RFID intelligent card copy verification and initialization method and system

By performing copy verification and dynamic encryption processing on Mifare 1K cards, the problem of ineffective card copying and forgery in the prior art is solved, and the high security of the RFID system and the uniqueness of legal cards are achieved.

CN120217342APending Publication Date: 2025-06-27SHENZHEN CARD SMART TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510280873.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-10
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The prior art cannot effectively prevent copying and forgery based on Mifare 1K cards, especially after the card key is cracked, the security of the system almost crashes.

Method used

The RFID smart card copy verification method is used to completely copy the legitimate original RFID smart card, read the copied data on the copy card, and compare it with the historical data in the card reader. If it is consistent, the first swipe of the copy card passes verification. Then, the sector address of the copy key and card number data access is determined through the encryption function, the card number data is read, and when the legal original RFID smart card swipes, the target encryption factor is replaced to prevent the subsequent card swiping of the copy card.

Benefits of technology

It effectively improves the security of the RFID system, prevents card copying and forgery, ensures the uniqueness and security of legal cards, and avoids the security risks that arise after the key is cracked.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120217342A_ABST
    Figure CN120217342A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of RFID intelligent cards, solves the problems that copied cards cannot be effectively detected and the system security is low in the prior art, and provides an RFID intelligent card copy verification and initialization method and system. The method comprises the steps that duplicated data and historical data are compared, if the duplicated data and the historical data are consistent, verification is passed, the duplicated data comprise a first duplicated encryption factor and a duplicated identifier, and the historical data comprise a target encryption factor and a unique identifier; determining a copy key and a copy sector address according to the first encryption function; according to the copy key and the copy sector address, when the card number data is successfully read, determining a second copy encryption factor according to a second encryption function, and replacing the target encryption factor with the second copy encryption factor; and when the original RFID smart card is swiped, the card is determined to be an illegal card, and the owner of the original card is reminded. According to the invention, the abuse of the copy card is effectively detected and prevented, and the system safety is improved.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of the invention patent application with the application date of December 10, 2024, the invention name of "A Method and System for Initializing and Dynamically Encrypting an Anti-Copy RFID Smart Card", and the application number of 202411803858.1. Technical Field

[0002] The present invention relates to the technical field of RFID smart cards, and in particular, to a method and system for RFID smart card replication verification and initialization. Background Art

[0003] With the wide application of RFID technology, Mifare 1K smart cards have been widely used in multiple scenarios such as access control, public transportation payment, and campus cards. The storage space of the Mifare 1K card is divided into 16 sectors, each sector contains 4 blocks, and the length of each block is 16 bytes. The last block of each sector usually stores the key of that sector, which is used to control the read and write permissions of that sector. In traditional applications, specific sectors are assigned to specific applications, and data security is protected by setting keys. However, with the cracking of encryption algorithms, the keys of Mifare 1K cards are easily obtained by attackers using low-cost tools, resulting in a serious decline in system security. Attackers can copy RFID smart cards and perform illegal card swiping operations, thereby obtaining improper access permissions and causing security risks.

[0004] In the prior art, for the cracking of Mifare 1K cards, the main solution is to upgrade to higher security-level chips, such as CPU cards, which can provide stronger encryption protection and resist cracking and replication attacks; however, such high-security-level chips usually have higher costs, and the deployment and maintenance costs also increase accordingly. Therefore, in some application scenarios with high security requirements, there is still a balance problem between cost and security. At the same time, the prior art cannot effectively prevent the replication and forgery of Mifare 1K cards. Especially after the card key is cracked, the security of the system almost collapses; the existing security protection measures usually focus on strengthening encryption protection, but cannot effectively prevent the behavior of illegally swiping cards by replicating legitimate cards. Therefore, the above problems still pose a difficult-to-solve security risk for many access control systems and other systems based on Mifare 1K cards.

[0005] The existing Chinese patent CN106529651A discloses a radio frequency card using a dual encryption algorithm. The radio frequency card uses dual encryption. The first encryption method: using encryption key 1, encrypting the card ID number through encryption algorithm 1 to obtain the card read-write password. The password is 32 bits, and the 32-bit password is written into storage block block7. The second encryption method: using encryption key 2 different from the first encryption key, obtaining a data password through encryption algorithm 2, and encrypting user data with the data password into exchange data and then writing it into card data storage blocks block1 - block6. Although the above patent obtains the read-write password by encrypting the ID number of the radio frequency card, and the password of each card is generated based on a unique ID number, so the password of each card is different, the encryption of the card ID number is essentially static. That is to say, once the ID number is cracked or leaked, the attacker can calculate the corresponding password based on the ID of the card; if the attacker obtains the ID number of a certain card and relevant information about encryption algorithm 1, such as key 1 and the encryption algorithm, they can use the same algorithm to crack it, thus avoiding password reset or additional encryption steps during batch replication.

[0006] Therefore, how to effectively detect duplicate cards and improve system security is an urgent problem to be solved. Summary of the Invention

[0007] In view of this, the present invention provides an RFID smart card replication verification and initialization method and system to solve the problem in the prior art that duplicate cards cannot be effectively detected and the system security is low.

[0008] The technical solution adopted by the present invention is as follows:

[0009] In the first aspect, the present invention provides an RFID smart card replication verification method, and the method includes:

[0010] Completely replicate a legitimate original RFID smart card and read the replication data on the replicated card;

[0011] Compare the replication data with the historical data in the card reader. If the replication data and the historical data are consistent, the first-time swipe of the replicated card passes the verification. Among them, the replication data includes a first replication encryption factor and a replication identifier, and the historical data includes a target encryption factor and a unique identifier;

[0012] According to a first encryption function, encrypt the first replication encryption factor and the replication identifier to determine a replication key and a replication sector address for accessing card number data;

[0013] Read the card number data according to the replication key and the replication sector address;

[0014] When the card number data is successfully read, according to the second encryption function, encrypt the replication identifier and the replication sector address to determine the second replication encryption factor, and replace the target encryption factor with the second replication encryption factor;

[0015] When a legitimate original RFID smart card is swiped, compare the target encryption factor with the second replication encryption factor to determine that the original RFID smart card is an illegal card and alert the original card holder.

[0016] Preferably, before completely replicating the legitimate original RFID smart card and reading the replication data on the replicated card, it further includes:

[0017] Read the real-time encryption factor in the preset sector, and compare the real-time encryption factor with the initial encryption factor;

[0018] If the initial encryption factor is the same as the real-time encryption factor, it is the first card swipe, and obtain the unique identifier of the RFID smart card;

[0019] According to the first encryption function, encrypt the real-time encryption factor and the unique identifier to obtain the first key and the first sector address for accessing the card number data;

[0020] Read the card number data according to the first key and the first sector address;

[0021] When the card number data is successfully read, according to the second encryption function, encrypt the first sector address and the unique identifier to determine a new target encryption factor;

[0022] Write the target encryption factor into the sector where the real-time encryption factor is located. According to the first encryption function, encrypt the target encryption factor and the unique identifier to determine the second key and the second sector address where the card number data is stored;

[0023] Delete the card number data in the first sector address, and write the card number data into the new sector corresponding to the second sector address according to the second sector address.

[0024] Preferably, after reading the real-time encryption factor and comparing the real-time encryption factor with the initial encryption factor, it further includes:

[0025] If the initial encryption factor is different from the real-time encryption factor, compare the real-time encryption factor with the historical encryption factor, and compare the unique identifier of the current RFID smart card with the historical identifier;

[0026] When the real-time encryption factor is the same as the historical encryption factor and the unique identifier is the same as the historical identifier, encrypt the real-time encryption factor and the unique identifier according to the first encryption function to obtain the first key and the address of the first sector where the card number data is stored;

[0027] Read the card number data according to the first key and the first sector address;

[0028] When the card number data is successfully read, encrypt the first sector address and the unique identifier according to the second encryption function to determine a new target encryption factor;

[0029] Replace the original historical encryption factor with the target encryption factor, and encrypt the target encryption factor and the unique identifier according to the first encryption function to determine the second key and the address of the second sector where the card number data is stored;

[0030] Delete the card number data at the first sector address, and write the card number data into the new sector corresponding to the second sector address according to the second sector address.

