RFID security authentication protocol method and system based on block-order-mode key matrix encryption algorithm
By designing an RFID security authentication protocol based on block-sequence-modular variable key matrix encryption algorithm, the shortcomings of the existing RFID security authentication protocol in data security and privacy protection are solved, and the effect of high security and low storage space requirements is achieved.
Patent Information
- Application Number
- CN202510010128.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-03
- Publication Date
- 2025-05-13
AI Technical Summary
The existing RFID security authentication protocols have shortcomings in data security and privacy protection. The heavyweight protocol is complex and difficult to promote, while the ultra-lightweight protocol has low security and is difficult to meet the security needs of mobile RFID systems.
An RFID security authentication protocol based on the block-sequence-modular variable key matrix encryption algorithm is designed. By constructing an adaptive modular value, self-update encryption sequence and diagonal block local transposed key matrix encryption algorithm, the block-sequence-modular variable key matrix encryption algorithm is constructed, which is suitable for mobile RFID systems and low-cost RFID tags.
Without increasing the overhead of key matrix storage, this protocol expands the feasible domain of the key space, improves security, and accelerates the protocol design through fast convolution Winograd algorithm, saving 99.59% of RFID tag storage space.
Smart Images

Figure CN119997002A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of radio frequency identification technology in Internet of Things technology, and in particular to an RFID security authentication protocol method and system based on a block-sequence-module variable key matrix encryption algorithm. Background Art
[0002] The "Guidelines for the Construction of the Internet of Things Standard System" issued by the Ministry of Industry and Information Technology of China on July 22, 2024 revealed the widespread application of Internet of Things technology in my country's logistics, environmental protection, medical care, transportation and other fields. Among them, Radio Frequency Identification (RFID) technology, as a key link in the realization of the Internet of Things, shines in the field of Internet of Things applications with its contactless characteristics and ability to identify multiple objects at the same time.
[0003] However, with the widespread application of RFID technology, its data security and privacy protection issues have become increasingly prominent. For example, user RFID tags are secretly located and tracked, infringing personal privacy; for example, detailed information of items is vulnerable to attacks during transmission, leading to privacy leakage. In response to these problems, among the existing RFID security authentication protocols, heavyweight protocols usually use more mature and complex encryption algorithms, which have complex mathematical theories and are difficult to implement in engineering, which is not conducive to large-scale promotion and application. On the contrary, ultra-lightweight protocols only use some simple bit operations and are easy to implement, but because of this, they are less secure and vulnerable to attacks.
[0004] In view of this, the matrix encryption algorithm has become an ideal choice for designing new RFID security authentication protocols because of its intuitive and easy-to-understand algorithm structure, the characteristics of realizing encryption and decryption processes through simple matrix multiplication, and good scalability, that is, adjusting the size and parameters of the key matrix to meet different security requirements. At present, how to design an authentication protocol based on the matrix encryption algorithm that can meet the security requirements of mobile RFID systems and is suitable for low-cost RFID tag deployment has become a key task that needs to be solved urgently. Summary of the invention
[0005] The purpose of the present invention is to provide a low-cost, high-security RFID security authentication protocol method and system based on a block-sequence-module variable key matrix encryption algorithm that is applicable to a mobile RFID system and can be deployed in an RFID tag with limited storage resources.
[0006] The technical solution to achieve the purpose of the present invention is: an RFID security authentication protocol method based on a block-sequence-modular key matrix encryption algorithm, comprising the following steps:
[0007] Step 1: Construct a system model of mobile RFID network;
[0008] Step 2, construct an adaptive modulus encryption algorithm, namely AM, a self-updating encryption order, namely SUEO, and a diagonal block local transposition key matrix, namely DBLTKM;
[0009] Step 3: Based on the AM encryption algorithm, the SUEO encryption algorithm and the DBLTKM encryption algorithm, a block-sequence-modular variable key matrix encryption algorithm is constructed, namely, the AM-SUEO-DBLTKM algorithm;
[0010] Step 4: Based on the AM-SUEO-DBLTKM algorithm, an RFID security authentication protocol based on the block-sequence-modular variable key matrix encryption algorithm is constructed.
[0011] Furthermore, the system model of building a mobile RFID network in step 1 is as follows:
[0012] Step 1.1: In the mobile RFID system, the server, reader and RFID tag all communicate with each other through radio frequency signals, i.e. wireless insecure communication. During communication, the server and reader, and the reader and RFID tag need to authenticate each other. Only after successful authentication can the subsequent confidential information be transmitted.
[0013] Step 1.2, the mathematical principle of the key matrix encryption and decryption algorithm is: for a given n-order integer matrix A, if the value of its determinant is coprime with the integer p, the inverse matrix B of the matrix A modulo p can be obtained by using elementary transformation methods. The encryption and decryption process of using A, B and p to establish the key matrix is as follows:
[0014] E(t,A,p)=A×t mod(p)=c
[0015] D(c,B,p)=B×c mod(p)=t
[0016] Where E(·), D(·), t, and c represent the encryption process, decryption process, plaintext, and ciphertext, respectively.
[0017] Furthermore, the construction of the adaptive modulus value, namely the AM encryption algorithm, the self-updating encryption order, namely the SUEO encryption algorithm, and the diagonal block local transposition key matrix, namely the DBLTKM encryption algorithm in step 2 is as follows:
[0018] Step 2.1: Construct an adaptive modulus encryption algorithm:
[0019] If the integer p and the determinant of matrix A are coprime, then the integer divisor q of p is also coprime to the determinant of matrix A, and p×q is still coprime to the determinant of matrix A. Thus, the AM encryption algorithm is constructed, and the integer divisors q and p×q modulo p are used to multiply the key matrix A respectively to encrypt and decrypt the data, achieving 2Q encryption and decryption, where Q is the number of integer divisors of modulo p that do not contain 1;
[0020] Step 2.2: Build a self-updating encryption sequence encryption algorithm:
[0021] For integer square matrices A1 and A2, if A1×tmod(p)=c1 and A2×c1 mod(p)=c2, and A2×tmod(p)=c3 and A1×c3 mod(p)=c4, then c2≠c4. Thus, the SUEO algorithm is constructed. For multiple key matrices, multiple key matrices are multiplied by matrix multiplication to encrypt and decrypt data.
