and transmit the tag key ciphertext, the issuing data information and the pre-configured write instruction to the tag reader / writer 130 through the serial port. In the embodiment, the pre-configured write instruction includes an instruction code, a write region, an offset address, a write byte length and a write data type. The write data type includes writing the tag key ciphertext or writing the personalized data in the issuing data information. The write region can include the tag key region or the user region. The offset address can include the starting address of writing the personalized data or the starting address of writing the tag key ciphertext.
[0042] In the embodiment, the preset first rule corresponding to the write instruction includes that the instruction code in the write instruction is the write key instruction, the region is the security region of the electronic tag, the offset address is the starting address of storing the key data, and the write data is the tag key ciphertext. The preset second rule includes that the instruction code in the write instruction is the write personalized data instruction, the region is the security region of the electronic tag, the offset address is the starting address of storing the personalized data, and the write data is the personalized data.
[0043] In the embodiment, the pre-configured decryption key refers to that a decryption key consistent with the KeyP in the password machine is pre-embedded in the security chip in the tag reader / writer 130. The pre-configured decryption key can be used to decrypt the tag key ciphertext based on the pre-configured decryption key when the write instruction meets the preset first rule.
[0044] In the embodiment, the tag reader / writer 130 is connected with the host computer 120 in the form of the serial port or the USB port, and is used to decrypt the tag key ciphertext based on the pre-configured decryption key to obtain a decryption result when the write instruction meets the preset first rule. The decryption result is the plaintext key. The decryption result is written into the tag key region of the RFID electronic tag, and the written plaintext key is subjected to security authentication. After the security authentication passes, the issuing data information is written into the user region of the RFID electronic tag based on the preset second rule corresponding to the write instruction, and the target RFID electronic tag 140 after the data is written is obtained. It can be understood that the ciphertext key Ke is decrypted into the plaintext key Kd in the tag reader / writer 130. The host computer 120 calls the DLL interface to write the key Kd into the tag key region. The plaintext key Kd is used for security authentication in the tag. After the authentication passes, the issuing data information is written into the user region of the tag, that is, the plaintext key is written first, then the plaintext key is subjected to authentication, and after the authentication passes, the issuing data information is written. Specifically, the security authentication can be performed on the plaintext key through the SM7 algorithm.
[0045] In the embodiment, the label issuing station interface and the label inspection station interface are called to transmit the issued data information and the decryption result written in the target RFID electronic label 140 to the label issuing module 150 and the label inspection module 160; the label issuing module 150 is configured to perform a first integrity inspection on the issued data information and the decryption result written in the target RFID electronic label 140 based on a label issuing inspection library; the label inspection module 160 is configured to perform a second integrity inspection on the issued data information and the decryption result written in the target RFID electronic label 140 based on a label inspection library, and to confirm whether the RFID electronic label can be issued based on the first inspection result and the second inspection result, and to read the TID of the RFID electronic label in the case that the RFID electronic label can be issued. In the embodiment, the TID of the electronic label can only be read but not written, and is written in the factory as a unique identifier of the label and a product class identification number of the electronic label, which will be different for each manufacturer.
[0046] In the embodiment, the host computer 120 includes at least label issuing software, label inspection software and label printing software, and the corresponding interfaces include at least a label issuing station interface, a label inspection station interface, a key derivation interface and a label printing interface. The label issuing station interface is connected to the label issuing module (which can be understood as a label issuing station), the label inspection station is connected to the label inspection module (which can also be referred to as a label inspection station), the key derivation interface is connected to the cryptographic machine, and the label printing interface is connected to the printer. It should be noted that the label issuing station interface also includes an integrity inspection in the label issuing module. It can be understood that the issued data information and the decryption result written in the label issuing station will be subjected to a first integrity inspection, and then subjected to a second integrity inspection in the label inspection interface connected to the label inspection module. Through the two integrity inspections, the security and integrity of the writing are further ensured, and then it is confirmed whether the RFID electronic label can be issued based on the first integrity inspection and the second integrity inspection. In the case that the RFID electronic label can be issued, the TID of the RFID electronic label is read and returned to the label data management subsystem for storage.