[0031] Preferably, when the card number data is successfully read, encrypting the first sector address and the unique identifier according to the second encryption function to determine a new target encryption factor includes:

[0032] Perform a multiplication calculation on the first sector address and the unique identifier to determine a fourth string;

[0033] Extract the character at the fourth preset position in the fourth string, and use the extraction result as the target encryption factor.

[0034] Preferably, after replacing the original historical encryption factor with the target encryption factor, encrypting the target encryption factor and the unique identifier according to the first encryption function to determine the second key and the address of the second sector where the card number data is stored, it further includes:

[0035] According to the second sector address, obtain the target read frequency of the sector corresponding to the second sector address, and obtain the read frequencies corresponding to the remaining sectors and a preset frequency threshold;

[0036] Calculate the average value of the read frequencies of each sector according to the target read frequency and the read frequencies corresponding to the remaining sectors;

[0037] If the target read frequency is less than the average value and the target read frequency is less than the frequency threshold, delete the card number data at the first sector address, and write the card number data into the new sector corresponding to the second sector address according to the second sector address;

[0038] If the target read frequency is greater than or equal to the average value and / or the target read frequency is greater than or equal to the frequency threshold, the second sector address is updated through a hash function and a pseudo-random algorithm to determine the third sector address where the card number data is stored;

[0039] Delete the card number data at the first sector address, and write the card number data into the new sector corresponding to the third sector address according to the third sector address.

[0040] Preferably, if the target read frequency is greater than or equal to the average value or the target read frequency is greater than or equal to the frequency threshold, the second sector address is updated through a hash function and a pseudo-random algorithm to determine the third sector address where the card number data is stored, including:

[0041] Combine the unique identifier and the target encryption factor to determine a target string;

[0042] Process the target string through a hash function to determine a hash value;

[0043] Normalize the hash value to convert the hash value into a hash integer value;

[0044] Map the hash integer value to the sector address range according to the hash integer value and the preset sector address range to determine the target sector address;

[0045] According to the hash integer value, the first sector address, the sector address range, and the target sector address, and combining the pseudo-random number generation algorithm, determine the third sector address.

[0046] Preferably, according to the hash integer value, the first sector address, the sector address range, and the target sector address, and combining the pseudo-random number generation algorithm, determining the third sector address includes:

[0047] Initialize the preset pseudo-random number generator according to the hash integer value;

[0048] Input the first sector address into the initialized pseudo-random number generator to determine a pseudo-random number;

[0049] Perform a modulo operation on the pseudo-random number according to the sector address range to determine an offset, where the offset is within the sector address range;

[0050] Perform an addition calculation and a modulo operation on the offset and the target sector address to determine the third sector address.

[0051] Second aspect, the present invention provides an RFID smart card initialization method. The RFID smart card is replicated and verified through the RFID smart card replication and verification method as described above. The initialization method includes:

[0052] Obtain a preset initial encryption factor;

[0053] Write the initial encryption factor into a preset sector, and obtain the unique identifier of the RFID smart card;

[0054] According to a first encryption function, encrypt the unique identifier and the initial encryption factor in the preset sector to determine the initial sector address and the initial key for storing the card number data.

[0055] Preferably, the step of encrypting the unique identifier and the initial encryption factor in the preset sector according to the first encryption function to determine the initial sector address and the initial key for storing the card number data includes:

[0056] Perform an exclusive OR operation on the unique identifier and the initial encryption factor to determine a first string;

[0057] Perform an exclusive OR operation on the character at a first preset position in the unique identifier and the character at a second preset position in the initial encryption factor to determine a second string;

[0058] Combine the first string and the second string to determine the initial key;

[0059] Perform an exclusive OR operation on the character at a third preset position in the unique identifier and the character at a third preset position in the initial encryption factor to determine a third string;

[0060] Determine the initial sector address according to the third string.

[0061] Third aspect, an embodiment of the present invention further provides an RFID smart card replication verification and initialization system. The replication verification system includes an RFID smart card and a card reader. The RFID smart card is initialized through the RFID smart card initialization method as described above, and the card reader replicates and verifies the RFID smart card through the RFID smart card replication and verification method as described above.

[0062] In summary, the beneficial effects of the present invention are as follows:

[0063] The RFID smart card replication verification and initialization method and system provided by the present invention, the method comprising: completely replicating a legitimate original RFID smart card, and reading the replication data on the replicated card; comparing the replication data with the historical data in the card reader, if the replication data and the historical data are consistent, the first swipe of the replicated card passes the verification, wherein the replication data includes a first replicated encryption factor and a replication identifier, and the historical data includes a target encryption factor and a unique identifier; encrypting the first replicated encryption factor and the replication identifier according to a first encryption function to determine a replication key and a replication sector address for accessing card number data; reading the card number data according to the replication key and the replication sector address; when the card number data is successfully read, encrypting the replication identifier and the replication sector address according to a second encryption function to determine a second replicated encryption factor, and replacing the target encryption factor with the second replicated encryption factor; when the legitimate original RFID smart card is swiped, comparing the target encryption factor and the second replicated encryption factor to determine that the original RFID smart card is an illegal card, and alerting the original card holder. The present invention effectively improves the security of the RFID system through a series of encryption and verification steps, especially in preventing card replication and forgery. First, when the replicated card enters the radio frequency signal range of the card reader, the card reader reads the replication data on the replicated card, including sensitive information related to encryption, such as the first replicated encryption factor and the replication identifier. Then, the card reader compares this replication data with the historical data (including the target encryption factor and the unique identifier) to confirm whether the replicated card is consistent with the legitimate card. If they are consistent, the replicated card passes the first swipe verification. Next, the encryption factor and identifier of the replicated card are encrypted according to the first encryption function to determine the replication key and the replication sector address for access. Then, the card number data is read through this key and sector address. When the reading is successful, the system generates a second replicated encryption factor using the second encryption function and replaces the target encryption factor with it, updating the verification flag. In this way, after the first swipe of the replicated card, the target encryption factor is replaced with the second replicated encryption factor, while the encryption factor inside the replicated card remains unchanged. During subsequent swipes, the encryption factor of the replicated card does not match the second replicated encryption factor stored in the card reader, resulting in verification failure. Therefore, the replicated card can only pass the verification during the first swipe and cannot be swiped subsequently, effectively preventing batch replication attacks. Finally, when the legitimate original RFID smart card is swiped, when the target encryption factor of the original card is compared with the second replicated encryption factor, the unmatched result is recognized as an illegal card, and the system triggers a warning and alerts the original card holder. This mechanism not only effectively detects and prevents the abuse of replicated cards, but also can notify the original card holder in a timely manner, further improving the security of the system and avoiding unauthorized access even after the key is cracked. BRIEF DESCRIPTION OF THE DRAWINGS

[0064] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings, and all of these are within the protection scope of the present invention.