[0022] Step 2.3: Construct the diagonal block local transposition key matrix encryption algorithm:
[0023] If A1 is an m-order square matrix, A2 is an n-order square matrix, and there exists A1×t1mod(p)=c1 and A2×t2 mod(p)=c2, then Where t1 is an m-dimensional vector and t2 is an n-dimensional vector. The DBLTKM algorithm is constructed based on this. By updating the order of the key matrix on the main diagonal, multiple different key matrices are formed to encrypt and decrypt the data.
[0024] Furthermore, in step 2.2, multiple key matrices are multiplied by matrix multiplication operation, using the fast convolution Winograd algorithm, as follows:
[0025] For the matrix A=(a1,a2,…,a n ) T and B=(b1,b2,…,b n ),in(·) T represents the transposition operation, a1=(a1,a2,…,a n ), b1=(b1,b2,…,b n ), so for the matrix multiplication C = AB, the element value c 11 is represented as:
[0026] a1·b1=a1×b1+a2×b2+…+a n ×b n
[0027] The Winograd algorithm reduces multiplication operations by adding a small number of addition operations. The matrix multiplication using the Winograd algorithm is described as follows:
[0028] make When n is an odd number,
[0029]
[0030] When n is an even number,
[0031]
[0032] When n is an odd number, the calculation method is similar to that of an even number, with only one more correction term. For n-order square matrix multiplication, the Winograd algorithm only needs n 2 (n+2) addition and n 2 (n / 2+1) multiplication.
[0033] Furthermore, based on the AM encryption algorithm, the SUEO encryption algorithm and the DBLTKM encryption algorithm in step 3, a block-sequence-modular variable key matrix encryption algorithm, namely the AM-SUEO-DBLTKM algorithm, is constructed as follows:
[0034] The block-sequence-module variable key matrix encryption algorithm is constructed. The AM encryption algorithm updates the module value to weaken the correlation between plaintext and ciphertext; the SUEO encryption algorithm is used to update the encryption order to improve security; the DBLTKM encryption algorithm is used to update the key matrix and expand the feasible domain of the key space.
[0035] Furthermore, in step 4, based on the AM-SUEO-DBLTKM algorithm, an RFID security authentication protocol based on a block-sequence-modular variable key matrix encryption algorithm is constructed, as follows:
[0036] (1) The reader sends a “Query” to the RFID tag;
[0037] (2) The RFID tag responds to the reader and uses its internal pseudo-random number generator to generate a random number N t , then the RFID tag uses the encryption matrix A and the module p to N t ||S is encrypted, where S is the secret value, denoted as E(N t ‖S,A,p);
[0038] (3) RFID tag sends E(N t ‖S,A,p) to the reader;
[0039] (4) The reader responds to the E(N) sent by the RFID tag t ‖S,A,p) to decrypt and obtain the secret value S. If S is queried, the reader authenticates the RFID tag successfully and accepts N t , then the reader generates a random number N r , and use the encryption matrix A and modulus p to Nr ||S is encrypted and recorded as E(N r ‖S,A,p); if S is not found, the reader fails to authenticate the RFID tag and the protocol terminates;
[0040] (5) The reader sends E(N r ‖S,A,p) to the server;
[0041] (6) The server sends E(N) to the reader r ‖S,A,p) to decrypt and obtain the secret value S. If S is found, the server authenticates the reader successfully and accepts N r , then the server generates a new secret value S d ,S p ,S c , and use the encryption matrix A and modulus p to N r ||S d ||S p ||S c Encryption is performed, recorded as E(N r ‖S d ‖S p ‖S c ,A,p); if S is not queried, the server fails to authenticate the reader and the protocol terminates;
[0042] (7) The server sends E(N r ‖S d ‖S p ‖S c ,A,p) to the reader;
[0043] (8) The reader sends E(N) to the server r ‖S d ‖S p ‖S c ,A,p) to decrypt and obtain N r , if N r If the random number is equal to the one passed previously, the reader successfully authenticates the server and accordingly, the reader accepts the new secret value S d ,S p ,S c , then the reader uses the encryption matrix A and modulo p to N t ‖S d ‖S p ‖S c Encryption is performed, recorded as E(N t ‖S d ‖S p ‖S c ,A,p); if N rIf it is equal to the random number passed previously, the reader fails to authenticate the server and the protocol terminates;
[0044] (9) The reader sends E(N t ‖S d ‖S p ‖S c ,A,p) to RFID tag;
[0045] (10) E(N) sent by RFID tag to the reader t ‖S d ‖S p ‖S c ,A,p) to decrypt and obtain N t , if N t If the random number is equal to the one passed before, the RFID tag successfully authenticates the reader, and accordingly, the RFID tag accepts the new secret value S d ,S p ,S c , then calculate mod(S d ,Z DBLTKM ) is used to determine the construction method of the diagonal block local transpose key matrix and calculate mod(S p ,Z SUEO ) is used to determine the encryption order and calculate mod(S c ,Z AM ) is used to determine the choice of updating the modulus value. new , the new modulus value q, and the new encryption order are determined, and the RFID tag uses the new key matrix A new and modulus q to N t +1‖ID is encrypted and recorded as E(N t +1‖ID,A new ,q); if N t If it is not equal to the random number passed previously, the RFID tag fails to authenticate the reader and the protocol terminates;
[0046] (11) RFID tag sends E(N t +1‖ID,A new ,q) to the reader;
[0047] (12) The reader calculates mod(S d ,Z DBLTKM )、mod(S p ,Z SUEO ), and mod(S c ,Z AM ) value, and then based on the newly obtained decryption matrix B new and modulus q, E(N t+1‖ID,A new ,q) to decrypt, if the random number N t If it is equal to the random number passed before, the ID is obtained and the reader uses the new encryption matrix A new and modulus q to N r +1‖ID is encrypted and recorded as E(N r +1‖ID,A new ,q); if the random number N t If it is not equal to the random number passed previously, the reader fails to authenticate the RFID tag and the protocol terminates;
[0048] (13) The reader sends E(N r +1‖ID,A new ,q) to the server;
[0049] (14) Server calculation mod (S d ,Z DBLTKM )、mod(S p ,Z SUEO ), and mod(S c ,Z AM ) value, and then based on the newly obtained decryption matrix B new and modulus q, E(N r +1‖ID,A new ,q) to decrypt, if the random number N r If the random number N is equal to the random number passed before, the server successfully authenticates the RFID tag and obtains the ID; r If it is not equal to the random number passed previously, the server fails to authenticate the RFID tag and the protocol terminates.