[0047] The technical scheme of the embodiment of the present application uses the password machine to generate a tag issuing key, generates a tag key ciphertext based on the tag issuing key and a key dispersion factor, and can prevent leakage in the key transmission process; the host computer is used to obtain issuing data information from a preset database, and sends the tag key ciphertext, the issuing data information and a write instruction to the tag reader, the tag reader is used to decrypt the tag key ciphertext based on a decryption key to write into a tag key area when the write instruction meets a preset first rule, and write the issuing data information into a user area based on a preset second rule after security authentication passes, so that the key data of the electronic tag can be intercepted by a port monitoring tool, but cannot be easily cracked; the host computer selects a first verification library and a second verification library from the preset database, and verifies the written data content based on the first verification library and the second verification library to determine an issuing result, so that the data stored in the electronic tag cannot be illegally tampered with, and the security of the high-security electronic tag key data writing and personalized data issuing is ensured.
[0048] In an embodiment, the preset database is deployed on a server side, and the system further comprises a tag data management subsystem;
[0049] The tag data management subsystem is connected with the preset database and the host computer through a TCP / IP protocol, is used to receive the tag identification of the issued RFID electronic tag returned by the host computer, and stores the tag identification, so as to facilitate tracking and management of the issued RFID electronic tag.
[0050] The tag data management subsystem can also be referred to as an information unified centralized management system, that is, a background tag management system. The tag identification is a unique identification of the RFID electronic tag, and can also be referred to as a TID of the tag. In the embodiment, each tag has a unique TID, the identification of the issued tag is recorded after the issuing is completed, and then the issuing state is recorded, so that the tag can be traced back in the case of a problem in the field.
[0051] In the embodiment, the tag data management subsystem is connected with the preset database and the host computer through a TCP / IP protocol, is used to receive the tag identification of the issued RFID electronic tag returned by the host computer, and stores the tag identification, so as to facilitate tracking and management of the issued RFID electronic tag.
[0052] In an embodiment, the tag data management subsystem is further used to classify and store the RFID electronic tags of the same type; wherein the dynamic link library (DLL) library called by the RFID electronic tags of the same type is consistent, and the format of the personalized data written is universal.
[0053] In this embodiment, RFID electronic tags correspond to multiple tag types, such as electricity meter tags and metering box tags. In the tag data management subsystem, users can categorize and store the types of RFID electronic tags. RFID electronic tags of the same type call the same dynamic link library (DLL), and the format of the personalized data they write is universal. It can be understood that the issuance library, DLL dynamic library, and some verification libraries corresponding to each type of tag are not entirely consistent. For convenience, the tags are first categorized, with tags whose corresponding DLL libraries are completely consistent grouped together. The format of the personalized data used by the tags is universal. This categorization creates a universal DLL library, which is placed in the backend. Then, the frontend can obtain the data through a Webservice interface before issuance. That is, different types correspond to different issuance and verification libraries. For different types of tags, for example, selecting one type, the parameters of the reader and device corresponding to that type are directly obtained.
[0054] In this embodiment, the tag data management subsystem employs a front-end / back-end separation architecture, utilizing back-end storage. The front-end software retrieves write data and device parameter information from the back-end via an interface, controlling the equipment to execute corresponding mechanical actions to complete production. The integrated back-end management system centrally manages production data, parameter configurations, and other information, storing them in a MySQL database. This design enables rapid deployment and production when issuing different types of tags, significantly improving production efficiency.
[0055] In one embodiment, the host computer includes label printing software;
[0056] The label printing software is used to call the label printing interface and transmit the order asset number data from the issuance data information to the printer, so that the printer can print the order asset number data on the surface of the RFID electronic tag.
[0057] In this embodiment, the order asset number data can be a multi-digit asset number, for example, 21 or 23 digits, etc., which can include the online application enterprise number, the tag type, the tag number, the tag verification number, etc. In this embodiment, the tag printing software in the host computer is used to call the tag printing interface to transmit the order asset number data in the issuance data information to the printer, so that the printer can print the order asset number data on the surface of the RFID electronic tag.
[0058] In one embodiment, the host computer is also connected to a preset machine device to receive customized parameter information of the RFID electronic tag input by the user, so as to control the preset machine device to customize the RFID electronic tag according to the customized parameter information; wherein, the customized parameter information includes at least: the length, width, thickness, and color of the tag customization, as well as the power, frequency, and communication rate of the card reader.
[0059] The preset machine device can include a PLC, a mechanical arm, and the like, and the host computer further includes an interface for controlling the machine device, and the PLC, the mechanical arm, and the like are controlled through the control interface to perform an operation, which is the customization parameter information of the RFID electronic tag input by the user. The size and thickness of each tag are different, and therefore the operations corresponding to the mechanical arm and the PLC are also different.