[0065] Figure 1 It is a schematic flowchart of the overall operation of the RFID smart card replication verification method in Embodiment 1 of the present invention;

[0066] Figure 2 It is a schematic flowchart of determining the initial sector address and initial key for storing card number data in Embodiment 1 of the present invention;

[0067] Figure 3 It is a schematic flowchart of the overall operation when a legitimate card is swiped for the first time in Embodiment 2 of the present invention;

[0068] Figure 4 It is a schematic flowchart of the overall operation when a legitimate card is swiped subsequently in Embodiment 2 of the present invention;

[0069] Figure 5 It is a schematic flowchart of determining a new target encryption factor in Embodiment 2 of the present invention;

[0070] Figure 6 It is a schematic flowchart of the overall operation when a replicated card is swiped in Embodiment 2 of the present invention;

[0071] Figure 7 It is a schematic flowchart of determining the sector address for storing card number data according to the reading frequency of each sector in Embodiment 2 of the present invention;

[0072] Figure 8 It is a schematic flowchart of updating the second sector address through a hash function and a pseudo-random algorithm to determine the third sector address for storing card number data in Embodiment 2 of the present invention;

[0073] Figure 9 It is a schematic flowchart of determining the third sector address according to the hash integer value, the first sector address, the sector address range, and the target sector address, in combination with the pseudo-random number generation algorithm in Embodiment 2 of the present invention;

[0074] Figure 10 It is a schematic structural diagram of the RFID smart card replication verification and initialization system in Embodiment 3 of the present invention. Specific embodiments

[0075] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. It should be noted that in this text, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. In the description of the present invention, it should be understood that the terms "center", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, and are only for the convenience of describing the present application and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be construed as a limitation of the present invention. Moreover, the terms "include", "comprise" or any other variation thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, elements defined by the statement "including..." do not exclude the existence of additional identical elements in the process, method, article or device including the said elements. If there is no conflict, the embodiments of the present invention and the various features in the embodiments may be combined with each other, and all are within the protection scope of the present invention.

[0076] Embodiment 1

[0077] Please refer to Figure 1, Embodiment 1 of the present invention discloses an RFID smart card replication verification method. The RFID smart card includes a number of sectors, which are used to store encryption factors or card number data. Each of the sectors includes a key block, which is used to store the key for accessing the current sector. The encryption factor is an encrypted string used to calculate the sector address for accessing the card number data. Specifically, the RFID smart card includes multiple sectors. Among them, the key block is the last block of each sector and is used to store the key information required to access the current sector. Each key block can store two sets of keys, namely KeyA and KeyB, and the length of each set of keys is 6 bytes to ensure controlled access to the data of a specific sector. Some sectors are used to store encryption factors, which are random strings generated by an encryption algorithm. The length of the string can be selected between 1 and 16 bytes according to requirements. The main function of the encryption factor is to dynamically calculate the access sector address of the card number data according to the algorithm, so that the access position of the card number data changes continuously, ensuring the security of access. Some sectors are used to store card number data. The sectors for accessing the card number data and the sectors for accessing the encryption factors can be the same or different. The card number data is fixed content and is used for the authentication control process in access control systems or other applications. The sector key where the card number data is located is encrypted in a one-card-one-password manner, that is, each card uses a unique encryption key for the sector where the card number data is located to ensure security. According to the design requirements, each time the card is swiped, the encryption factor is regenerated and stored in the sector, and at the same time, a new sector address for accessing the card number data is calculated through the algorithm to ensure the dynamic change of the card number access position and effectively prevent the data from being easily cracked and replicated.

[0078] The method includes:

[0079] Obtain a preset initial encryption factor;

[0080] Specifically, in the initialization stage of the RFID smart card, to ensure the consistency and security of the card's encryption process, a default initial encryption factor is preset. This initial encryption factor is a fixed string, such as 16 Fs, and is used as the initial encryption basis. This encryption factor is equivalent to a default security mark, which provides a benchmark encryption value for the encryption calculation when the card is first activated. It ensures the consistency of the initial encryption environment and a convenient encryption starting point for operation.

[0081] Write the initial encryption factor into a preset sector and obtain the unique identifier of the RFID smart card;

[0082] Specifically, before writing the initial encryption factor, a sector address is specified. For example, the first block of the 0th sector is used as the encryption factor access area, and the initial encryption factor is written into this sector. The access position of the encryption factor is fixed in each card to ensure quick location and access to this factor in any read / write device. At the same time, the unique identifier of the RFID smart card is obtained. This unique identifier is the unique serial number at the hardware level. The unique identifier is combined with the initial encryption factor during the encryption process of the RFID smart card, enhancing the anti-copying and security of the card.

[0083] According to the first encryption function, encrypt the unique identifier and the initial encryption factor in the preset sector to determine the initial sector address and the initial key for storing the card number data.

[0084] Specifically, call the first encryption function to combine the UID of the card and the initial encryption factor in the preset sector. The design of the first encryption function supports multiple encryption algorithms, such as DES or AES, to generate a dedicated initial key and the initial sector address for accessing the card number data. The first encryption function will first use the UID and the initial encryption factor as input parameters to perform encryption operations such as exclusive OR operation and hash generation, generating 6 bytes of initial data for protecting the read / write permissions of the card number data. At the same time, the first encryption function calculates the storage sector address of the card number data based on the UID and the encryption factor. This method improves the anti-cracking ability of each RFID smart card.

[0085] In one embodiment, please refer to Figure 2 wherein, the encrypting the unique identifier and the initial encryption factor in the preset sector according to the first encryption function to determine the initial sector address and the initial key for storing the card number data includes:

[0086] Perform an exclusive OR operation on the unique identifier and the initial encryption factor to determine the first string;

[0087] Specifically, in the first step of the encryption process, in order to generate the intermediate data for card encryption, an exclusive OR operation is performed on the unique identifier UID of the RFID smart card and the initial encryption factor. This operation compares and converts each bit of the unique identifier UID and the encryption factor to output a new string, that is, the first string S1, as the basis for subsequent key calculation. For example, assume that the UID is 0x1A2B3C4D and the initial encryption factor is 0x1F2F3F4F. Then, perform an exclusive OR operation on 0x1A2B3C4D and 0x1F2F3F4F, that is, S1 = 0x1A2B3C4D xor 0x1F2F3F4F = 0x05040302, to obtain the calculation result, that is, the first string 0x05040302.

[0088] Perform an exclusive OR operation on the character at the first preset position in the unique identifier and the character at the second preset position in the initial encryption factor to determine the second string;

[0089] Specifically, to further enhance the security of key generation, the character extracted from the first preset position in the unique identifier is exclusive-ORed with the character extracted from the second preset position in the initial encryption factor to generate the second string S2. For example, the first two characters 0x1A2B are extracted from the UID, i.e., 0x1A2B3C4D, and the last two bytes 0x3F4F are extracted from the initial encryption factor, i.e., 0x1F2F3F4F, and an exclusive OR operation is performed, i.e., S2 = 0x1A2B xor 0x3F4F = 0x2564. The result 0x2564 obtained through this exclusive OR operation is used as the second string.

[0090] Combine the first string and the second string to determine the initial key;

[0091] Specifically, the first string S1 and the second string S2 are combined in sequence to generate an initial key S3; for example, the first string is placed in the front and the second string is placed in the back to form the initial key S3 as 0x050403022564, with a length of 6 bytes, meeting the key requirements of the Mifare 1K card. The combined initial key S3 is used to encrypt and control the read / write access rights of the sector. Since the initial key S3 is related to both the UID of the RFID smart card and the initial encryption factor, the unpredictability of the initial key greatly enhances the security of the card and effectively prevents unauthorized access.

[0092] Perform an exclusive OR operation on the character at the third preset position in the unique identifier and the character at the third preset position in the initial encryption factor to determine the third string;

[0093] Specifically, the characters located at the third preset position are respectively extracted from the UID and the initial encryption factor and an exclusive OR operation is performed to generate the third string SecAdr, which is used to determine the specific sector address for accessing the card number data. For example, assuming the first byte of the UID is 0x1A and the first byte of the encryption factor is 0x1F, then an exclusive OR operation is performed to obtain the third string 0x05. Through this operation, the generated third string SecAdr is used as the basis for the sector address for subsequent access to the card number data, ensuring the dynamic change and uniqueness of the sector address for accessing the card number data.