[0050] Furthermore, after step 4, the RFID security authentication protocol based on the block-sequence-module variable key matrix encryption algorithm is formally analyzed through BAN logic, as follows:
[0051] First, the syntax and semantics of the BAN logic involved in the protocol are determined;
[0052] Secondly, the BAN logic rules used in the protocol are summarized;
[0053] Then, determine the idealized message model of the protocol;
[0054] Next, the initialization assumptions of the BAN logic proof protocol are listed;
[0055] Finally, the reasoning goal of BAN logic proof is determined and deduced to prove that the protocol can achieve the expected goal.
[0056] An RFID security authentication system based on a block-sequence-modular key matrix encryption algorithm, the system is used to implement the RFID security authentication protocol method based on the block-sequence-modular key matrix encryption algorithm, including a model building module, a new encryption algorithm design module and a security authentication protocol construction module, wherein:
[0057] The model building module is used to build a system model of the mobile RFID network;
[0058] The novel encryption algorithm design module is used to design an adaptive module value encryption algorithm, a self-updating encryption sequence encryption algorithm, a diagonal block local transposition key matrix encryption algorithm, and a block-sequence-module variable key matrix encryption algorithm to address the problem that the fixed module value and key matrix in the traditional matrix encryption algorithm damage security;
[0059] The security authentication protocol construction module is used to construct an RFID security authentication protocol based on a block-sequence-modular variable key matrix encryption algorithm according to the block-sequence-modular variable key matrix encryption algorithm.
[0060] A mobile terminal comprises a memory, a processor and a computer program stored in the memory and executable on the processor. When the processor executes the program, the RFID security authentication protocol method based on the block-sequence-module variable key matrix encryption algorithm is implemented.
[0061] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps in the RFID security authentication protocol method based on a block-sequence-module variable key matrix encryption algorithm.
[0062] Compared with the prior art, the present invention has the following significant advantages: (1) without the need to store a new key matrix, the feasible domain of the key space is expanded, thereby improving the security of the protocol; (2) a fast convolution Winograd algorithm is used to accelerate protocol design, thereby improving the real-time performance of the algorithm; (3) a mobile RFID system in which mutual authentication is required for communication between a server, a reader, and an RFID tag, thereby improving the security of the mobile RFID system; and (4) a block-sequence-modular key matrix encryption algorithm is adopted, which saves 99.59% of the RFID tag storage space compared to the traditional encryption algorithm, and is suitable for deployment in low-cost RFID tags with limited storage resources. BRIEF DESCRIPTION OF THE DRAWINGS
[0063] Figure 1 The present invention is a flow chart of an RFID security authentication protocol based on a block-sequence-module variable key matrix encryption algorithm.
[0064] Figure 2It is a schematic diagram of the principle of the block-sequence-module variable key matrix encryption algorithm in the present invention.
[0065] Figure 3 Schematic diagram for comparing a mobile RFID system and a traditional RFID system in an embodiment of the present invention.
[0066] Figure 4 A schematic diagram comparing the adaptive modulus encryption algorithm designed in an embodiment of the present invention and the traditional key matrix encryption algorithm.
[0067] Figure 5 It is a schematic diagram comparing the self-updating encryption sequence encryption algorithm and the traditional key matrix encryption algorithm in an embodiment of the present invention.
[0068] Figure 6 Schematic diagram for comparing diagonal block local transposition key matrix encryption algorithms in an embodiment of the present invention.
[0069] Figure 7 The figure is a flow chart of an RFID security authentication protocol based on a block-sequence-module variable key matrix encryption algorithm in an embodiment of the present invention.
[0070] Figure 8 This is a curve diagram showing the relationship between the RFID tag storage space saving ratio and the number of key matrices in an embodiment of the present invention.
[0071] Fig. 9 Graph showing the relationship between the number of operands and the length of plaintext in an embodiment of the present invention. DETAILED DESCRIPTION
[0072] The present invention provides a radio frequency identification (RFID) security authentication protocol method and system based on a block-sequence-modulus key matrix encryption algorithm. The protocol method is specifically as follows: first, a system model of a mobile RFID network is constructed; then, in view of the problem that the fixed modulus and key matrix in the traditional matrix encryption algorithm are detrimental to security, adaptive modulus (AM), self-updating encryption order (SUEO) and diagonal block local transpose key matrix (DBLTKM) encryption algorithms are proposed in turn; further, based on the above three new encryption algorithms, a joint block-sequence-modulus matrix encryption algorithm, namely AM-SUEO-DBLTKM algorithm, is constructed; finally, based on the joint algorithm, a security authentication protocol suitable for low-cost RFID tags is proposed. The system includes four modules: model construction, encryption algorithm design, security authentication protocol proposal, and formal analysis and verification. The results of formal verification, informal security analysis, and performance analysis show that the block-sequence-modular variable key matrix encryption method designed in the present invention can save 99.59% of the tag storage space compared with the traditional encryption method, indicating that the proposed new RFID security authentication protocol is suitable for low-cost RFID tags and can effectively resist various typical attacks that RFID systems are often subjected to.
[0073] The present invention will be further described in detail below in conjunction with the accompanying drawings and specific embodiments.
[0074] Combination Figure 1 The present invention provides an RFID security authentication protocol method based on a block-sequence-modular key matrix encryption algorithm, comprising the following steps:
[0075] Step 1: Construct a system model of the mobile RFID network, as follows:
[0076] Step 1.1: Figure 2 As shown in the figure, unlike the traditional RFID system, in the mobile RFID (Radio frequency identification) system, the server, reader and RFID tag all communicate with each other through radio frequency signals, that is, wireless insecure communication; during communication, the server and reader, and the reader and RFID tag need to authenticate each other, and only after the authentication is successful can the subsequent confidential information be transmitted;
[0077] Step 1.2: Analyze the mathematical principle of the key matrix encryption and decryption algorithm:
[0078] Theorem 1: If p is a positive integer, a is an integer, and p and a are relatively prime, then the congruence equation ax≡1mod(p) has a unique solution modulo p, that is, there exists a positive integer a′<p such that aa′≡1mod(p).