[0060] In an embodiment, the tag reader / writer includes an MCU unit, a security chip, and a radio frequency module; the security chip is deployed with a preconfigured decryption key;
[0061] The MCU unit is connected with the host computer and the security chip respectively, configured to receive a write instruction and a tag key ciphertext transmitted by the host computer, and when the write instruction meets a preset first rule, obtain the preconfigured decryption key from the security chip, use the decryption key to analyze the write instruction and the tag key ciphertext to obtain a key plaintext and an executed write instruction, and transmit the key plaintext and the executed write instruction to the radio frequency module;
[0062] The radio frequency module is connected with the MCU unit and the RFID electronic tag respectively, configured to write the key plaintext into a tag key region of the RFID electronic tag according to an offset address in the write instruction, use the key plaintext for security authentication, obtain personalized data after the security authentication passes, and when the write instruction meets a preset second rule, write the personalized data into a user region of the RFID electronic tag.
[0063] In the embodiment, the MCU unit is connected with the host computer and the security chip respectively, configured to receive a write instruction and a tag key ciphertext transmitted by the host computer, and when the write instruction meets a preset first rule, obtain the preconfigured decryption key from the security chip, use the decryption key to analyze the write instruction and the tag key ciphertext to obtain a key plaintext and an executed write instruction, and transmit the key plaintext and the executed write instruction to the radio frequency module; the radio frequency module is connected with the MCU unit and the RFID electronic tag respectively, configured to write the key plaintext into a tag key region of the RFID electronic tag according to an offset address in the write instruction, use the key plaintext for security authentication, obtain personalized data after the security authentication passes, and when the write instruction meets a preset second rule, write the personalized data into a user region of the RFID electronic tag, to obtain a target RFID electronic tag after data writing.
[0064] Specifically, when the key plaintext is written into the tag key area of the RFID electronic tag, the MCU control unit of the reader receives the instruction and performs rule judgment. When the instruction code is a write instruction, the area is the security area of the electronic tag, and the offset address is the starting address of the key data storage, it is determined that the current operation is the key data write operation of the electronic tag, and then the decryption interface of the security chip is called to decrypt the KeyTEnc through the built-in key KeyP of the security chip to obtain the key plaintext KeyT and write it into the electronic tag. In this embodiment, a decryption key consistent with the protection key in the production password machine is built in the security chip in the reader. The key data is transmitted to the reader in the form of ciphertext by the encryption operation of the password machine, and then the decryption operation is performed by the reader to protect the key data of the electronic tag from being easily cracked even if it is intercepted by a port monitoring tool. If the reader wants to change the application data of the electronic tag, it must first obtain the change permission by performing the national secret identification with the electronic tag through the key data. The application protects the application data in the electronic tag from being illegally tampered with or deleted by protecting the key data. Although the ciphertext storage method in the prior art can protect the plaintext of the application data from being obtained, once the key data is leaked, the application data has the risk of being tampered with or deleted.
[0065] In an embodiment, the security authentication is performed on the key plaintext written in the RFID electronic tag and the key plaintext decrypted by the security chip in the tag reader; the security authentication method includes: the RFID electronic tag generates a first random number and transmits it to the security chip in the tag reader; the security chip generates a second random number and encrypts the first random number and the second random number to obtain a first ciphertext random number, and transmits the first ciphertext random number to the RFID electronic tag to decrypt the first ciphertext random number to obtain a first plaintext random number and a second plaintext random number; the RFID electronic tag compares the first plaintext random number with the first random number, and when the comparison result of the first plaintext random number and the first random number is consistent, the RFID electronic tag generates a third random number, encrypts the second plaintext random number and the third random number to obtain a second ciphertext random number, and transmits the second ciphertext random number to the security chip; the security chip decrypts the second ciphertext random number to obtain the second plaintext random number, and compares the second plaintext random number with the second random number. When the comparison is consistent, it is determined that the security authentication is passed.
[0066] In an embodiment, the integrity verification method includes: reading the personalized data from the offset address in the RFID electronic tag, and comparing the personalized data transmitted by the tag issuing station interface to obtain a first comparison result, and determining that the integrity verification check result is passed when the first comparison result is consistent.
[0067] In this embodiment, personalized data is read from the offset address in the RFID tag. Since the personalized data is written after the tag key authentication is successful, the integrity check result is determined to be successful after the first comparison result is consistent. In some embodiments, personalized data transmitted by calling the tag issuance station interface can also be obtained for comparison to get the first comparison result; the tag key ciphertext is read from the offset address in the RFID tag, and the MAC checksum corresponding to the tag key ciphertext is calculated to determine whether the MAC checksum is empty; if the first comparison result is consistent and the MAC checksum is empty, the integrity check result is determined to be successful.
