Bar code and RFID dual-mode fused tamper-proof data storage system
Through the tamper-proof data storage system that integrates barcode and RFID dual-mode, the combination of fluorescent particle optical fingerprint and dynamic keys is used to generate a multi-dimensional tamper map, and combined with hash tree cross-verification, the problems of barcode vulnerability and RFID tampering are solved, and the data is high security and integrity are achieved.
Patent Information
- Application Number
- CN202510757744.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-09
- Publication Date
- 2025-07-08
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing barcode storage system is physically fragile and easy to damage and has weak counterfeiting capabilities. The RFID storage system is highly concealed in tampering, lacks an effective protection mechanism, and communication is vulnerable to man-in-the-middle attacks, and has a high risk of key leakage.
The anti-tampering data storage system using a dual-mode fused barcode and RFID is used to divide the data into static and dynamic parts, and the optical fingerprint of fluorescent particles and dynamic keys are combined to generate a multi-dimensional tampering map, and combined with hash tree cross-verification, the data is achieved by dividing the data into static and dynamic parts.
Improves the security and integrity of data, prevents tampering, and supports misoperation and recovery, meets the traceability requirements of data modification, and complies with the electronic record integrity specification.
Smart Images

Figure CN120277727A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security storage, and specifically to an anti-tampering data storage system integrating barcodes and RFID in a dual-mode manner. Background Art
[0002] Data information realizes efficient storage, access, and management of data through physical media and logical architectures. Most traditional barcode storage systems use printed one-dimensional / two-dimensional codes. After the data is written, it cannot be modified, which cannot meet the requirements of dynamic data updates. At the same time, during its storage period, the surface of the barcode is vulnerable to physical damage such as soiling and scratching, and there is no effective detection method after tampering. At the same time, barcodes can also be forged by simple copying, lacking an active protection mechanism. If an independent RFID storage system is used instead, during the storage period, wireless communication is vulnerable to man-in-the-middle attacks, there is a risk of key leakage, and there is no physical trace after electronic data is tampered with, and the conventional verification mechanism has a time lag. Summary of the Invention
[0003] To solve the above technical problems, an anti-tampering data storage system integrating barcodes and RFID in a dual-mode manner is provided. This technical solution solves the problems proposed in the above background art that during the storage of data using barcodes or RFID storage, the barcodes have physical vulnerability and weak forgery ability, while during the RFID storage period, the tampering is highly concealed.
[0004] To achieve the above objectives, the technical solution adopted by the present invention is as follows: An anti-tampering data storage system integrating barcodes and RFID in a dual-mode manner, comprising: A data processing module: Connect the barcode and RFID to a scanning and monitoring platform, upload the complete data to be stored to the scanning and monitoring platform and split it into static data and dynamic data, write the static data into the barcode module, generate a barcode data label to automatically lock the internal data writing function of the barcode module, and only allow modification of the surface of the data label; A barcode encryption module: Generate randomly distributed initial fluorescent particles on the surface of the barcode data label through the scanning and monitoring platform to generate a unique initial optical fingerprint with a timestamp. If the barcode module is scanned and read again after the timestamp corresponding to the initial optical fingerprint, the scanning and monitoring platform records the timestamp of each scan and the number of the scanning device. If an attempt is made to write to or modify the barcode module after the scanning and reading, modify the distribution position of the initial fluorescent particles, summarize the modified target optical fingerprint, timestamp, and scanning device number to obtain an abnormal optical fingerprint and issue an alarm; RFID Encryption Module: Write dynamic data into the RFID module, and pre - install an encryption chip in the RFID module. Generate a dynamic key each time for communication. In the production or circulation links where data needs to be uploaded, input the real - time dynamic key. If the dynamic key is accurate, data can be written or modified in the RFID module and the timestamp is recorded. If the dynamic key is incorrect, data operations on the RFID module are not allowed and the timestamp is recorded; Barcode and RFID Dual - mode Fusion Module: Based on static data and dynamic data, cross - verify the hash values to determine that the overall data has not been tampered with.