[0079] Corollary 1: If A and B are both integer square matrices, and A×B≡Emod(p), where E is the identity matrix, then B is called the modulo p inverse matrix of A.
[0080] It can be concluded that the condition for the existence of a modulo p inverse matrix of an n-order integer matrix A is that the value of the determinant of the matrix A is relatively prime to p. According to Theorem 1 and Corollary 1, for a given n-order integer matrix A, if the value of its determinant is relatively prime to the integer p, the modulo p inverse matrix B of the matrix A can be obtained by using elementary transformation methods. The encryption and decryption process of the key matrix can be established using A, B and p as follows:
[0081] E(t,A,p)=A×t mod(p)=c (1)
[0082] D(c,B,p)=B×c mod(p)=t (2)
[0083] Where E(·), D(·), t, and c represent the encryption process, decryption process, plaintext, and ciphertext, respectively.
[0084] According to the above encryption and decryption process, in the traditional key matrix-based RFID security authentication protocol, a possible approach to improve the security of the protocol is to directly store multiple sets of encryption and decryption matrices. Compared with a single key matrix, this method of pre-sharing multiple sets of key matrices can improve the security of the protocol, but it is not suitable for use in low-cost RFID tags with limited storage resources.
[0085] Step 2: Construct the adaptive modulus value (AM) encryption algorithm, the self-updating encryption order (SUEO) encryption algorithm, and the diagonal block local transposition key matrix (DBLTKM) encryption algorithm, as follows:
[0086] Step 2.1: Construct an adaptive modulus encryption algorithm:
[0087] Theorem 2: If positive integers a and p are relatively prime, then a and q are also relatively prime, where q is an integer divisor of p.
[0088] Corollary 2: If A and B are both integer square matrices, and A×B≡Emod(p), where E is the identity matrix, then B is the modulo p inverse matrix of A. At the same time, B is also the modulo q inverse matrix of A, where q is an integer divisor of p.
[0089] Theorem 3: For any positive integers a, b and c, if a and c are relatively prime, and b and c are relatively prime, then a×b and c are relatively prime.
[0090] If the integer p and the determinant of matrix A are coprime, then the integer divisor q of p is also coprime to the determinant of matrix A, and p×q is still coprime to the determinant of matrix A. Thus, the AM algorithm is constructed, and the integer divisors q and p×q modulo p are used to multiply the key matrix A respectively to encrypt and decrypt the data, which can achieve 2Q encryption and decryption, where Q is the number of integer divisors modulo p that do not contain 1;
[0091] It can be concluded that if the integer p and the determinant of matrix A are coprime, then the integer divisor q of p is also coprime to the determinant of matrix A, and p×q is still coprime to the determinant of matrix A. Thus, the AM algorithm is constructed, and the integer divisors q and p×q of modulo p are multiplied with the key matrix A respectively to encrypt and decrypt the data, which can achieve 2Q encryption and decryption, where Q is the number of integer divisors of modulo p that do not contain 1. Figure 3 As shown, taking modulus p=16 as an example, the traditional key matrix encryption algorithm can only achieve one encryption under a constant modulus, while in the constructed adaptive modulus encryption algorithm, 2Q=8 encryptions can be achieved, where Q is the number of integer divisors of the modulus p that does not include 1.
[0092] Step 2.2: Build a self-updating encryption sequence encryption algorithm:
[0093] Theorem 4: If A and B are both integer matrices, then det(A×B)=det(A)×det(B), where det(·) represents the determinant of the matrix.
[0094] Theorem 5: In general, if A and B are both integer matrices and A≠B, then A×B≠B×A.
[0095] Corollary 3: If A1 and A2 are both integer square matrices, and there exists A1×tmod(p)=c1 and A2×c1mod(p)=c2, and there exists A2×tmod(p)=c3 and A1×c3mod(p)=c4, then c2≠c4.
[0096] It can be concluded that for integer matrices A1 and A2, if A1×tmod(p)=c1 and A2×c1mod(p)=c2, and A2×tmod(p)=c3 and A1×c3mod(p)=c4, then c2≠c4. Thus, the SUEO algorithm is constructed. For multiple key matrices, multiple key matrices are multiplied by matrix multiplication to encrypt and decrypt data.
[0097] Depend on Figure 3It can be seen that the self-updating encryption order encryption algorithm can achieve the purpose of improving security by updating the encryption order of the existing key matrix without increasing the storage overhead of the key matrix. In addition, since a large number of matrix multiplication operations are introduced in the self-updating encryption order encryption algorithm, the fast convolution Winograd algorithm can be used to accelerate the protocol design and improve the real-time performance of the algorithm, as follows:
[0098] For the matrix A=(a1,a2,…,a n ) T and B=(b1,b2,…,b n ),in(·) T represents the transposition operation, a1=(a1,a2,…,a n ), b1=(b1,b2,…,b n ), so for the matrix multiplication C = AB, the element value c 11 It can be expressed as:
[0099] a1·b1=a1×b1+a2×b2+…+a n ×b n (3)
[0100] The Winograd algorithm reduces multiplication operations by adding a small number of addition operations. Matrix multiplication using the Winograd algorithm can be described as follows:
[0101] make When n is an odd number,
[0102]
[0103] When n is an even number,
[0104]
[0105] Comparing (4) and (5), we can find that when n is an odd number, the calculation method is similar to that of an even number, with only one more correction term. For n-order square matrix multiplication, the ordinary algorithm contains n 2 (n-1) addition and n 3 multiplication, while the Winograd algorithm only requires n 2 (n+2) addition and n 2 (n / 2+1) multiplication.
[0106] Step 2.3: Construct the diagonal block local transposition key matrix encryption algorithm:
[0107] Theorem 6: If A is an m-order square matrix and B is an n-order square matrix, then
[0108] Theorem 7: If A is an m-order square matrix, then det(AT )=det(A), where (·) T Represents a transpose operation.
[0109] Corollary 4: If A is an m-order square matrix and there exists A×t mod(p)=c1, then A T ×t mod(p)=c2.
[0110] Corollary 5: If A1 is an m-order square matrix, A2 is an n-order square matrix, and there exists A1×t1mod(p)=c1 and A2×t2 mod(p)=c2, then Where t1 is an m-dimensional vector and t2 is an n-dimensional vector.