[0094] Determine the initial sector address according to the third string;

[0095] Specifically, the specific position of the initial sector address is determined according to the last bit of the third string. If the last bit of SecAdr is 0, the initial sector address is set to 15 to avoid the special state of the 0 address. For example, if the current calculation result of SecAdr is 0x05, the card number data will be stored in the 5th sector. In this way, by dynamically allocating the sector address, the fixed storage of the card number data is effectively prevented, and the security and anti-cracking ability of the card are further improved.

[0096] Embodiment 2

[0097] Please refer to Figure 3 , Embodiment 2 of the present invention discloses an anti-copying RFID smart card replication verification method. The RFID smart card is initialized by the initialization method of the RFID smart card as described in Embodiment 1. The replication verification method includes:

[0098] Read the real-time encryption factor in the preset sector, and compare the real-time encryption factor with the initial encryption factor;

[0099] Specifically, when the RFID smart card enters the radio frequency signal range of the card reader, the card reader reads the real-time encryption factor data stored in the preset sector of the RFID card, such as the 1st block of the 0th sector. This encryption factor is usually a 16-byte string. Compare the real-time encryption factor with the initial encryption factor. If the read real-time encryption factor value is the preset initial default value, such as 0xFFFFFFFFFFFFFFFF, it is determined that the current RFID smart card is swiped for the first time. If the read real-time encryption factor value is not the preset initial default value, it indicates that the current RFID smart card has been used.

[0100] If the initial encryption factor is the same as the real-time encryption factor, it is the first time to swipe the card, and obtain the unique identifier of the RFID smart card;

[0101] Specifically, if the initial encryption factor is the same as the real-time encryption factor, it is the first time to swipe the card. Obtain the unique identifier UID of the card from the RFID smart card. This UID is unique data for each RFID smart card, usually a 4-byte or 7-byte unique serial number. The UID will be used as an input parameter together with the real-time encryption factor in the encryption calculation to generate a key exclusive to this card and the sector address for accessing the card number data, so that the storage address and key of the card number data for each card are unique.

[0102] According to the first encryption function, encrypt the real-time encryption factor and the unique identifier to obtain the first key and the first sector address for accessing the card number data;

[0103] Specifically, taking the real-time encryption factor and the UID as inputs, using the first encryption function, encrypt the real-time encryption factor and the unique identifier to generate the first key and the first sector address for accessing card number data. Through this encryption process, a unique 6-byte first key is obtained for encrypting the access permission of the card, and a first sector address for accessing card number data is determined. This calculation ensures that the keys and the card number data access positions of each card are different, thus effectively avoiding the security risk of repeated use.

[0104] Read the card number data according to the first key and the first sector address;

[0105] Specifically, after obtaining the first key and the first sector address, use the first key to access the card number data in the sector corresponding to the first sector address. The first key controls the data access permission of this sector, and the first sector address controls the address for reading the card number data, ensuring that the card number data can be successfully read only when both the key and the sector address are correct.

[0106] When the card number data is successfully read, according to the second encryption function, encrypt the first sector address and the unique identifier to determine a new target encryption factor;

[0107] Specifically, according to the first key and the first sector address, after successfully reading the card number data, to further improve data security, process the first sector address and the UID according to the second encryption function to generate a new target encryption factor. This operation ensures that the encryption factor changes after each card swipe, making the card present new data access rules during the next use. This dynamic update mechanism can effectively prevent security vulnerabilities caused by fixed encryption factors and enhance the flexibility of card access control.

[0108] Write the target encryption factor into the sector where the real-time encryption factor is located, and according to the first encryption function, encrypt the target encryption factor and the unique identifier to determine the second key and the second sector address for storing the card number data;

[0109] Specifically, after generating the new target encryption factor, write it back to the preset sector position, such as sector 0 block 1, to replace the original real-time encryption factor. Then, use the first encryption function again, taking the updated target encryption factor and the UID as inputs to calculate the second key and the new storage position of the card number data, that is, the second sector address. This operation ensures that the sector address and the encryption key are different for each card swipe, thus further improving the anti-counterfeiting and security performance of the card.

[0110] Delete the card number data at the first sector address, and write the card number data into the new sector corresponding to the second sector address according to the second sector address.

[0111] Specifically, after updating the key and the sector address, the card number data originally stored in the first sector address is deleted to avoid the security risks brought by repeated storage. Subsequently, the card number data is rewritten into the sector corresponding to the second sector address. Through this operation, the dynamic migration of data is realized, effectively preventing multiple accesses to the same sector, and at the same time ensuring that the storage location of the card number data is different each time the card is swiped, thereby further enhancing the data security and usage flexibility of the card.

[0112] In one embodiment, deleting the card number data of the first sector address and writing the card number data into the new sector corresponding to the second sector address according to the second sector address further includes:

[0113] Deleting the card number data of the first sector address, performing a standardization process on the card number data to be written, and determining the standard card number data;

[0114] Specifically, using a low-level storage interface, such as a direct sector access command, to locate the first sector address and perform a data erasure operation. The erasure methods include: Overwrite method: Overwrite the data in the first sector with all zeros (0x00) or all ones (0xFF); Marking method: Mark the first sector as invalid to prevent data recovery; After completing the erasure, verify whether the first sector is emptied. Assume that the card number data was originally stored in the first sector at address 0x0010. After performing the erasure operation, the original data cannot be read, and by clearing the sensitive data, data leakage caused by misuse or attack is prevented. Collect the card number data to be written and perform a format check (such as length, character set). Perform a standardization operation on the data to ensure that the data conforms to a unified format. For example: If the card number length is less than 16 bits, pad it with zeros; or convert all data to uppercase letters or a specified encoding format. After determining the standard card number data, record its check information for subsequent verification; For example, the original card number data 1234-5678-90 is standardized to 1234567890000000, and the MD5 check value is recorded; This is to ensure a unified format for different data sources, avoid write failures, and reduce data errors or omissions caused by non-standard formats.

[0115] Using a splitting function, splitting the standard card number data to determine several partial card number data;

[0116] Specifically, the standardized card number data is divided into several parts of a fixed size, usually based on the size of the storage sector, such as 512 bytes. The splitting methods include: string splitting: splitting by the number of characters; binary splitting: directly splitting into blocks by the number of bytes. Independent metadata, such as an index number or an identifier, is generated for each part of the card number data. For example, the standardized card number data 1234567890000000 is split into two parts: 12345678 (the first part) and 90000000 (the second part). On the one hand, the split data is more easily stored dispersedly, which is beneficial to data security. On the other hand, some data can be stored in different areas, reducing the risk of data loss.

[0117] According to the second sector address, determine a plurality of preset associated sector addresses corresponding to the second sector address;

[0118] Specifically, use a preset mapping table to derive the associated sector address based on the second sector address. For example, simple increment or hash calculation is adopted: the second sector address is 0x0020, and the associated sector addresses are 0x0030 and 0x0040. At the same time, the mapping relationship table is updated dynamically and regularly to ensure that subsequent data can be accurately located. For example, the second sector address 0x0020 determines the associated addresses 0x0030 and 0x0040 through the mapping relationship table.

[0119] According to the mapping relationship between the preset card number data and the sector address, write each part of the card number data into each of the associated sector addresses.

[0120] Specifically, traverse each part of the card number data, and perform a data writing operation according to its corresponding associated sector address: check whether the associated sector is idle. If it is not empty, the old data needs to be erased first; write each part of the data into the corresponding sector in sequence. After the data writing is completed, generate index information to mark the storage location of each part of the data. For example, the first part of the data 12345678 is written into the address 0x0030, and the second part of the data 90000000 is written into the address 0x0040. Through this dispersed storage method, the risk of single-point failure can be reduced. At the same time, the layout of the associated sectors can be adjusted dynamically to adapt to different storage requirements.