[0005] Preferably, the splitting of the complete data to be stored into static data and dynamic data when uploading to the scanning and monitoring platform specifically includes: The scanning and monitoring platform constructs a hash tree for the complete data to be stored, generates a main hash value and hierarchical sub - hash values, and embeds the main hash value inside the static data; Screen the basic attributes, unique identifiers, main hash values, and circulation track reference parameters in the data to be stored as static data, and use the environmental dynamic parameters and operation log update records as dynamic data; Based on the historical data processing process, count the historical update frequencies of each field in the static data and dynamic data. Set the static data update frequency threshold to 1 time within the whole life cycle, and the dynamic data update frequency threshold to more than 1 time; Embed the logical address pointer of the dynamic data storage block in the dynamic data storage block inside the static data to form a one - way index from static data to dynamic data. The logical address pointer of the dynamic data storage block in the dynamic data storage block contains the encoding and storage location of the RFID chip; Write the static data digest value inside the dynamic data to form a reverse index from dynamic data to static data. The static data digest value is the main hash value of the static data, the generated timestamp, and the associated barcode serial number.
[0006] Preferably, the scanning and monitoring platform constructs a hash tree for the complete data to be stored, generates a main hash value and hierarchical sub - hash values specifically including: Based on the total number of all bytes of the data to be stored, divide the data to be stored into multiple units to form data blocks, perform a hash operation on each data block to obtain leaf - node hash values; Cascade the hash values of two adjacent leaf nodes, perform a hash operation on the cascaded string to generate secondary - node hash values, and repeat the cascading and hash operations until a single root node is generated as the main hash value; Append the generation timestamp and RFID chip code to the sub-hash values at each level, combine and encapsulate the main hash value with the sub-hash values at each level to form a hash tree structure data packet. The hash tree structure data packet contains level identification, hash value, timestamp, and RFID chip code.
[0007] Preferably, the modification of the distribution position of the initial fluorescent particles specifically includes: Based on the size of the surface of the barcode data label, establish a plane coordinate system with the lower left corner point of the label surface as the origin, obtain the static data type written inside the barcode module, set the basic attributes and unique identifier as the change amount of the horizontal axis. When attempting to modify the basic attributes, the randomly distributed fluorescent particles will move in the positive direction of the horizontal axis. When attempting to modify the unique identifier, the randomly distributed fluorescent particles will move in the negative direction of the horizontal axis. Set the main hash value and the circulation trajectory reference parameter as the change amount of the vertical axis. When attempting to modify the main hash value, the randomly distributed fluorescent particles will move in the positive direction of the vertical axis. When attempting to modify the circulation trajectory reference parameter, the randomly distributed fluorescent particles will move in the negative direction of the vertical axis. If there is displacement in both the horizontal and vertical axes, trigger a multi-dimensional tampering mark and record the vector trajectory; When attempting to write to or modify the barcode module after scanning and reading, the scanning monitoring platform will record the data type of the write or modification. According to the specific data type of the written or modified data, make the fluorescent particles perform corresponding physical displacements on the surface of the barcode data label to obtain the distribution position of the modified target fluorescent particles and generate a target optical fingerprint.
[0008] Preferably, the summarization of the modified target optical fingerprint, timestamp, and scanning device number to obtain an abnormal optical fingerprint and issue an alarm specifically includes: The optical sensor inside the scanning monitoring platform scans the distribution position of the original fluorescent particles to form an original fluorescent particle distribution map, and aligns the lower left corner of the original fluorescent particle distribution map with the origin of the coordinate system, so that the original fluorescent particle distribution map is mapped inside the coordinate system, and obtains the coordinates of each point of the original fluorescent particle distribution map, denoted as the original coordinates; The optical sensor inside the scanning monitoring platform scans the distribution position of the target fluorescent particles after physical displacement to form a displacement fluorescent particle distribution map, projects the displacement fluorescent particle distribution map into the coordinate system with reference fingerprint data according to the same projection operation, denoted as the target coordinates, and connects the original coordinates and the corresponding target coordinates to form a displacement vector; After each displacement operation, summarize the original coordinates, target coordinates, and displacement vector to form a traceable particle operation chain, write it into the barcode module and trigger an abnormal alarm; After the abnormal alarm is issued, the operator verifies whether the current writing or modification operation is a tampering operation. If it is a tampering operation, data destruction processing is carried out according to the regulations on internal information leakage and tampering of the enterprise. If it is a non-tampering misoperation, according to the displacement vector parameters recorded in the particle operation chain, the fluorescent particles are driven back to the original coordinates by reverse laser pulses, and the distribution state of the fluorescent particles after returning is scanned again to obtain the reset fluorescent particle distribution map, and the reset fluorescent particle distribution map is projected into the coordinate system through the same projection operation, which is recorded as the reset coordinate; Compare the coincidence degree of the original coordinate and the reset coordinate. If the coincidence degree is greater than or equal to 99%, the record of this abnormal alarm is cleared and a reset confirmation voucher is generated. The reset confirmation voucher includes the reset timestamp, the biometric characteristics of the operator and the optical fingerprint comparison map before and after reset. If the coincidence degree is less than 99%, the operation of returning the fluorescent particles is repeated.