[0111] Thus, the diagonal block local transposition key matrix encryption algorithm is constructed. By updating the order of the key matrix on the main diagonal, multiple different key matrices are formed to encrypt and decrypt the data. The diversity of the newly formed key matrix does not require additional storage of new key matrices, that is, the diagonal block local transposition key matrix encryption algorithm expands the feasible domain of the key space without wasting storage space. The comparison between the diagonal block local transposition key matrix encryption algorithm and the traditional key matrix encryption algorithm is as follows: Figure 5 shown.
[0112] Step 3: Based on the AM encryption algorithm, the SUEO encryption algorithm and the DBLTKM encryption algorithm, a block-sequence-modular variable key matrix encryption algorithm, namely the AM-SUEO-DBLTKM algorithm, is constructed. The details are as follows:
[0113] The adaptive modular value encryption algorithm, the self-updating encryption sequence encryption algorithm and the diagonal block local transposition key matrix encryption algorithm can be used to implement the encryption and decryption of the algorithm respectively. Among them, the adaptive modular value encryption algorithm weakens the correlation between plaintext and ciphertext, the self-updating encryption sequence encryption algorithm improves security, and the diagonal block local transposition key matrix encryption algorithm expands the feasible domain of the key space. In order to make full use of the advantages of the three algorithms, a joint block-sequence-modular variable matrix encryption algorithm is constructed. The adaptive modular value encryption algorithm is used to update the modular value to weaken the correlation between plaintext and ciphertext; the self-updating encryption sequence encryption algorithm is used to update the encryption sequence to improve security; the diagonal block local transposition key matrix encryption algorithm is used to update the key matrix to expand the feasible domain of the key space. Taking the key matrix A, B and modulus p=16 as an example, the designed block-sequence-modular variable key matrix encryption algorithm is as follows Figure 6 shown.
[0114] Step 4: Based on the AM-SUEO-DBLTKM algorithm, an RFID security authentication protocol based on the block-sequence-modular key matrix encryption algorithm is constructed, such as Figure 7 As shown, the details are as follows:
[0115] (1) The reader sends a “Query” to the RFID tag;
[0116] (2) The RFID tag responds to the reader and uses its internal pseudo-random number generator to generate a random number N t , then the RFID tag uses the encryption matrix A and the module p to N t ||S is encrypted, where S is the secret value, denoted as E(N t ‖S,A,p);
[0117] (3) RFID tag sends E(N t ‖S,A,p) to the reader;
[0118] (4) The reader responds to the E(N) sent by the RFID tag t ‖S,A,p) to decrypt and obtain the secret value S. If S is queried, the reader authenticates the RFID tag successfully and accepts N t , then the reader generates a random number N r , and use the encryption matrix A and modulus p to N r ||S is encrypted and recorded as E(N r ‖S,A,p); if S is not found, the reader fails to authenticate the RFID tag and the protocol terminates;
[0119] (5) The reader sends E(N r ‖S,A,p) to the server;
[0120] (6) The server sends E(N) to the reader r ‖S,A,p) to decrypt and obtain the secret value S. If S is found, the server authenticates the reader successfully and accepts N r , then the server generates a new secret value S d ,S p ,S c , and use the encryption matrix A and modulus p to N r ||S d ||S p ||S c Encryption is performed, recorded as E(N r ‖S d ‖S p ‖S c ,A,p); if S is not queried, the server fails to authenticate the reader and the protocol terminates;
[0121] (7) The server sends E(N r ‖S d ‖S p ‖S c ,A,p) to the reader;
[0122] (8) The reader sends E(N) to the server r ‖S d ‖S p ‖S c ,A,p) to decrypt and obtain N r , if N r If the random number is equal to the one passed previously, the reader successfully authenticates the server and accordingly, the reader accepts the new secret value S d ,S p ,S c , then the reader uses the encryption matrix A and modulo p to N t ‖S d ‖S p ‖S c Encryption is recorded as E(N t ‖S d ‖S p ‖S c ,A,p); if N r If it is equal to the random number passed previously, the reader fails to authenticate the server and the protocol terminates;
[0123] (9) The reader sends E(N t ‖S d ‖S p ‖S c ,A,p) to RFID tag;
[0124] (10) E(N) sent by RFID tag to the reader t ‖S d ‖S p ‖S c ,A,p) to decrypt and obtain N t , if N t If the random number is equal to the one passed before, the RFID tag successfully authenticates the reader, and accordingly, the RFID tag accepts the new secret value S d ,S p ,S c , then calculate mod(S d ,Z DBLTKM ) is used to determine the construction method of the diagonal block local transpose key matrix and calculate mod(S p ,Z SUEO ) is used to determine the encryption order and calculate mod(S c ,Z AM ) is used to determine the choice of updating the modulus value. new , the new modulus value q, and the new encryption order are determined, and the RFID tag uses the new key matrix A new and modulus q to N t +1‖ID is encrypted and recorded as E(Nt +1‖ID,A new ,q); if N t If it is not equal to the random number passed previously, the RFID tag fails to authenticate the reader and the protocol terminates;
[0125] (11) RFID tag sends E(N t +1‖ID,A new ,q) to the reader;
[0126] (12) The reader calculates mod(S d ,Z DBLTKM )、mod(S p ,Z SUEO ), and mod(S c ,Z AM ) value, and then based on the newly obtained decryption matrix B new and modulus q, E(N t +1‖ID,A new ,q) to decrypt, if the random number N t If it is equal to the random number passed before, the ID is obtained and the reader uses the new encryption matrix A new and modulus q to N r +1‖ID is encrypted and recorded as E(N r +1‖ID,A new ,q); if the random number N t If it is not equal to the random number passed previously, the reader fails to authenticate the RFID tag and the protocol terminates;
[0127] (13) The reader sends E(N r +1‖ID,A new ,q) to the server;
[0128] (14) Server calculation mod (S d ,Z DBLTKM )、mod(S p ,Z SUEO ), and mod(S c ,Z AM ) value, and then based on the newly obtained decryption matrix B new and modulus q, E(N r +1‖ID,A new ,q) to decrypt, if the random number N r If the random number N is equal to the random number passed before, the server successfully authenticates the RFID tag and obtains the ID; r If it is not equal to the random number passed previously, the server fails to authenticate the RFID tag and the protocol terminates.