[0121] In one embodiment, please refer to Figure 4 , after reading the real-time encryption factor and comparing the real-time encryption factor with the initial encryption factor, it further includes:

[0122] If the initial encryption factor is different from the real-time encryption factor, then compare the real-time encryption factor with the historical encryption factor, and compare the unique identifier of the current RFID smart card with the historical identifier.

[0123] Specifically, after reading and comparing the initial encryption factor with the real-time encryption factor, if the two are different, it means that the current RFID smart card is not being swiped for the first time. In this case, the currently read real-time encryption factor will be further compared with the historical encryption factor stored in the read head EEPROM of the card reader to determine whether the current encryption factor is the same as the historical encryption factor used in the previous use. In addition, the current unique identifier of the RFID card will also be compared with the historical identifier recorded in the EEPROM to confirm the identity of the RFID smart card, which helps to verify the legitimacy of the card and avoid security risks caused by counterfeiting cards or data tampering.

[0124] When the real-time encryption factor is the same as the historical encryption factor and the unique identifier is the same as the historical identifier, according to the first encryption function, encrypt the real-time encryption factor and the unique identifier to obtain the first key and the address of the first sector where the card number data is stored;

[0125] Specifically, if the real-time encryption factor is consistent with the historical encryption factor and the unique identifier is consistent with the historical identifier, it is confirmed that the RFID smart card is not being swiped for the first time. Next, use the first encryption function with the real-time encryption factor and the unique identifier as input parameters to generate the first key of the card and the storage address of the card number data, that is, the address of the first sector. The first key will be used to unlock the card data to ensure the security of accessing the card information, while the address of the first sector indicates the storage location of the card number data of the card.

[0126] Read the card number data according to the first key and the first sector address;

[0127] Specifically, after obtaining the first key and the first sector address, use the first key to access the address corresponding to the first sector to read the card number data stored therein. The first key controls the access permission to this sector, ensuring that data can be successfully read only when the key verification passes. This step ensures that the identity authentication information of the card can be correctly accessed for subsequent encryption update operations.

[0128] When the card number data is successfully read, according to the second encryption function, encrypt the first sector address and the unique identifier to determine the new target encryption factor;

[0129] Specifically, when the card number data is successfully read, the current RFID smart card passes the verification. According to the second encryption function, an encryption operation is performed on the first sector address and the unique identifier to generate a new target encryption factor. This new target encryption factor is intended to replace the existing historical encryption factor and real-time encryption factor to ensure that the encryption factor and the card number data access address are different after each card swipe. The generation of the new target encryption factor can further improve the security of the card information, prevent potential security risks caused by the repeated use of fixed factors, and enhance the dynamic and flexibility of the card swiping process.

[0130] In one embodiment, please refer to Figure 5 , when the card number data is successfully read, according to the second encryption function, the encryption process is performed on the first sector address and the unique identifier, and determining the new target encryption factor includes:

[0131] Perform a multiplication calculation on the first sector address and the unique identifier to determine the fourth string;

[0132] Specifically, when the card number data is successfully read, that is, when the current RFID smart card passes the verification, perform a multiplication operation on the unique identifier of the current RFID smart card and the obtained first sector address. According to the calculation result, determine the new target encryption factor. The result of the multiplication operation of the unique identifier and the obtained first sector address generates a temporary string, that is, the fourth string. For example, the fourth string Kn = 0x1A2B3C4D * 0x05 = 0x82D82D81. By combining the unique identifier of the RFID smart card and the first sector address where the card number data is stored, it is ensured that the new target encryption factor and the sector address where the card number data is stored are unique, thereby improving data security and preventing the repeated use of encryption factors.

[0133] Extract the character at the fourth preset position in the fourth string, and use the extraction result as the target encryption factor.

[0134] Specifically, extract the character at the fourth preset position from the calculated fourth string and use it as the new target encryption factor. For example, extract the last 4 bytes of the fourth string as the target encryption factor. This ensures that the generated target encryption factor is within a certain length and has a high degree of uniqueness. By extracting the specified character at the fourth preset position, an encryption factor with sufficient complexity can be obtained to replace the old factor. This new target encryption factor will be stored in a specific sector and used during the next verification, further enhancing the security and dynamics of card information protection.

[0135] Replace the original historical encryption factor with the target encryption factor, and encrypt the target encryption factor and the unique identifier according to the first encryption function to determine the second key and the second sector address where the card number data is stored;

[0136] Specifically, after determining the new target encryption factor, replace the historical encryption factor stored in the EEPROM of the card reader head with the target encryption factor, and process the new target encryption factor and the unique identifier through the first encryption function to generate a new second key and the second sector address where the card number data is stored. The second key is used to access the new card number data storage address, thereby enhancing the security of the card data. Using the dynamic target encryption factor can effectively avoid the security risks caused by swiping a cloned card. At the same time, the generated second sector address will dynamically adjust the storage location of the card number data, further improving the protection ability of the card.

[0137] Delete the card number data at the first sector address, and write the card number data into the new sector corresponding to the second sector address according to the second sector address.

[0138] Specifically, first delete the card number data from the sector corresponding to the old first sector address to prevent the card data from being read repeatedly or data leakage problems; subsequently, write the card number data to the location specified by the second sector address. This operation makes the storage location of the card number data change every time the card is swiped, increasing data security, and cooperating with the dynamic update mechanism of the key, further improving the effect of protecting and verifying the management of the card data.

[0139] In one embodiment, please refer to Figure 6 , after completely cloning the RFID smart card, it includes:

[0140] Read the copied data on the cloned card, where the copied data includes the first copied encryption factor and the copied identifier;

[0141] Specifically, when the cloned card enters the radio frequency signal range of the card reader, the card reader reads the copied data on the cloned card, especially the sensitive information related to encryption, including the first copied encryption factor and the copied identifier of the cloned card; these copied data are used to verify whether the card is a legitimate card in the subsequent steps.

[0142] Compare the copied data with the historical data in the card reader. If the copied data is consistent with the historical data, the first swipe of the cloned card passes the verification, where the historical data includes the target encryption factor and the unique identifier;

[0143] Specifically, the first copy encryption factor and the copy identifier of the read copy card are compared with the historical data stored in the EEPROM of the card reader head. This step is mainly used to detect whether the card data is consistent with the previously recorded legal information.

[0144] According to the first encryption function, encrypt the first copy encryption factor and the copy identifier to determine the copy key and the copy sector address for accessing the card number data;

[0145] Specifically, according to the first encryption function, encrypt the first copy encryption factor and the copy identifier of the copy card to generate a copy key and a copy sector address. Since the first copy encryption factor and the copy identifier are the same as the historical data stored in the EEPROM of the card reader head, the calculated copy key is consistent with the second key, and the copy sector address for accessing the card number data is consistent with the second sector address where the card number data is stored.

[0146] Read the card number data according to the copy key and the copy sector address;

[0147] When the card number data is successfully read, according to the second encryption function, encrypt the copy identifier and the copy sector address to determine the second copy encryption factor, and replace the target encryption factor with the second copy encryption factor;

[0148] Specifically, after the card number data of the copy card is successfully read, according to the second encryption function, perform an encryption operation on the copy identifier and the copy sector address to generate a second copy encryption factor. This new second encryption factor is used to replace the target encryption factor and saved in the EEPROM of the card reader head through a replacement operation. The purpose of this step is to update the unique second copy encryption factor as a new verification and identification flag after the first swipe of the copy card.