[0068] In one embodiment, to facilitate a better understanding of the RFID electronic tag data issuance system, Figure 2 This is a schematic diagram of the structure of another RFID electronic tag data issuance system provided in an embodiment of the present invention, as shown below. Figure 2 As shown, the RFID electronic tag data issuance system includes: a cryptographic machine 210, host computer software 220, a tag reader / writer 230, a target RFID electronic tag 240 (also known as a high-security RFID electronic tag), a tag issuance module 250, a tag inspection module 260, and a tag data management subsystem 270. The host computer software 220 includes tag printing software, tag issuance software, tag inspection software, and customized tag software for controlling PLCs, robotic arms, and other equipment. The tag reader / writer 230 includes an MCU unit, a security chip, and an RF module. A server interface is provided between the host computer software 220 and the tag data management subsystem 270.
[0069] In the embodiment, the password machine generates a tag issuing key, and generates a tag key ciphertext based on the tag issuing key and a pre-configured key dispersion factor, and gives to the upper computer, the upper computer acquires issuing data information from a database through a preset WebService interface, calls an interface of tag printing, and transmits order asset number data in the issuing data information to a printer, so that the printer prints the order asset number data on the surface of the RFID electronic tag, and acquires the tag key ciphertext from the password machine, and transmits the tag key ciphertext, the issuing data information and a pre-configured write instruction to a tag reader-writer through a serial port, the tag reader-writer is used for decrypting the tag key ciphertext to obtain a decryption result based on a pre-configured decryption key when the write instruction meets a preset first rule, writing the decryption result into a tag key area of the RFID electronic tag, and writing the issuing data information into a user area of the RFID electronic tag based on a preset second rule corresponding to the write instruction after security authentication of the decryption result passes, to obtain a target RFID electronic tag after data writing, and the upper computer is also used for selecting a first verification library and a second verification library from a preset database through the preset WebService interface after receiving a data writing completion instruction, performing first integrity verification on the written issuing data information and the decryption result in the target RFID electronic tag based on the first verification library, performing second integrity verification on the written issuing data information and the decryption result in the target RFID electronic tag based on the second verification library, determining an issuing result based on the first integrity verification and the second integrity verification, reading a TID of the tag and returning to a data management system for storage after the verification is completed, to facilitate subsequent tracking and management of the tag.
[0070] For better understanding of the RFID electronic tag data issuing system and the specific tag key issuing process, Figure 3 For another RFID electronic tag data issuing system structure diagram provided by the embodiment of the application, Figure 4 For a tag key issuing process diagram of the RFID electronic tag provided by the embodiment of the application. The background information unified centralized management system is the tag data management subsystem in the above embodiment, the production password machine is the password machine in the above embodiment, the high-security RFID electronic tag is the target RFID electronic tag in the above embodiment, and the production software is the upper computer in the above embodiment.
[0071] As Figure 3As shown, the RFID electronic tag data issuing system comprises a production password machine, production software, the production software comprising: tag printing software, tag issuing software and tag inspection software, a tag reader, a high-security RFID electronic tag and a background information unified centralized management system. Similarly, the tag reader is connected with the PC in a serial port or USB port mode, and internally comprises an MCU control unit, a security chip and a radio frequency module. In the embodiment, the production software downloads the DLL dependent library, order asset number data, personalized information, device configuration information and the like from the database through a WebService interface, and calls a printer interface to realize real-time printing of the order asset number data. Meanwhile, the production software acquires the tag key ciphertext Ke from the production password machine using a TCP / IP protocol, transmits the ciphertext data to the tag reader through a serial port, decrypts the ciphertext key Ke into a plaintext key Kd in the reader, and writes the key Kd into the tag key area by calling a DLL interface in the issuing station. The tag internally uses the plaintext key Kd for SM7 security authentication, writes the personalized information into the user area of the tag after the authentication, inspects the personalized data in the tag at a device inspection station, judges the integrity of the data writing, reads the TID of the tag and returns it to the data management system for storage, facilitating subsequent tracking and management of the tag.