[0129] BAN logic analysis is a type of modal logic, which has been used to verify the security of many authentication protocols. The following is a formal analysis of the designed RFID security authentication protocol based on the block-sequence-modular key matrix encryption algorithm through BAN logic, as follows:
[0130] (1) The syntax and semantics of the BAN logic involved in the RFID security authentication protocol based on the block-sequence-modular variable key matrix encryption algorithm are shown in Table 1.
[0131] Table 1 Syntax and semantics of BAN logic
[0132]
[0133] (2) The BAN logic rules used in the RFID security authentication protocol based on the block-sequence-modular key matrix encryption algorithm are summarized as shown in Table 2.
[0134] Table 2 BAN logic rules
[0135]
[0136] (3) The idealized message model of the RFID security authentication protocol based on the block-sequence-modular variable key matrix encryption algorithm is shown in Table 3.
[0137] Table 3 Idealized message model
[0138]
[0139] (4) The initialization assumptions of the RFID security authentication protocol based on the block-sequence-modular key matrix encryption algorithm proved by BAN logic are shown in Table 4.
[0140] Table 4 Initialization assumptions
[0141]
[0142] (5) The reasoning objectives of BAN logic proof are shown in Table 5.
[0143] Table 5 Reasoning objectives
[0144]
[0145] (6) The specific reasoning process of the agreement is as follows:
[0146] Through M1, A1 and R1, it can be deduced that:
[0147] R∣≡T∣~{N t ‖S}(6) Through A2 and R4, it can be deduced that:
[0148] R∣≡#{Nt ‖S}(7) can be derived from equation (6), equation (7) and R2:
[0149] R∣≡T∣≡{N t ‖S}(8) Through formula (8), A3 and R3, it can be deduced that:
[0150] R∣≡{N t ‖S}(9) Formula (9) shows that the reasoning target shown in G1 is derived.
[0151] Through M2, A4 and R1, it can be deduced that:
[0152] S∣≡R∣~{N r ‖S}(10) can be derived through A5 and R4:
[0153] S∣≡#{N r ‖S}(11) can be derived from equation (10), equation (11) and R2:
[0154] S|≡R|≡{N r ‖S}(12) Through formula (12), A6 and R3, it can be derived that:
[0155] S|≡{N r ‖S}(13) Formula (13) shows that the reasoning target shown in G2 is derived.
[0156] Through M3, A7 and R1, it can be deduced that:
[0157] R∣≡S∣~{N r ‖S d ‖S p ‖S c}(14)
[0158] Through A8 and R4, it can be deduced that:
[0159] R∣≡#(N r ‖S d ‖S p ‖S c )(15) Through formula (14), formula (15) and R2, it can be deduced that:
[0160] R∣≡S∣≡{N r ‖S d ‖S p ‖S c}(16)
[0161] Through formula (16), A9 and R3, it can be deduced that:
[0162] R∣≡{N r ‖S d ‖Sp ‖S c}(17)Equation (17) shows that the inference target shown in G3 is derived.
[0163] Through M4, A10 and R1, it can be deduced that:
[0164] T∣≡R∣~{N t ‖S d ‖S p ‖S c}(18) Through A11 and R4, it can be deduced that:
[0165] T∣≡#{N t ‖S d ‖S p ‖S c}(19)
[0166] Through formula (18), formula (19) and R2, it can be deduced that:
[0167] T∣≡R∣≡{N t ‖S d ‖S p ‖S c}(20)
[0168] Through formula (20), A12 and R3, it can be deduced that:
[0169] T∣≡{N t ‖S d ‖S p ‖S c}(twenty one)
[0170] Formula (21) shows that the reasoning target shown in G4 is derived.
[0171] Through M5, A1 and R1, it can be deduced that:
[0172] R∣≡T∣~{N t +1‖ID}(22)
[0173] Through A13 and R4, it can be deduced that:
[0174] R∣≡#{N t +1‖ID}(23)
[0175] Through formula (22), formula (23) and R2, it can be deduced that:
[0176] R∣≡T∣≡{N t +1‖ID}(24)
[0177] Through formula (24), A14 and R3, it can be deduced that:
[0178] R∣≡{Nt +1‖ID}(25)
[0179] Formula (25) shows that the reasoning target shown in G5 is derived.
[0180] Through M6, A4 and R1, it can be deduced that:
[0181] S∣≡R∣~{N r +1 ‖ID}(26)
[0182] Through A15 and R4, it can be deduced that:
[0183] S∣≡#{N r +1‖ID}(27)
[0184] Through formula (26), formula (27) and R2, it can be deduced that:
[0185] S|≡R|≡{N r +1‖ID}(28)
[0186] Through formula (28), A16 and R3, it can be deduced that:
[0187] S|≡{N r +1‖ID}(29)
[0188] Formula (29) shows that the reasoning target shown in G6 is derived.
[0189] The present invention also provides an RFID security authentication system based on a block-sequence-module variable key matrix encryption algorithm, comprising a model building module, a new encryption algorithm design module and a security authentication protocol construction module:
[0190] The model building module is used to build a system model of the mobile RFID network;
[0191] The novel encryption algorithm design module is used to design an adaptive module value encryption algorithm, a self-updating encryption sequence encryption algorithm, a diagonal block local transposition key matrix encryption algorithm, and a block-sequence-module variable key matrix encryption algorithm to address the problem that the fixed module value and key matrix in the traditional matrix encryption algorithm damage security;
[0192] The security authentication protocol construction module is used to construct an RFID security authentication protocol based on a block-sequence-modular variable key matrix encryption algorithm according to the block-sequence-modular variable key matrix encryption algorithm.
[0193] The present invention also provides a mobile terminal, including a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor implements the RFID security authentication protocol based on the block-sequence-modular key matrix encryption algorithm when executing the program.
[0194] The present invention also provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the steps in the RFID security authentication protocol based on the block-sequence-module variable key matrix encryption algorithm are implemented.
[0195] In summary, after BAN logic formal analysis, the designed RFID security authentication protocol based on block-sequence-module variable key matrix encryption algorithm can achieve the expected goal.
[0196] Example
[0197] This embodiment provides a simulation embodiment in which the number of key matrices N=3 and the plaintext length n=2.