[0009] Preferably, a cryptographic chip is pre-installed in the RFID module. The specific process of generating a dynamic key for each communication includes: The operator wears a biometric collection device to complete biometric sampling and generate an operator ID. All operator IDs are aggregated to form a biometric sample library; The cryptographic chip has a built-in key center. After generating an initial key in the key center, the biometric sample library is embedded inside the initial key to form a dynamic key, and the key center signs the dynamic key. The key center consists of biometric recognition, dynamic key generation, digital signature verification, an encrypted communication channel and a self-destruction mechanism. All the data written in the RFID module is encrypted and protected by the encrypted communication channel of the key center; After the operator triggers an RFID writing request, the scanning monitoring platform uses a biosensor to obtain real-time biometric characteristics and compares them with all the operator IDs in the biometric sample library for verification. After the verification is passed, the scanning monitoring platform activates the decryption module in the encrypted communication channel in the key center, allowing the operator to write and modify the data inside the RFID module through the decryption module. When the verification fails, the operator is not allowed to perform data operations on the RFID module.
[0010] Preferably, the cross-verification of the hash value based on static data and dynamic data to determine that the overall data has not been tampered with specifically includes: The surface of the barcode data label is scanned multispectrally by a scanning device to obtain a real-time fluorescent particle distribution map, and the original fluorescent particle distribution map of the current static data is extracted. The real-time fluorescent particle distribution map and the original fluorescent particle distribution map are projected into the coordinate system, and the deviation degree between the real-time fluorescent particle distribution map and the original fluorescent particle distribution map is calculated. Based on the deviation degree, a static data tampering mark is triggered; The scanning and monitoring platform reads the biometrics of the internal operator of the reset confirmation voucher and synchronously sends a dynamic key verification request to the RFID module. When the biometrics of the internal operator of the reset confirmation voucher match the operator ID in the biometric sample library during dynamic key verification, the dynamic data decryption channel in the RFID chip is activated; Extract the logical address pointer of the dynamic data storage block in the dynamic data storage block in the decryption channel. According to the one-way index from static data to dynamic data, locate the storage location of the RFID chip and extract the dynamic data main hash value written in the corresponding storage location; Perform the first hash comparison between the extracted dynamic data main hash value and the main hash value stored internally in the static data. When the compared hash values are the same, compare the sub-hash values with the hash values of the corresponding levels in the hash tree structure data packet level by level according to the hash tree level identifier; Based on the static data digest value, obtain the generation timestamp and the associated barcode serial number. Verify the time continuity of the dynamic data operation log through the timestamp sequence. When an isolated timestamp or parameter mutation is detected in the dynamic data, trigger a dynamic data tampering mark; Perform a logical OR operation on the static data tampering mark and the dynamic data tampering mark. When either mark is activated, generate a data integrity alarm signal and mark the hierarchical position of the abnormal data segment in the hash tree in the alarm information; When the main hash value and each level of sub-hash values match completely, the scanning and monitoring platform generates a data integrity certificate, which includes the main hash value, the verification timestamp, and the topology relationship diagram of the scanning devices participating in the verification.
[0011] Preferably, calculating the deviation degree between the real-time fluorescence particle distribution map and the original fluorescence particle distribution map, and triggering the static data tampering mark based on the deviation degree specifically includes: Project the real-time fluorescence particle distribution map and the original fluorescence particle distribution map onto the same coordinate system, perform point-by-point comparison of the coordinates of each fluorescence particle, calculate the modulus length of the displacement vector of each particle, where the modulus length of the displacement vector is the Euclidean distance between the real-time coordinates and the original coordinates of the particle, and statistically sum up the modulus lengths of all fluorescence particle displacement vectors, denoted as the total displacement; The fluorescence particles with the modulus length of the displacement vector exceeding the displacement threshold are recorded as abnormal particles, filter out all abnormal particles, and count the total number of abnormal particles; Perform an OR operation on the situation where the total displacement exceeds the displacement threshold and the situation where the total number of abnormal particles exceeds the abnormal quantity threshold. If either situation exists, it is determined that there is a risk of static data tampering, and the static data tampering mark is triggered. The displacement threshold is the standard deviation of the particle displacement in the historical tampering scenario, with an initial value of the mean of the average distances between the original coordinates of all particles, and the abnormal quantity threshold is the mean proportion of abnormal particles in the total particles in the historical tampering scenario.