[0072] As Figure 4As shown, the production host software takes a key dispersion factor, which can be taken from the identification code of the electronic tag or an external system. The host calls the password machine key derivation interface, and the password machine uses the tag issuance root key KeyR to generate a tag key KeyT. The password machine encrypts KeyT using the protection key KeyP to generate tag key ciphertext KeyTEnc, and the host software obtains KeyTEnc. The host software sends the write instruction and KeyTEnc to the tag reader. The tag reader is connected to the PC in a serial or USB port, and internally includes an MCU control unit, a security chip, and a radio frequency module. The MCU control unit is responsible for parsing the instructions and data sent by the host software (that is, parsing the encrypted tag key ciphertext KeyTEnc, specifically by embedding a decryption key consistent with KeyP in the password machine to decrypt KeyTEnc to obtain plaintext key, and then writing the plaintext key to the tag), controlling the security chip to perform encryption and decryption, and operating the radio frequency module to read and write the electronic tag. The security chip has a decryption key consistent with KeyP in the password machine. The radio frequency module is responsible for communicating with the electronic tag. In this embodiment, the complete write instruction includes at least the following factors: instruction code, write area, offset address (starting address), write word number, and write data; wherein the write data is the KeyTEnc key ciphertext. After the MCU control unit of the reader receives the instruction, it performs rule judgment. When the instruction code is a write instruction, the area is the security area of the electronic tag, and the offset address is the starting address of the key data storage, it is determined that the current is doing the key data write operation of the electronic tag, and then the decryption interface of the security chip is called to decrypt KeyTEnc through the key KeyP in the security chip to obtain the key plaintext KeyT, and write it into the electronic tag. After the security authentication is passed, the personalized data is written into the electronic tag in the same way to obtain the target electronic tag, which is a high-security electronic tag.
[0073] In an embodiment, Figure 5 A flowchart of an RFID electronic tag data issuance method according to an embodiment of the present application is shown in FIG. 6. Figure 5 As shown, the method is applied to an RFID electronic tag data issuance system. The method specifically includes the following steps:
[0074] S510, the password machine generates tag key ciphertext based on the tag issuance key in the password machine and the key dispersion factor transmitted by the password machine interface.
[0075] S520, the host obtains the corresponding issuance data information from the preset database based on the tag issuance requirement, and transmits the tag key ciphertext, the issuance data information, and the preconfigured write instruction to the tag reader through the serial port.
[0076] S530, the tag read-write device decrypts the tag key ciphertext based on the pre-configured decryption key to obtain a decryption result, writes the decryption result into the tag key area of the RFID electronic tag, and after the security authentication of the decryption result passes, writes the issuance data information into the user area of the RFID electronic tag based on the preset second rule corresponding to the write instruction, to obtain the target RFID electronic tag after data writing.
[0077] S540, after the host computer receives the data writing completion instruction, the tag issuance station interface and the tag inspection station interface are called, and the written issuance data information and the decryption result in the target RFID electronic tag are transmitted to the tag issuance module and the tag inspection module for inspection.
[0078] S550, the tag issuance module performs a first integrity inspection on the written issuance data information and the decryption result in the target RFID electronic tag based on the tag issuance inspection library.
[0079] S560, the tag inspection module performs a second integrity inspection on the written issuance data information and the decryption result in the target RFID electronic tag based on the tag inspection inspection library, and determines the issuance result based on the first integrity inspection and the second integrity inspection.
[0080] In an embodiment, the preset database is deployed on a server side, and the method further comprises:
[0081] The tag data management subsystem receives the tag identification of the issued RFID electronic tag returned by the tag read-write device, and stores the tag identification, facilitating tracking and management of the issued RFID electronic tag.
[0082] In an embodiment, the method further comprises: classifying and storing RFID electronic tags of the same type through the tag data management subsystem; wherein the dynamic link library (DLL) library called by RFID electronic tags of the same type is consistent, and the format of the written personalized data is universal.
[0083] In an embodiment, the tag issuance key includes an issuance root key and a protection key; correspondingly, the cryptographic machine generates a tag key ciphertext based on the tag issuance key in the cryptographic machine and the key dispersion factor transmitted by the cryptographic machine interface, including:
[0084] The root key in the tag issuance key is dispersed by the key dispersion factor transmitted by the cryptographic machine interface to generate a tag key; wherein the key dispersion factor includes: an identification code of the RFID electronic tag, or a self-defined identification code input through a third-party system;
[0085] The tag key is encrypted using a protection key in the key issuance key to generate tag key ciphertext.