[0198] Figure 8 The simulation curve between the tag storage space saving ratio and the number of key matrices is shown. As can be seen from the figure, as the key matrix increases, the tag storage space saving ratio increases. In addition, the designed RFID security authentication protocol based on block-sequence-modular variable key matrix encryption algorithm (AM-SUEO-DBLTKM-RFID) can save the most tag storage space. Compared with the traditional key matrix algorithm, it can save 99.59% of the tag storage space, followed by the diagonal block local transposition key matrix encryption algorithm (DBLTKM), adaptive modulus encryption algorithm (AM), and self-updating encryption order encryption algorithm (SUEO).
[0199] Fig. 9 The simulation curve between the number of operations and the length of the plaintext is shown. As can be seen from the figure, the protocol can be accelerated by using the Winograd algorithm. Specifically, after using the Winograd algorithm, the amount of multiplication operations is greatly reduced (44.44%) by adding a small amount (15.00%) of addition operations.
[0200] The above are only preferred embodiments of the present invention. It should be pointed out that, for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.
Claims
1. A RFID security authentication protocol method based on a block-sequence-modular key matrix encryption algorithm, characterized in that: The following steps are involved: Step 1: Construct a system model of mobile RFID network; Step 2, construct an adaptive modulus encryption algorithm, namely AM, a self-updating encryption order, namely SUEO, and a diagonal block local transposition key matrix, namely DBLTKM; Step 3: Based on the AM encryption algorithm, the SUEO encryption algorithm and the DBLTKM encryption algorithm, a block-sequence-modular variable key matrix encryption algorithm is constructed, namely, the AM-SUEO-DBLTKM algorithm; Step 4: Based on the AM-SUEO-DBLTKM algorithm, an RFID security authentication protocol based on the block-sequence-modular variable key matrix encryption algorithm is constructed.
2. The RFID security authentication protocol method based on the block-sequence-modular key matrix encryption algorithm according to claim 1 is characterized in that: The system model of building a mobile RFID network in step 1 is as follows: Step 1.1: In the mobile RFID system, the server, reader and RFID tag all communicate with each other through radio frequency signals, i.e. wireless insecure communication. During communication, the server and reader, and the reader and RFID tag need to authenticate each other. Only after successful authentication can the subsequent confidential information be transmitted. Step 1.2, the mathematical principle of the key matrix encryption and decryption algorithm is: for a given n-order integer matrix A, if the value of its determinant is coprime with the integer p, the inverse matrix B of the matrix A modulo p can be obtained by using elementary transformation methods. The encryption and decryption process of using A, B and p to establish the key matrix is as follows: E(t,A,p)=A×tmod(p)=c D(c,B,p)=B×cmod(p)=t Where E(·), D(·), t, and c represent the encryption process, decryption process, plaintext, and ciphertext, respectively.
3. The RFID security authentication protocol method based on the block-sequence-modular key matrix encryption algorithm according to claim 1 is characterized in that: The construction of the adaptive modulus value, namely the AM encryption algorithm, the self-updating encryption order, namely the SUEO encryption algorithm, and the diagonal block local transposition key matrix, namely the DBLTKM encryption algorithm in step 2 is as follows: Step 2.1: Construct an adaptive modulus encryption algorithm: If the integer p and the determinant of matrix A are coprime, then the integer divisor q of p is also coprime to the determinant of matrix A, and p×q is still coprime to the determinant of matrix A. Thus, the AM encryption algorithm is constructed, and the integer divisors q and p×q modulo p are used to multiply the key matrix A respectively to encrypt and decrypt the data, achieving 2Q encryption and decryption, where Q is the number of integer divisors of modulo p that do not contain 1; Step 2.2: Build a self-updating encryption sequence encryption algorithm: For integer square matrices A1 and A2, if A1×tmod(p)=c1 and A2×c1 mod(p)=c2, and A2×tmod(p)=c3 and A1×c3 mod(p)=c4, then c2≠c4. Thus, the SUEO algorithm is constructed. For multiple key matrices, multiple key matrices are multiplied by matrix multiplication to encrypt and decrypt data. Step 2.3: Construct the diagonal block local transposition key matrix encryption algorithm: If A1 is an m-order square matrix, A2 is an n-order square matrix, and there exists A1×t1mod(p)=c1 and A2×t2 mod(p)=c2, then Where t1 is an m-dimensional vector and t2 is an n-dimensional vector. The DBLTKM algorithm is constructed based on this. By updating the order of the key matrix on the main diagonal, multiple different key matrices are formed to encrypt and decrypt the data.
4. The RFID security authentication protocol method based on the block-sequence-modular key matrix encryption algorithm according to claim 3 is characterized in that: In step 2.2, multiple key matrices are multiplied by matrix multiplication, using the fast convolution Winograd algorithm, as follows: For the matrix A=(a1,a2,…,a n ) T and B=(b1,b2,…,b n ),in(·) T represents the transposition operation, a1=(a1,a2,…,a n ), b1=(b1,b2,…,b n ), so for the matrix multiplication C = AB, the element value c 11 is represented as: a1·b1=a1×b1+a2×b2+…+a n ×b n The Winograd algorithm reduces multiplication operations by adding a small number of addition operations. The matrix multiplication using the Winograd algorithm is described as follows: make When n is an odd number, When n is an even number, When n is an odd number, the calculation method is similar to that of an even number, with only one more correction term. For n-order square matrix multiplication, the Winograd algorithm only needs n 2 (n+2) addition and n 2 (n / 2+1) multiplication.
5. The RFID security authentication protocol method based on block-sequence-modular key matrix encryption algorithm according to claim 1 is characterized in that: In step 3, based on the AM encryption algorithm, the SUEO encryption algorithm and the DBLTKM encryption algorithm, a block-sequence-modular variable key matrix encryption algorithm, namely the AM-SUEO-DBLTKM algorithm, is constructed as follows: The block-sequence-module variable key matrix encryption algorithm is constructed. The AM encryption algorithm updates the module value to weaken the correlation between plaintext and ciphertext; the SUEO encryption algorithm is used to update the encryption order to improve security; the DBLTKM encryption algorithm is used to update the key matrix and expand the feasible domain of the key space.