[0149] After the first swipe of the copy card, the card reader has stored the newly generated second copy encryption factor in its EEPROM as an identification flag. However, the encryption factor inside the copy card itself cannot change dynamically and remains the original first copy encryption factor. This means that when the copy card is swiped again, although the copy card has the same UID as the original RFID smart card, the encryption factor read by the card reader on the copy card, that is, the first copy encryption factor, does not match the second copy encryption factor stored in the EEPROM, resulting in a verification failure. This mechanism ensures that the copy card can only pass the first swipe and cannot be swiped repeatedly, effectively avoiding the situation of batch card copying after the key is cracked.

[0150] When a legitimate original RFID smart card is swiped, compare the target encryption factor with the second replicated encryption factor to determine that the original RFID smart card is an illegal card and alert the original card holder.

[0151] Specifically, when a legitimate original RFID smart card is swiped, read the target encryption factor of the original RFID smart card and compare it with the second replicated encryption factor. Since the target encryption factor was replaced with the second replicated encryption factor when the replicated card was swiped for the first time, the original RFID smart card will no longer match when swiped; this mismatch will be recognized as an illegal card behavior, and a warning message will be recorded in the background or a reminder will be sent to the original card holder. In this way, after detecting the activity of the replicated card, the normal access of the original card can be blocked and the original card holder can be alerted, improving security and preventing further unauthorized access.

[0152] In one embodiment, please refer to Figure 7 After replacing the original historical encryption factor with the target encryption factor, encrypting the target encryption factor and the unique identifier according to the first encryption function, and determining the second key and the second sector address where the card number data is stored, the following steps are further included:

[0153] According to the second sector address, obtain the target read frequency of the sector corresponding to the second sector address, and obtain the read frequencies corresponding to the remaining sectors and a preset frequency threshold respectively;

[0154] Specifically, read the target read frequency of the sector corresponding to the second sector address, that is, the number of times the sector is accessed by the card reader and the read frequencies of the remaining sectors, and compare these frequency data with the preset frequency threshold. The preset frequency threshold is a limit value set by security management and can be set to different values according to actual different security management needs. The preset frequency threshold is used to determine whether the access frequency of a certain sector exceeds the safe range. For example, the read frequency of the second sector is obtained as 5 times, and the read frequencies of the other sectors are 2, 4, and 6 times respectively, and the frequency threshold is set to 10 times. By obtaining and comparing the read frequency information and the threshold, dynamically adjust the access position of the card number data to avoid the risk exposure and damage of the RFID smart card caused by frequent access to a certain sector, and ensure the security of the data and the balanced read distribution.

[0155] Calculate the average value of the read frequencies of each sector according to the target read frequency and the read frequencies corresponding to the remaining sectors respectively;

[0156] Specifically, according to the read frequencies of all sectors, including the target sector and the remaining sectors, calculate the average value of the read frequencies as the benchmark for whether to migrate data. For example, if the read frequencies of each sector are 2, 4, 5, and 6 times respectively, the average value is (2 + 4 + 5 + 6) / 4 = 4.25 times; the calculation of the average read frequency helps to determine the access distribution of the card number data in each sector, prevent over-concentration of access to specific sectors, ensure the balanced distribution of card data among multiple sectors, and enhance security and anti-attack capabilities.

[0157] If the target read frequency is less than the average value and the target read frequency is less than the frequency threshold, delete the card number data at the first sector address, and write the card number data into the new sector corresponding to the second sector address according to the second sector address;

[0158] Specifically, compare the target read frequency, the average value, and the frequency threshold. If the target read frequency is less than the average value and the target read frequency is less than the frequency threshold, it is considered that the data access frequency of the new sector corresponding to the second sector address is safe. Delete the card number data in the sector corresponding to the first sector address and migrate it to the new sector corresponding to the second sector address, so as to store the data in the sector with a lower read frequency to disperse the risk. For example, if the target read frequency is 3 times, which is lower than the average value of 4.25 and less than the frequency threshold of 10 times, then the card number data in the first sector will be deleted and written into the second sector. By balancing the read frequencies of each sector, the service life of the card can be extended.

[0159] If the target read frequency is greater than or equal to the average value and / or the target read frequency is greater than or equal to the frequency threshold, update the second sector address through a hash function and a pseudo-random algorithm to determine the third sector address where the card number data is stored;

[0160] Specifically, if the target read frequency is greater than or equal to the average value and / or the target read frequency is greater than or equal to the frequency threshold, a hash function and a pseudo-random algorithm are used to recalculate the sector address to determine the new card number data access location, that is, the third sector address. By calculating a new address that is not easily predictable through the hash and pseudo-random algorithms to store the card number data, it prevents the data location from being pre-judged. Assume that the target read frequency is 8 times, exceeding the average value of 4.25 or approaching the threshold of 10 times, the third sector address will be regenerated. For example, it is calculated that sector 8 is the new storage address. By dynamically updating the sector address, the storage location is different after each read and write operation, enhancing the unpredictability of data access, greatly improving the data security, and effectively preventing potential targeted attacks. At the same time, the scheme of determining the third sector address through the hash function and the pseudo-random algorithm can effectively generate evenly distributed sector addresses, avoiding the risk of a certain fixed sector being frequently accessed. The hash function can generate a difficult-to-predict and relatively evenly distributed address according to the input, ensuring that the address generation does not depend on specific rules, reducing the possibility of being cracked. With the use of the pseudo-random algorithm, the patterned distribution is further broken, making the results of each address calculation different, avoiding concentrated access to a single sector. The advantage of this method is that it balances the read frequencies of each sector, reduces the physical wear caused by frequent access to the same sector, thereby effectively extending the service life of the card, and enhancing the security and data anti-interference ability.

[0161] In one embodiment, please refer to Figure 8 , if the target read frequency is greater than or equal to the average value or the target read frequency is greater than or equal to the frequency threshold, then through a hash function and a pseudo-random algorithm, the second sector address is updated to determine the third sector address where the card number data is stored, including:

[0162] Combine the unique identifier and the target encryption factor to determine a target string;

[0163] Specifically, concatenate the unique identifier and the target encryption factor or combine them according to other rules to form a unique target string. For example, if the unique identifier is 0x1A2B3C4D and the target encryption factor is 0x123456, then these two values are combined in a certain order into 0x1A2B3C4D123456; this combination ensures the uniqueness and dynamics of the input because the target string generated each time is different, providing a diverse input for subsequent hash operations.

[0164] Process the target string through a hash function to determine the hash value;

[0165] Specifically, the target string is used as input and a fixed-length hash value is generated through a hash function such as SHA-256 or MD5. For example, the hash value generated by processing 0x1A2B3C4D123456 through SHA-256 is: 5e884898da28047151d0e56f8dc6292773603dcfc1e004a6bbcbaf58d6a8. The main advantages of this hash value are irreversibility, uniqueness and unpredictability, which can ensure the security and uniqueness of the output results and provide a random and uniformly distributed data foundation for subsequent mapping.

[0166] Performing standardization processing on the hash value to convert the hash value into a hash integer value;

[0167] Specifically, the generated hash value needs to be standardized, that is, the hash value is converted into digital form for easy operation; for example, the first 8 characters of the hash value are intercepted and converted into a hexadecimal integer or a decimal integer, thereby converting the complex hash value 5e884898 into an integer 1581254296. The standardized hash integer value simplifies subsequent calculations and lays the foundation for mapping to a specific sector address range.