[0012] Compared with the prior art, the beneficial effects of the present invention are as follows: The present invention proposes an anti-tampering data storage system integrating barcodes and RFID in a dual-mode. Fluorescent particles are randomly distributed on the surface of the barcode to form a unique optical fingerprint. When it is tampered with, it can trigger the directional displacement of the fluorescent particles. By combining fingerprints, iris, vein and other biometric features with dynamic keys, the physical layer of the displacement of the fluorescent particles and the cryptographic layer of the dynamic keys can be effectively and quickly integrated to generate a multi-dimensional tampering map. Then, static data and dynamic data are divided based on the historical update frequency, and a dynamic storage address pointer is embedded in the static data, while the dynamic data is reverse-indexed to the static digest, which can effectively perform intelligent differentiation and two-way indexing of the data. By combining with the hierarchical tree of the main hash value (root node) and sub-hash values, the main hash of the static data is embedded in the dynamic data, and the dynamic hash is used for reverse verification, realizing cross-verification of the hierarchical hash tree. During tampering, it is necessary to break through the physical layer of the fluorescent marker, the data layer of the hash tree and the authentication layer of the biometric key simultaneously, improving the security. The present invention proposes an anti-tampering data storage system integrating barcodes and RFID in a dual-mode. When the laser pulse drives the fluorescent particles to return to the original coordinates, it can be reset autonomously during misoperation, and an encrypted certificate is generated after the reset. Thus, the overall anti-tampering mechanism supports the recovery of misoperations, and when tracing the operations, a complete operation chain record of the particle displacement vector and the device number is retained, meeting the requirements of data modification traceability and conforming to the electronic record integrity specification. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] Figure 1 is a schematic flow chart of the present invention; Figure 2 is a schematic flow chart of splitting the complete data to be stored into static data and dynamic data and uploading them to the scanning and monitoring platform in the present invention; Figure 3 is a schematic flow chart of constructing a hash tree for the complete data to be stored by the scanning and monitoring platform in the present invention to generate the main hash value and hierarchical sub-hash values; Figure 4 is a schematic flow chart of modifying the distribution position of the initial fluorescent particles in the present invention; Figure 5 is a schematic flow chart of summarizing the modified target optical fingerprint, time stamp and scanning device number to obtain an abnormal optical fingerprint and giving an alarm in the present invention; Figure 6 is a schematic flow chart of pre-installing an encryption chip in the RFID module and generating a dynamic key for each communication in the present invention; Figure 7 is a schematic flow chart of cross-verifying the hash values based on the static data and dynamic data to determine that the overall data has not been tampered with in the present invention; Figure 8 It is a schematic flowchart for calculating the deviation degree between the real-time fluorescence particle distribution map and the original fluorescence particle distribution map in the present invention and triggering the static data tampering mark based on the deviation degree. Specific embodiments
[0014] The following description is used to disclose the present invention so that those skilled in the art can implement the present invention. The preferred embodiments in the following description are only examples, and those skilled in the art can think of other obvious variants.
[0015] Refer to Figure 1 As shown, the anti-tampering data storage system with the dual-mode fusion of barcode and RFID includes: Data processing module: Connect the barcode and RFID to the scanning and monitoring platform, upload the complete data to be stored to the scanning and monitoring platform and split it into static data and dynamic data, write the static data into the barcode module, generate a barcode data label to automatically lock the internal data writing function of the barcode module, and only allow modification on the surface of the data label; Barcode encryption module: Generate randomly distributed initial fluorescence particles on the surface of the barcode data label through the scanning and monitoring platform, generate a unique initial optical fingerprint with a timestamp. If the barcode module is scanned and read again after the timestamp corresponding to the initial optical fingerprint, the scanning and monitoring platform records the timestamp of each scan and the number of the scanning device. If an attempt is made to write to or modify the barcode module after the scan and read, the distribution position of the initial fluorescence particles is modified, and the modified target optical fingerprint, timestamp, and scanning device number are summarized to obtain an abnormal optical fingerprint and an alarm is issued; RFID encryption module: Write the dynamic data into the RFID module, and pre-install an encryption chip in the RFID module. Generate a dynamic key each time for communication. In the links where data needs to be uploaded during production or circulation, input the real-time dynamic key. If the dynamic key is accurate, data can be written to or modified in the RFID module and the timestamp is recorded. If the dynamic key is incorrect, data operations on the RFID module are not allowed and the timestamp is recorded; Dual-mode fusion module of barcode and RFID: Cross-verify the hash value based on the static data and dynamic data to determine that the overall data has not been tampered with.