6. The RFID security authentication protocol method based on block-sequence-modular variable key matrix encryption algorithm according to claim 4 is characterized in that: In step 4, based on the AM-SUEO-DBLTKM algorithm, an RFID security authentication protocol based on a block-sequence-modular variable key matrix encryption algorithm is constructed, as follows: (1) The reader sends a "Query" to the RFID tag; (2) The RFID tag responds to the reader and uses its internal pseudo-random number generator to generate a random number N t , then the RFID tag uses the encryption matrix A and the module p to N t ||S is encrypted, where S is the secret value, denoted as E(N t ‖S,A,p); (3) RFID tag sends E(N t ‖S,A,p) to the reader; (4) The reader responds to the E(N) sent by the RFID tag t ‖S,A,p) to decrypt and obtain the secret value S. If S is queried, the reader authenticates the RFID tag successfully and accepts N t , then the reader generates a random number N r , and use the encryption matrix A and modulus p to N r ||S is encrypted and recorded as E(N r ‖S,A,p); if S is not found, the reader fails to authenticate the RFID tag and the protocol terminates; (5) The reader sends E(N r ‖S,A,p) to the server; (6) The server sends E(N) to the reader r ‖S,A,p) to decrypt and obtain the secret value S. If S is found, the server authenticates the reader successfully and accepts N r , then the server generates a new secret value S d ,S p ,S c , and use the encryption matrix A and modulus p to N r ||S d ||S p ||S c Encryption is performed, recorded as E(N r ‖S d ‖S p ‖S c ,A,p); if S is not queried, the server fails to authenticate the reader and the protocol terminates; (7) The server sends E(N r ‖S d ‖S p ‖S c ,A,p) to the reader; (8) The reader sends E(N) to the server r ‖S d ‖S p ‖S c ,A,p) to decrypt and obtain N r , if N r If the random number is equal to the one passed previously, the reader successfully authenticates the server and accordingly, the reader accepts the new secret value S d ,S p ,S c , then the reader uses the encryption matrix A and modulo p to N t ‖S d ‖S p ‖S c Encryption is performed, recorded as E(N t ‖S d ‖S p ‖S c ,A,p); if N r If it is equal to the random number passed previously, the reader fails to authenticate the server and the protocol terminates; (9) The reader sends E(N t ‖S d ‖S p ‖S c ,A,p) to RFID tag; (10) E(N) sent by RFID tag to the reader t ‖S d ‖S p ‖S c ,A,p) to decrypt and obtain N t , if N t If the random number is equal to the one passed before, the RFID tag successfully authenticates the reader, and accordingly, the RFID tag accepts the new secret value S d ,S p ,S c , then calculate mod(S d ,Z DBLTKM ) is used to determine the construction method of the diagonal block local transpose key matrix and calculate mod(S p ,Z SUEO ) is used to determine the encryption order and calculate mod(S c ,Z AM ) is used to determine the choice of updating the modulus value. new , the new modulus value q, and the new encryption order are determined, and the RFID tag uses the new key matrix A new and modulus q to N t +1‖ID is encrypted and recorded as E(N t +1‖ID,A new ,q); if N t If it is not equal to the random number passed previously, the RFID tag fails to authenticate the reader and the protocol terminates; (11) RFID tag sends E(N t +1‖ID,A new ,q) to the reader; (12) The reader calculates mod(S d ,Z DBLTKM )、mod(S p ,Z SUEO ), and mod(S c ,Z AM ) value, and then based on the newly obtained decryption matrix B new and modulus q, E(N t +1‖ID,A new ,q) to decrypt, if the random number N t If it is equal to the random number passed before, the ID is obtained and the reader uses the new encryption matrix A new and modulus q to N r +1‖ID is encrypted and recorded as E(N r +1‖ID,A new ,q); if the random number N t If it is not equal to the random number passed previously, the reader fails to authenticate the RFID tag and the protocol terminates; (13) The reader sends E(N r +1‖ID,A new ,q) to the server; (14) Server calculation mod (S d ,Z DBLTKM )、mod(S p ,Z SUEO ), and mod(S c ,Z AM ) value, and then based on the newly obtained decryption matrix B new and modulus q, E(N r +1‖ID,A new ,q) to decrypt, if the random number N r If it is equal to the random number passed previously, the server successfully authenticates the RFID tag and obtains the ID; If the random number N r If it is not equal to the random number passed previously, the server fails to authenticate the RFID tag and the protocol terminates.
7. The RFID security authentication protocol method based on the block-sequence-modular key matrix encryption algorithm according to claim 6 is characterized in that: After step 4, the RFID security authentication protocol based on the block-sequence-modular key matrix encryption algorithm is formally analyzed through BAN logic, as follows: First, the syntax and semantics of the BAN logic involved in the protocol are determined; Secondly, the BAN logic rules used in the protocol are summarized; Then, determine the idealized message model of the protocol; Next, the initialization assumptions of the BAN logic proof protocol are listed; Finally, the reasoning goal of BAN logic proof is determined and deduced to prove that the protocol can achieve the expected goal.
8. An RFID security authentication system based on a block-sequence-modular key matrix encryption algorithm, characterized in that: The system is used to implement the RFID security authentication protocol method based on the block-sequence-modular variable key matrix encryption algorithm according to any one of claims 1 to 7, comprising a model building module, a new encryption algorithm design module and a security authentication protocol construction module, wherein: The model building module is used to build a system model of the mobile RFID network; The novel encryption algorithm design module is used to design an adaptive module value encryption algorithm, a self-updating encryption sequence encryption algorithm, a diagonal block local transposition key matrix encryption algorithm, and a block-sequence-module variable key matrix encryption algorithm to address the problem that the fixed module value and key matrix in the traditional matrix encryption algorithm damage security; The security authentication protocol construction module is used to construct an RFID security authentication protocol based on a block-sequence-modular variable key matrix encryption algorithm according to the block-sequence-modular variable key matrix encryption algorithm.
9. A mobile terminal comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the RFID security authentication protocol method based on the block-sequence-modular variable key matrix encryption algorithm as described in any one of claims 1 to 7 is implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps in the RFID security authentication protocol method based on the block-sequence-modular variable key matrix encryption algorithm as described in any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Group based key array security authentication protocol in RFID (Radio Frequency Identification) system
CN106027237A
Method and apparatus for the generation of cryptographic keys
US7415110B1