[0168] According to the hash integer value and a preset sector address interval, the hash integer value is mapped to the sector address interval to determine a target sector address;

[0169] Specifically, by mapping the standardized hash integer value to the sector address range of the card, the dynamic positioning of the sector is realized. For example, within the range of 16 sectors, the hash integer value is modulo 16 to obtain the sector number. The hash integer value modulo 16 to obtain the sector number includes performing a modulo operation on the standardized hash integer value and 16, that is, calculating the remainder after the integer value is divided by 16. Since the address range of 16 sectors is 0 to 15, by taking the modulo of the hash integer value, it can be ensured that the result is always between 0 and 15, thereby obtaining a valid sector number. For example, if the hash integer value is 1581254296, after the operation of dividing 1581254296 by 16, the remainder is 8, which means that the hash value is mapped to the 8th sector. In this way, a uniform mapping of hash values ​​and specific sectors is achieved, thereby avoiding frequent access to certain sectors, dispersing the storage load, and increasing the stability and durability of the storage system. This ensures that the sector address generated each time is different while covering all available sectors, avoiding frequent access to a fixed sector, and reducing the risk of physical damage to the card.

[0170] The third sector address is determined according to the hash integer value, the first sector address, the sector address interval and the target sector address in combination with the pseudo-random number generation algorithm.

[0171] Specifically, finally, by synthesizing the hash integer value, the first sector address, and the target sector address, and then combining with a pseudo-random algorithm to generate the final third sector address. The introduction of the pseudo-random algorithm can further perturb on the basis of the target sector address generated by the basic hash, breaking the single mapping rule. For example, by generating an offset and adding it to the target sector address, the third sector address is finally obtained. This process further improves the randomness of the accessed sector distribution, avoids security risks brought by specific rules, realizes a decentralized storage distribution at the same time, reduces the risk of the card being read centrally, and effectively improves the service life of the card.

[0172] In one embodiment, please refer to Figure 9 that determining the third sector address according to the hash integer value, the first sector address, the sector address range, and the target sector address, and combining with the pseudo-random number generation algorithm includes:

[0173] Initializing a preset pseudo-random number generator according to the hash integer value;

[0174] Specifically, inputting the hash integer value as a seed into a preset pseudo-random number generator to ensure that the generated pseudo-random number sequence is closely related to the hash integer value. The pseudo-random number generator can generate different random number sequences through different initial seed values, while the same seed value will generate the same sequence, ensuring consistency and predictability in different environments. This method helps to improve data security and avoid generating duplicate sector addresses for different cards.

[0175] Inputting the first sector address into the initialized pseudo-random number generator to determine a pseudo-random number;

[0176] Specifically, taking the first sector address, such as 0x05, as input data to further enhance the unpredictability of the random number. The input data is combined with the seed value, that is, the hash integer value, and the pseudo-random number generator calculates and generates a new pseudo-random number. This process ensures that the access data and offset of each card are unique. Even if the cards use the same hash value, the change in the first sector address will affect the final pseudo-random number. For example, the hash integer value 1581254296 is input as a seed into the pseudo-random number generator, and the generated random number sequence will always be associated with this seed value. If the first sector address is 0x05, the generated pseudo-random number will depend on the combination of this address and the previously generated random number sequence. The core of the pseudo-random number generator is to recursively generate pseudo-random numbers through a mathematical algorithm, such as the linear congruence method, so as to ensure that each access to the card has a certain difference and security.

[0177] Perform a modulo operation on the pseudo-random number according to the sector address range to determine an offset, where the offset is within the sector address range;

[0178] Specifically, the pseudo-random number is processed by taking the modulo of a preset sector address range to ensure that the offset is always within the valid sector address range. The sector address range is usually from 0 to 15, corresponding to the 16 sectors of the RFID smart card. By performing a modulo operation on the pseudo-random number, it can be ensured that the generated offset is within this range. For example, assume the generated pseudo-random number is 35, and the result after taking modulo 16 is 3, which means the offset is 3.

[0179] Perform an addition calculation and a modulo operation on the offset and the target sector address to determine the third sector address.

[0180] Specifically, by adding the offset and the target sector address and then performing a modulo operation on the result again, the final third sector address where the card number data is stored is determined. The addition calculation ensures that the target sector address changes under the influence of the offset, and the modulo operation keeps the result within the legal sector address range. Assume the target sector address is 5 and the offset is 3, then the addition result is 8, and taking modulo 16 of 8 gives the final third sector address as 8. This design makes the sector position for data storage more flexible, effectively avoiding excessive access to a certain sector and reducing the burden on the storage device.

[0181] Delete the card number data of the first sector address, and write the card number data into the new sector corresponding to the third sector address according to the third sector address.

[0182] Specifically, to ensure data update and the security of the card number data, first delete the old data in the first sector, and then write the card number data into the new address according to the newly calculated third sector address. This operation ensures that the data is always in an updated state, avoiding the risk of card damage or reduced storage performance caused by long-term concentration of stored data in a certain sector. By distributing the storage of card number data among different sectors, the service life of the card can be effectively extended, while improving the reading efficiency and security.

[0183] Embodiment 3

[0184] Embodiment 3 of the present invention discloses an RFID smart card replication verification and initialization system. The replication verification system includes an RFID smart card and a card reader. The RFID smart card is initialized by the RFID smart card initialization method as described in Embodiment 1, and the card reader performs replication verification on the RFID smart card by the RFID smart card replication verification method as described in Embodiment 2.

[0185] Specifically, the RFID smart card replication verification and initialization system provided by the embodiments of the present invention is adopted. The replication verification system includes an RFID smart card and a card reader. The RFID smart card is initialized by the RFID smart card initialization method as described in Embodiment 1, and the card reader performs replication verification on the RFID smart card by the RFID smart card replication verification method as described in Embodiment 2. On the one hand, by introducing the mechanisms of encryption factors and dynamic access addresses, this system effectively solves the problem of batch replication after the RFID smart card key is cracked. In this solution, the encryption factor of each card changes every time the card is swiped, resulting in changes in the sector address and key for accessing the card number. Even if a replicated card successfully swipes by replicating the UID and key of a legitimate card, the next time the card is swiped, due to the change in the encryption factor, the sector address for accessing the card number no longer matches, causing the replicated card to be unable to access the legitimate data stored in the new location, thus rendering it ineffective. In addition, since the key and storage address of each card are dynamic calculation results based on the UID and encryption factor, the encryption method of each card is different, which means that even if an attacker cracks the key of a certain card, it is still impossible to batch replicate other cards because each card has an independent access address and key. Through this design of replication verification and address change, the long-term use of replicated cards is effectively prevented, and the security risks brought by batch replication are avoided, thereby significantly enhancing the security and ensuring that the access rights of legitimate users are not tampered with or imitated by illegal cards. On the other hand, since this system does not require a separate physical key to be configured for each card, but generates dynamic keys and storage addresses through algorithms, the hardware deployment cost is reduced.

[0186] In summary, the embodiments of the present invention provide a method and system for RFID smart card replication verification and initialization.

[0187] It should be clear that the present invention is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, the detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of the present invention is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order between steps after understanding the spirit of the present invention.

[0188] The functional blocks shown in the above-described structural block diagrams can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, it can be, for example, an electronic circuit, an application-specific integrated circuit (ASIC), appropriate firmware, a plug-in, a functional card, and so on. When implemented in software, the elements of the present invention are programs or code segments for performing the required tasks. The program or code segment can be stored in a machine-readable medium or transmitted via a data signal carried in a carrier wave over a transmission medium or a communication link. "Machine-readable medium" can include any medium that can store or transmit information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical discs, hard disks, fiber optic media, radio frequency (RF) links, and so on. The code segment can be downloaded via a computer network such as the Internet, an intranet, and so on.

[0189] The user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data that have been authorized by the user or fully authorized by all parties. And the collection, use, and processing of the relevant data need to comply with the relevant laws, regulations, and standards of the relevant location, and corresponding operation entrances are provided for the user to select to authorize or refuse.