[0016] The laser engraving device of the barcode module is physically connected to the encryption chip of the RFID module and time stamp synchronization is performed. Meanwhile, the scanning monitoring platform includes a high-precision optical sensor array, a multi-band RFID reader / writer, and a biometric acquisition module. During its use, the data to be stored is divided into static data and dynamic data through the hash tree construction algorithm. The static data consists of low-frequency updated fields such as basic attributes and unique identifiers and is stored inside the barcode module, while the dynamic data is written into the EEPROM storage array of the RFID chip.
[0017] Nanoscale fluorescent particles are deposited on the surface of the barcode label through microfluidic technology. The distribution coordinates of the piezoelectric nozzle are controlled by a random number generator to form a unique optical fingerprint containing the initial time stamp. When data is modified, the scanning monitoring platform monitors the particle displacement vector in real time through the coordinate mapping algorithm, and triggers the particle displacement in different axes according to the type of modified data (basic attributes, main hash value, etc.). Moreover, the displacement trajectory generated by each modification operation will be recorded as a multi-dimensional tampering mark and transmitted to the central monitoring system, thus realizing physical layer anti-counterfeiting through the fluorescent particle displacement detection technology.
[0018] The key center in the RFID module deploys a key derivation function based on the elliptic curve cryptosystem, and generates a dynamic key seed after Fourier transform of the fingerprint features of the operator. Each time data is written, biometric real-time verification is triggered through near-field communication. Only when the biometric hash value collected by the iris recognition module is verified to be consistent with the pre-stored sample can the encryption channel be activated for data operations.
[0019] And hierarchical verification is performed using the dynamic data hash tree in the RFID and the static hash tree stored in the barcode. When it is detected that the deviation of the hash value at any level exceeds the preset threshold, a data tampering alarm is triggered and the abnormal data block is located. The sensitivity of data tampering detection is improved through the dual-mode storage architecture, and the hash tree cross-verification technology extends the data integrity verification dimension from a single time sequence to a spatial topological structure, thus shortening the discovery time of data tampering events and reducing the false alarm rate.
[0020] Refer to Figure 2 As shown, the splitting of the complete data to be stored into static data and dynamic data when uploading it to the scanning monitoring platform specifically includes: The scanning monitoring platform constructs a hash tree for the complete data to be stored, generates a main hash value and hierarchical sub-hash values, and embeds the main hash value inside the static data; Select the basic attributes, unique identifiers, main hash value, and circulation track reference parameters in the data to be stored as static data, and use the environmental dynamic parameters and operation log update records as dynamic data; Based on the historical data processing flow, the historical update frequencies of each field in the static data and dynamic data are statistically calculated. The static data update frequency threshold is set to 1 time within the entire life cycle, and the dynamic data update frequency threshold is set to be greater than 1 time; Embed the logical address pointer of the dynamic data storage block of the dynamic data storage block inside the static data to form a one-way index from the static data to the dynamic data. The logical address pointer of the dynamic data storage block of the dynamic data storage block contains the encoding and storage location of the RFID chip; Write the static data digest value inside the dynamic data to form a reverse index from the dynamic data to the static data. The static data digest value is the main hash value, generation timestamp, and associated barcode serial number of the static data.
[0021] The original data is segmented into data blocks in units of 128KB. Each data block generates a leaf node hash value, and they are aggregated upward level by level to form a main hash tree. Among them, 1 bit of hash check bit is inserted every 2048 bits of the static data binary stream to form a steganographic embedding structure. The selection of static data adopts a three-level filtering mechanism: the first level extracts basic attribute fields (such as product batch number, production date) through regular expression matching; the second level uses a Bloom filter to identify unique identifiers; the third level uses a spatio-temporal association algorithm to extract the benchmark parameters of the circulation trajectory.
[0022] Load the historical operation log dataset in the data processing engine and use an LSTM neural network to establish a field update cycle prediction model. For static data fields, the system performs an update frequency statistics every 24 hours. When it is detected that the actual update times of a certain field exceed 10% of the preset threshold, the Bayesian optimization algorithm is triggered to recalibrate the threshold parameters.
[0023] Reserve an index area at the end of the static data storage area. Convert the physical address of the dynamic data storage block (including the RFID chip UID encoding, storage cluster number, sector offset) into a hexadecimal pointer value, and append a check code to form an anti-interference pointer structure. The reverse index at the dynamic data end adopts a ciphertext embedding method. After compressing the static data main hash value, generation timestamp, and barcode serial number, write them into the reserved storage area of the RFID tag to form a verifiable ciphertext digest package, so that the two-way index structure is doubly bound by the ciphertext digest and the physical address, improving the data association verification speed and shortening the cross-retrieval time-consuming.