[0086] In an embodiment, the preconfigured write instruction comprises: an instruction code, a write region, an offset address, a write byte length, and a write data type; wherein the write data type comprises: write tag key ciphertext, or personalized data in the issuance data information.
[0087] In an embodiment, the method further comprises: transmitting order asset number data in the issuance data information to a printer through a label printing software interface in the host computer to enable the printer to print the order asset number data on the surface of the RFID electronic tag.
[0088] In an embodiment, the label reader / writer comprises an MCU unit, a security chip, and a radio frequency module; the security chip is deployed with a preconfigured decryption key;
[0089] The method comprises: receiving the write instruction and the tag key ciphertext transmitted by the host computer through the MCU unit, and obtaining the preconfigured decryption key from the security chip when the write instruction meets a preset first rule, using the decryption key to parse the write instruction and the tag key ciphertext to obtain key plaintext and the executed write instruction, and transmitting to the radio frequency module;
[0090] The radio frequency module writes the key plaintext into the tag key region of the RFID electronic tag according to the offset address in the write instruction, and uses the key plaintext for security authentication, and after the security authentication passes, obtains the personalized data from the host computer software, and writes the personalized data into the user region of the RFID electronic tag when the write instruction meets a preset second rule.
[0091] In an embodiment, the preset first rule comprises: the instruction code in the write instruction is a write key instruction, the region is a security region of the electronic tag, the offset address is a starting address of key data storage, and the write data is write tag key ciphertext;
[0092] The preset second rule comprises: the instruction code in the write instruction is a write personalized data instruction, the region is a user region of the electronic tag, the offset address is a starting address of personalized data storage, and the write data is write personalized data.
[0093] In an embodiment, the issuance data information at least comprises: a DLL dependent library, order asset number data, personalized data, and device configuration information; the DLL dependent library at least comprises: a label issuance dependent library, a label issuance verification dependent library, and a label verification dependent library.
[0094] In an embodiment, the preset database communicates with the host computer through a preset WebService interface; the preset WebService interface comprises an order number taking interface, a configuration information downloading interface, an issuing library downloading interface, an inspection library downloading interface, a production state updating interface, and a label backtracking interface.
[0095] In an embodiment, the host computer is configured to receive custom parameter information of an RFID electronic label input by a user, so as to control the preset machine device to customize the RFID electronic label according to the custom parameter information; wherein the custom parameter information at least comprises a length, a width, and a thickness of the label customization, and a label color.
[0096] In an embodiment, the security authentication is performed between a key plaintext written in the RFID electronic label and a key plaintext decrypted from a security chip in the label reader-writer; the security authentication comprises:
[0097] The RFID electronic label generates a first random number and transmits the first random number to the security chip in the label reader-writer;
[0098] The security chip generates a second random number, encrypts the first random number and the second random number to obtain a first ciphertext random number, and transmits the first ciphertext random number to the RFID electronic label, so that the RFID electronic label decrypts the first ciphertext random number to obtain a first plaintext random number and a second plaintext random number;
[0099] The RFID electronic label compares the first plaintext random number with the first random number, and after the comparison result of the first plaintext random number and the first random number is consistent, the RFID electronic label generates a third random number, encrypts the second plaintext random number and the third random number to obtain a second ciphertext random number, and transmits the second ciphertext random number to the security chip;
[0100] The security chip decrypts the second ciphertext random number to obtain a second plaintext random number, and compares the second plaintext random number with the second random number, and in the case that the comparison is consistent, it is determined that the security authentication is passed.
[0101] In an embodiment, the integrity verification comprises:
[0102] The personalized data is read from the offset address in the RFID electronic label, and the personalized data transmitted by the calling label issuing station interface is obtained for comparison to obtain a first comparison result, and after the first comparison result is consistent, it is determined that the integrity verification passes.
[0103] In an embodiment, the system further comprises: the password machine is connected with the host computer through TCP / IP protocol; the host computer is connected with the password machine and the tag reader respectively; the tag reader is connected with the host computer in a serial port or USB port mode.
[0104] It should be understood that the various forms of flow shown above can be used to reorder, add or delete steps. For example, the steps described in the present application can be performed in parallel, sequentially or in a different order, as long as the desired results of the technical solutions of the present application can be achieved, which is not limited herein.
[0105] The above detailed description does not constitute a limitation on the protection scope of the present application. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent replacements and improvements made within the spirit and principles of the present application shall be included in the protection scope of the present application.