[0190] It should also be noted that the exemplary embodiments mentioned in the present invention describe some methods or systems based on a series of steps or devices. However, the present invention is not limited to the order of the above steps. That is to say, the steps can be executed in the order mentioned in the embodiments, can be different from the order in the embodiments, or several steps can be executed simultaneously.

[0191] As described above, the above is only the specific implementation manner of the present invention. Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described systems, modules, and units can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein. It should be understood that the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of various equivalent modifications or substitutions, and these modifications or substitutions should all be covered by the protection scope of the present invention.

Claims

1. A RFID smart card duplication verification method, characterized in that: The method comprises: Completely copy the legal original RFID smart card and read the copied data on the copied card; Compare the copied data with the historical data in the card reader. If the copied data and the historical data are consistent, the first swipe of the copied card passes the verification, wherein the copied data includes a first copy encryption factor and a copy identifier, and the historical data includes a target encryption factor and a unique identifier; According to a first encryption function, the first copy encryption factor and the copy identifier are encrypted to determine a copy sector address for accessing the copy key and the card number data; Reading the card number data according to the copy key and the copy sector address; When the card number data is successfully read, the copy identifier and the copy sector address are encrypted according to a second encryption function, a second copy encryption factor is determined, and the target encryption factor is replaced with the second copy encryption factor; When the legitimate original RFID smart card is swiped, the target encryption factor is compared with the second duplicate encryption factor to determine that the original RFID smart card is an illegal card, and the original card holder is reminded.

2. The RFID smart card duplication verification method according to claim 1, characterized in that: Before completely copying the legitimate original RFID smart card and reading the copied data on the copied card, the method further includes: Reading the real-time encryption factor in the preset sector, and comparing the real-time encryption factor with the initial encryption factor; If the initial encryption factor is the same as the real-time encryption factor, it is the first time to swipe the card, and the unique identifier of the RFID smart card is obtained; According to the first encryption function, the real-time encryption factor and the unique identifier are encrypted to obtain a first sector address for accessing a first key and card number data; Reading the card number data according to the first key and the first sector address; When the card number data is successfully read, the first sector address and the unique identifier are encrypted according to a second encryption function to determine a new target encryption factor; Writing the target encryption factor into the sector where the real-time encryption factor is located, encrypting the target encryption factor and the unique identifier according to the first encryption function, and determining the second sector address where the second key and the card number data are stored; The card number data at the first sector address is deleted, and the card number data is written into a new sector corresponding to the second sector address according to the second sector address.

3. The RFID smart card duplication verification method according to claim 2, characterized in that: After reading the real-time encryption factor and comparing the real-time encryption factor with the initial encryption factor, the method further includes: If the initial encryption factor is different from the real-time encryption factor, the real-time encryption factor is compared with the historical encryption factor, and the unique identifier of the current RFID smart card is compared with the historical identifier; When the real-time encryption factor is the same as the historical encryption factor and the unique identifier is the same as the historical identifier, encrypting the real-time encryption factor and the unique identifier according to a first encryption function to obtain a first sector address where a first key and card number data are stored; Reading the card number data according to the first key and the first sector address; When the card number data is successfully read, the first sector address and the unique identifier are encrypted according to a second encryption function to determine a new target encryption factor; Replacing the original historical encryption factor with the target encryption factor, encrypting the target encryption factor and the unique identifier according to the first encryption function, and determining a second sector address where the second key and the card number data are stored; The card number data at the first sector address is deleted, and the card number data is written into a new sector corresponding to the second sector address according to the second sector address.

4. The RFID smart card duplication verification method according to claim 2, characterized in that: When the card number data is successfully read, the first sector address and the unique identifier are encrypted according to a second encryption function, and determining a new target encryption factor includes: performing multiplication calculation on the first sector address and the unique identifier to determine a fourth character string; The characters at the fourth preset position in the fourth character string are extracted, and the extraction result is used as the target encryption factor.

5. The RFID smart card duplication verification method according to claim 3, characterized in that: After replacing the original historical encryption factor with the target encryption factor, encrypting the target encryption factor and the unique identifier according to the first encryption function, and determining the second sector address where the second key and the card number data are stored, the method further includes: According to the second sector address, obtaining a target read frequency of the sector corresponding to the second sector address, and obtaining read frequencies and preset frequency thresholds corresponding to the remaining sectors respectively; Calculating an average value of the reading frequencies of each sector according to the target reading frequency and the reading frequencies corresponding to the remaining sectors; If the target reading frequency is less than the average value and the target reading frequency is less than the frequency threshold, the card number data at the first sector address is deleted, and the card number data is written into a new sector corresponding to the second sector address according to the second sector address; If the target reading frequency is greater than or equal to the average value and / or the target reading frequency is greater than or equal to the frequency threshold, the second sector address is updated by a hash function and a pseudo-random algorithm to determine a third sector address where the card number data is stored; The card number data at the first sector address is deleted, and according to the third sector address, the card number data is written into a new sector corresponding to the third sector address.

6. The RFID smart card duplication verification method according to claim 5, characterized in that: If the target reading frequency is greater than or equal to the average value or the target reading frequency is greater than or equal to the frequency threshold, the second sector address is updated by a hash function and a pseudo-random algorithm to determine the third sector address where the card number data is stored, including: Combining the unique identifier and the target encryption factor to determine a target character string; Processing the target string through a hash function to determine a hash value; Performing standardization processing on the hash value to convert the hash value into a hash integer value; According to the hash integer value and a preset sector address interval, the hash integer value is mapped to the sector address interval to determine a target sector address; The third sector address is determined according to the hash integer value, the first sector address, the sector address interval and the target sector address in combination with the pseudo-random number generation algorithm.

7. The RFID smart card duplication verification method according to claim 6, characterized in that: Determining the third sector address according to the hash integer value, the first sector address, the sector address interval and the target sector address in combination with the pseudo-random number generation algorithm includes: Initializing a preset pseudo-random number generator according to the hash integer value; Inputting the first sector address into the initialized pseudo-random number generator to determine a pseudo-random number; According to the sector address interval, performing modulo processing on the pseudo-random number to determine an offset, wherein the offset is within the sector address interval; The offset and the target sector address are added and modulo processed to determine the third sector address.

8. A method for initializing an RFID smart card, characterized in that: The RFID smart card is duplicated and verified by the RFID smart card duplication verification method according to any one of claims 1 to 7, and the initialization method comprises: Obtain a preset initial encryption factor; Writing the initial encryption factor into a preset sector and obtaining a unique identifier of the RFID smart card; According to the first encryption function, the unique identifier and the initial encryption factor in the preset sector are encrypted to determine the initial sector address and initial key where the card number data is stored.

9. The RFID smart card initialization method according to claim 8, characterized in that: The step of encrypting the unique identifier and the initial encryption factor in the preset sector according to the first encryption function to determine the initial sector address and the initial key for storing the card number data comprises: Performing an XOR operation on the unique identifier and the initial encryption factor to determine a first character string; Performing an XOR operation on the character at the first preset position in the unique identifier and the character at the second preset position in the initial encryption factor to determine a second character string; Combining the first character string and the second character string to determine the initial key; Performing an XOR operation on the character at the third preset position in the unique identifier and the character at the third preset position in the initial encryption factor to determine a third character string; The initial sector address is determined according to the third character string.

10. An RFID smart card duplication verification and initialization system, characterized in that: The RFID smart card copy verification system includes an RFID smart card and a card reader, wherein the card reader performs copy verification on the RFID smart card by using the RFID smart card copy verification method described in any one of claims 1 to 7, and the RFID smart card is initialized by using the RFID smart card initialization method described in claim 8 or 9.

Citation Information

Patent Citations

  • Radio frequency card with double encryption algorithm

    CN106529651A