[0024] Refer to Figure 3 As shown, the scanning and monitoring platform constructs a hash tree for the complete data to be stored, and generating the main hash value and hierarchical sub-hash values specifically includes: Based on the total number of all bytes of the data to be stored, divide the data to be stored into multiple units to form data blocks, and perform a hash operation on each data block to obtain the leaf node hash value; Concatenate the hash values of two adjacent leaf nodes, perform a hash operation on the concatenated string to generate the hash value of the secondary node, and repeat the concatenation and hash operations until a single root node is generated as the main hash value; Append the generation timestamp and RFID chip code to the sub-hash values at each level, combine and encapsulate the main hash value with the sub-hash values at each level to form a hash tree structure data packet. The hash tree structure data packet contains a level identifier, a hash value, a timestamp, and an RFID chip code.
[0025] First, calculate the entropy value distribution curve of the data to be stored. When a data entropy value mutation point is detected, automatically insert a block boundary to form an adaptive data unit. Each data block generates a leaf node hash value through the BLAKE3 algorithm.
[0026] During the construction of the hash tree, a binary tree topology structure is adopted for hierarchical aggregation. At the hardware level, a dual-channel is deployed to implement parallel concatenation operations. The hash values of two adjacent leaf nodes are bit-crossed and spliced (the odd bits are taken from the previous node, and the even bits are taken from the subsequent node) to form a composite string. The generation of the secondary node hash value adopts a hierarchical encryption strategy: the first 512 bits are processed by SHA-3 512, the last 512 bits are processed by the K12 algorithm, and the results of the two are XORed and then the middle 512 bits are intercepted as the final hash value, so that the hybrid hash mechanism reduces the collision probability and improves the security.
[0027] Append 32 bytes of structured data to the end of each sub-hash value: the first 8 bytes are the timestamp, the middle 12 bytes are the EPC code (including the check bit) of the RFID chip, and the last 12 bytes are the digital signature to ensure the anti-interference ability during wireless transmission.
[0028] The encapsulation of the hash tree structure data packet adopts a hierarchical nested protocol: the outermost layer is the transport layer encapsulation, and the inner data body is arranged in a quadruple structure. Each quadruple contains a 2-byte level identifier, a 64-byte hash value, a 12-byte timestamp, RFID binding data, and a 4-byte check code. The finally generated hash tree data packet is divided into multiple shards and distributedly stored in a hybrid storage pool composed of blockchain nodes and local encrypted SSDs.
[0029] Refer to Figure 4 As shown, the modification of the distribution position of the initial fluorescent particles specifically includes: Based on the size of the surface of the barcode data label, a plane coordinate system is established with the lower left corner point of the label surface as the origin. The static data type written inside the barcode module is obtained. The basic attributes and unique identifier are set as the horizontal axis change amount. When attempting to modify the basic attributes, the randomly distributed fluorescent particles will move in the positive direction of the horizontal axis. When attempting to modify the unique identifier, the randomly distributed fluorescent particles will move in the negative direction of the horizontal axis. The main hash value and the circulation trajectory reference parameter are set as the vertical axis change amount. When attempting to modify the main hash value, the randomly distributed fluorescent particles will move in the positive direction of the vertical axis. When attempting to modify the circulation trajectory reference parameter, the randomly distributed fluorescent particles will move in the negative direction of the vertical axis. If there is displacement in both the horizontal and vertical axes, a multi-dimensional tampering mark is triggered and the vector trajectory is recorded; When attempting to write to or modify the barcode module after scanning and reading, the monitoring platform will record the data type of the write or modification. According to the specific data type of the written or modified data, the fluorescent particles will perform corresponding physical displacements on the surface of the barcode data label, obtaining the distribution position of the modified target fluorescent particles and generating a target optical fingerprint.
[0030] A nanoscale piezoelectric ceramic array is used as the driving substrate and is connected to the FPGA controller of the scanning monitoring platform through a matrix-type FPC cable. The fluorescent particles are rare-earth doped crystal microspheres with a photochromic material coating on the surface. The coordinate system is established using laser interferometry positioning technology, with the gold reference mark at the lower left corner of the barcode label as the origin, and a plane rectangular coordinate system is established through a dual-frequency laser rangefinder.