Claims
1. An RFID electronic tag data issuing system characterized by comprising: The RFID electronic tag data issuing system comprises a password machine, an upper computer, a tag reader / writer, a target RFID electronic tag, a tag issuing module, and a tag inspection module. The password machine is configured to generate a tag key ciphertext based on a tag issuing key in the password machine and a key dispersion factor transmitted by a password machine interface. The upper computer is configured to obtain corresponding issuing data information from a preset database based on a tag issuing requirement, and transmit the tag key ciphertext, the issuing data information, and a preconfigured write instruction to the tag reader / writer through a serial port. The tag reader / writer is configured to decrypt the tag key ciphertext based on a preconfigured decryption key to obtain a decryption result when the write instruction meets a preset first rule, write the decryption result into a tag key area of the RFID electronic tag, and write the issuing data information into a user area of the RFID electronic tag based on a preset second rule corresponding to the write instruction after the security authentication of the decryption result is passed, to obtain a target RFID electronic tag after data writing. The upper computer is further configured to call a tag issuing station interface and a tag inspection station interface after receiving a data writing completion instruction, and transmit the written issuing data information and the decryption result in the target RFID electronic tag to the tag issuing module and the tag inspection module for inspection. The tag issuing module is configured to perform a first integrity inspection on the written issuing data information and the decryption result in the target RFID electronic tag based on a tag issuing inspection library. The tag inspection module is configured to perform a second integrity inspection on the written issuing data information and the decryption result in the target RFID electronic tag based on a tag inspection library, and determine an issuing result based on the first integrity inspection and the second integrity inspection. The preset database is deployed on a server side, and the system further comprises a tag data management subsystem. The tag data management subsystem is connected to the preset database and the upper computer through a TCP / IP protocol, configured to receive a tag identification of the issued RFID electronic tag returned by the upper computer, and store the tag identification, to facilitate tracking and management of the issued RFID electronic tag.
2. The system of claim 1, wherein, The tag data management subsystem is further configured to classify and store RFID electronic tags of the same type; wherein, a dynamic link library (DLL) library called by the RFID electronic tags of the same type is consistent, and the format of the written personalized data is universal.
3. The system of claim 1, wherein, The tag issuing key comprises an issuing root key and a protection key; correspondingly, the process of generating the tag key ciphertext by the password machine comprises: dispersing the root key in the tag issuing key based on the key dispersion factor transmitted by the password machine interface to generate a tag key; wherein, the key dispersion factor comprises an identification code of the RFID electronic tag or a self-defined identification code input through a third-party system; encrypting the tag key based on the protection key in the tag issuing key to generate the tag key ciphertext.
4. The system of claim 1, wherein, The preconfigured write instruction comprises: an instruction code, a write area, an offset address, a write byte length, and a write data type; wherein the write data type comprises: write tag key ciphertext or personalized data in write issuance data information.
5. The system of claim 1, wherein, The upper computer comprises label printing software; The label printing software is configured to call an interface for label printing, and transmit order asset number data in the issuance data information to a printer, so that the printer prints the order asset number data on the surface of the RFID electronic tag.
6. The system of claim 1, wherein, The label reader / writer comprises an MCU unit, a security chip, and a radio frequency module; and the security chip is deployed with a preconfigured decryption key. The MCU unit is connected with the upper computer and the security chip, respectively, and is configured to receive the write instruction and the tag key ciphertext transmitted by the upper computer, acquire the preconfigured decryption key from the security chip when the write instruction meets a preset first rule, analyze the write instruction and the tag key ciphertext using the decryption key to obtain key plaintext and the executed write instruction, and transmit the key plaintext and the executed write instruction to the radio frequency module. The radio frequency module is connected with the MCU unit and the RFID electronic tag, respectively, and is configured to write the key plaintext into a tag key area of the RFID electronic tag according to the offset address in the write instruction, perform security authentication using the key plaintext, acquire personalized data from the upper computer software after the security authentication passes, and write the personalized data into a user area of the RFID electronic tag when the write instruction meets a preset second rule.
7. The system of any of claims 1 or 6, wherein, The preset first rule comprises: the instruction code in the write instruction is a write key instruction, the area is a security area of the electronic tag, the offset address is a starting address of key data storage, and the write data is write tag key ciphertext. The preset second rule comprises: the instruction code in the write instruction is a write personalized data instruction, the area is a user area of the electronic tag, the offset address is a starting address of personalized data storage, and the write data is write personalized data.