[0031] When a data modification operation is detected and the basic attributes are modified, a pulse voltage of a specific timing is output to drive the piezoelectric unit in the positive X-axis direction to generate an inverse piezoelectric effect, causing the fluorescent particles in the corresponding area to undergo mass migration under the influence of the surface tension gradient. When the unique identifier is modified, a -15V bias voltage is reversely applied to trigger negative migration. The vertical axis displacement control uses a thermally actuated mechanism. A micro thin film heater is integrated in the Y-axis direction. When the main hash value is modified, a current is applied to increase the local temperature, and the particles are driven to migrate in the positive direction through thermophoresis. When the circulation trajectory parameter is modified, the symmetric cooling unit is activated to achieve negative displacement, thereby achieving a directional displacement mechanism based on physical effects to visualize tampering behavior and improve the anti-counterfeiting strength.
[0032] The movement trajectory of the particles is captured in real time by a high-speed CMOS image sensor array. When an X / Y-axis composite displacement is detected, the tampering weights of each data type are distinguished through a vector decomposition algorithm: Let the abscissa of the basic attribute modification + the modulus of the displacement vector, and the ordinate of the main hash value modification + the modulus of the displacement vector, then the tampering confidence level is , Where: C is the tampering confidence level, A is the modulus of the displacement vector along the abscissa, and B is the modulus of the displacement vector along the ordinate. Thus, a multi-dimensional tampering atlas including a displacement heat map, a vector arrow map, and a confidence matrix is automatically generated.
[0033] Refer to Figure 5 As shown, the steps of summarizing the modified target optical fingerprint, timestamp, and scanning device number to obtain an abnormal optical fingerprint and issuing an alarm specifically include: The optical sensor inside the scanning monitoring platform scans the distribution positions of the original fluorescent particles to form a distribution map of the original fluorescent particles, and aligns the lower left corner of the distribution map of the original fluorescent particles with the origin of the coordinate system, so that the distribution map of the original fluorescent particles is mapped inside the coordinate system, and the coordinates of each point on the distribution map of the original fluorescent particles are obtained, denoted as the original coordinates; The optical sensor inside the scanning monitoring platform scans the distribution positions of the target fluorescent particles after physical displacement to form a distribution map of the displaced fluorescent particles, projects the distribution map of the displaced fluorescent particles into the coordinate system with reference fingerprint data according to the same projection operation, denoted as the target coordinates, and connects the original coordinates and the corresponding target coordinates to form a displacement vector; After each displacement operation, the original coordinates, target coordinates, and displacement vector are summarized to form a traceable particle operation chain, which is written into the barcode module and an abnormal alarm is triggered; After the abnormal alarm is issued, the operator verifies whether the current write or modification operation is a tampering operation. If it is a tampering operation, according to the enterprise's internal information leakage and tampering regulations, data destruction processing is performed. If it is a non-tampering misoperation, according to the displacement vector parameters recorded in the particle operation chain, the fluorescent particles are driven back to the original coordinates by reverse laser pulses, the distribution state of the fluorescent particles after return is re-scanned, a reset fluorescent particle distribution map is obtained, and the reset fluorescent particle distribution map is projected into the coordinate system through the same projection operation, denoted as the reset coordinates; The coincidence degree between the original coordinates and the reset coordinates is compared. If the coincidence degree is greater than or equal to 99%, the record of this abnormal alarm is cleared and a reset confirmation certificate is generated. The reset confirmation certificate includes a reset timestamp, the biometric characteristics of the operator, and a comparison diagram of the optical fingerprints before and after reset. If the coincidence degree is less than 99%, the fluorescent particle return operation is repeated.
[0034] A high-precision linear array CMOS sensor and a laser interference positioning module constitute an optical detection unit, and the coordinate positioning accuracy is achieved through a six-axis precision displacement stage. Coordinate system calibration adopts an algorithm based on SIFT feature matching. Silicon carbide reference marks are preset at the four corners of the barcode label. Through feature point extraction, an affine transformation matrix is established to accurately register the original fluorescence distribution map and the target distribution map in the same coordinate system, and a two-way optimal matching model is established by calculating the local texture features of each fluorescent particle.
[0035] After the displacement vector is generated, abnormal outliers are eliminated, and finally, structured operation chain data including the starting coordinates, ending coordinates, displacement angle, and velocity vector is formed. This data is written into the encrypted storage area of the barcode module after adding a digital signature.
[0036] For reversible tampering operations, a laser pulse sequence is used to trigger the photomigration effect of fluorescent particles. The reverse reset algorithm optimizes the laser parameters, controls the voltage waveform of the piezoelectric actuator and the temperature gradient of the thermal actuator, and drives the particles to move in the opposite direction of the original displacement vector. After its reverse movement, the phase correlation method is used to calculate the coordinate coincidence degree, and the matching degree is quantified through the normalized cross-correlation algorithm. When the coordinate coincidence degree ≥ 0.99, it is determined that the reset is successful, and a reset certificate of the biometric hash value (iris feature + finger vein pattern) is generated.