8. The system of claim 1, wherein, The issuance data information at least comprises: a DLL dependent library, order asset number data, personalized data, and device configuration information; and the DLL dependent library at least comprises: a tag issuance dependent library, a tag issuance verification dependent library, and a tag verification dependent library.
9. The system of claim 1, wherein, The preset database and the upper computer communicate through a preset WebService interface; The preset WebService interface comprises: an order number taking interface, a configuration information downloading interface, an issuance library downloading interface, a verification library downloading interface, a production state updating interface, and a tag backtracking interface.
10. The system of claim 1, wherein, The upper computer is further connected with a preset machine device, and is configured to receive customized parameter information of the RFID electronic tag input by a user, so as to control the preset machine device to customize the RFID electronic tag according to the customized parameter information; wherein the customized parameter information at least comprises: the length, width, and thickness of the label customization, the color of the label, and the power, frequency, and communication rate of the card reader.
11. The system of any of claims 1 or 6, wherein, The security authentication is performed between the key plaintext written in the RFID electronic tag and the key plaintext decrypted from the security chip in the tag read-write device; The security authentication includes: The RFID electronic tag generates a first random number and transmits it to the security chip in the tag read-write device; The security chip generates a second random number and encrypts the first random number and the second random number to obtain a first ciphertext random number, and transmits the first ciphertext random number to the RFID electronic tag, so that the RFID electronic tag decrypts the first ciphertext random number to obtain a first plaintext random number and a second plaintext random number; The RFID electronic tag compares the first plaintext random number with the first random number, and when the comparison result of the first plaintext random number and the first random number is consistent, the RFID electronic tag generates a third random number, encrypts the second plaintext random number and the third random number to obtain a second ciphertext random number, and transmits the second ciphertext random number to the security chip; The security chip decrypts the second ciphertext random number to obtain a second plaintext random number, and compares the second plaintext random number with the second random number. When the comparison is consistent, it is determined that the security authentication is passed.
12. The system of any of claims 1 or 6, wherein, The integrity verification includes: The personalized data in the RFID electronic tag is read from the offset address, and the personalized data transmitted by the tag issuing station interface is obtained for comparison to obtain a first comparison result. When the first comparison result is consistent, it is determined that the integrity verification is passed.
13. The system of claim 1, wherein, The password machine is connected to the host computer through the TCP / IP protocol; the host computer is connected to the password machine and the tag read-write device; the tag read-write device is connected to the host computer through a serial port or a USB port.
14. An RFID electronic tag data issuing method characterized by comprising: The RFID electronic tag data issuing system according to any one of claims 1-13; the RFID electronic tag data issuing system includes a password machine, a host computer, a tag read-write device, a target RFID electronic tag, a tag issuing module, and a tag verification module; The RFID electronic tag data issuing method includes: The password machine generates a tag key ciphertext based on the tag issuing key in the password machine and the key dispersion factor transmitted by the password machine interface; The host computer obtains the corresponding issuing data information from the preset database based on the tag issuing requirement, and transmits the tag key ciphertext, the issuing data information, and the pre-configured write instruction to the tag read-write device through the serial port; When the write instruction meets the preset first rule, the tag read-write device decrypts the tag key ciphertext based on the pre-configured decryption key to obtain a decryption result, writes the decryption result into the tag key area of the RFID electronic tag, and when the security authentication of the decryption result is passed, writes the issuing data information into the user area of the RFID electronic tag based on the preset second rule corresponding to the write instruction to obtain the target RFID electronic tag after data writing; The host computer receives the data write completion instruction, calls a label issuing station interface and a label inspection station interface, and transmits the issued data information and the decryption result in the target RFID electronic tag after writing to a label issuing module and a label inspection module for inspection; The label issuing module performs a first integrity inspection on the issued data information and the decryption result in the target RFID electronic tag after writing based on a label issuing inspection library; The label inspection module performs a second integrity inspection on the issued data information and the decryption result in the target RFID electronic tag after writing based on a label inspection inspection library, and determines an issuing result based on the first integrity inspection and the second integrity inspection; The preset database is deployed on a server side, and the RFID electronic tag data issuing system further comprises a label data management subsystem; correspondingly, the RFID electronic tag data issuing method further comprises: The label data management subsystem receives the label identification of the issued RFID electronic tag returned by the host computer, and stores the label identification, so as to facilitate tracking and management of the issued RFID electronic tag.
Citation Information
Patent Citations
RFID tag key updating method, device and system, RFID tag reader-writer, electronic equipment and storage medium
CN118487762A