[0037] Refer to Figure 6 As shown, an encrypted chip is pre-installed in the RFID module. The generation of dynamic keys for each communication specifically includes: The operator wears a biometric collection device to complete biometric sampling to generate the operator ID. All operator IDs are aggregated to form a biometric sample library. The encrypted chip has a built-in key center. After the initial key is generated in the key center, the biometric sample library is embedded inside the initial key to form a dynamic key, and the key center signs the dynamic key. The key center consists of biometric recognition, dynamic key generation, digital signature verification, encrypted communication channel, and self-destruction mechanism. All data written in the RFID module is encrypted and protected by the encrypted communication channel of the key center. After the operator triggers the RFID write request, the scanning monitoring platform uses a biosensor to obtain real-time biometrics and compares and verifies them with all operator IDs in the biometric sample library. After the verification passes, the scanning monitoring platform activates the decryption module in the encrypted communication channel in the key center, allowing the operator to write and modify the data inside the RFID module through the decryption module. When the verification fails, the operator is not allowed to perform data operations on the RFID module.
[0038] The dynamic key uses a standard dedicated encrypted chip, which integrates a biometric processing unit and a quantum-resistant cryptographic coprocessor inside. The encrypted chip is connected to the RFID antenna module through an interface, and a physically unclonable function circuit is built-in to generate a unique root key for the device. The biometric collection device selects a multi-modal biosensor group, including a fingerprint module with infrared liveness detection, a 3D structured light facial recognition unit, and a vein pattern scanner. It is connected to the main control system through an interface to form a biometric sample library, and the sample data is protected by a certified encrypted memory.
[0039] During the dynamic key generation process, the key center first generates a root key through the PUF circuit, and combines it with the operator's biometric hash value (extracting multi-modal features of fingerprints / iris / veins) for operation to generate an initial master key. The embedding of the biometric sample library adopts a threshold secret sharing scheme, which divides the operator's biometric characteristics into multiple fragments, and the complete biometric key component can be reconstructed only when the verification is passed. Each time a dynamic key is generated, a temporary session key is generated for digital signature. When a write request is triggered, the multi-modal sensor synchronously collects the operator's fingerprint, face depth map, and palm vein, and the feature extraction uses a deep residual network to generate feature vectors. The verification process uses the cosine similarity algorithm for feature comparison. When the similarity exceeds the 0.92 threshold, the decryption channel is activated.
[0040] Referring to Figure 7 As shown, the cross-verification of the hash value based on static data and dynamic data to determine that the overall data has not been tampered with specifically includes: Perform multi-spectral scanning on the surface of the barcode data label through a scanning device to obtain a real-time fluorescence particle distribution map, extract the original fluorescence particle distribution map of the current static data, project the real-time fluorescence particle distribution map and the original fluorescence particle distribution map into a coordinate system, calculate the deviation between the real-time fluorescence particle distribution map and the original fluorescence particle distribution map, and trigger a static data tampering mark based on the deviation; The scanning monitoring platform reads the operator's biometric characteristics inside the reset confirmation voucher and synchronously sends a dynamic key verification request to the RFID module. When the operator's biometric characteristics inside the reset confirmation voucher match the operator ID in the biometric sample library during the dynamic key verification, the dynamic data decryption channel in the RFID chip is activated; Extract the logical address pointer of the dynamic data storage block of the dynamic data storage block in the decryption channel. According to the one-way index from static data to dynamic data, locate the storage location of the RFID chip and extract the main hash value of the dynamic data written in the corresponding storage location; Perform the first hash comparison between the extracted main hash value of the dynamic data and the main hash value stored inside the static data. When the compared hash values are the same, compare the sub-hash values with the hash values of the corresponding levels in the hash tree structure data packet level by level according to the hash tree level identifier; Based on the static data digest value, obtain the generation timestamp and the associated barcode serial number, and verify the time continuity of the dynamic data operation log through the timestamp sequence. When an isolated timestamp or parameter mutation is detected in the dynamic data, trigger a dynamic data tampering mark; Perform a logical OR operation on the static data tampering mark and the dynamic data tampering mark. When any mark is activated, generate a data integrity alarm signal, and mark the hierarchical position of the abnormal data segment in the hash tree in the alarm information; When the main hash value and each hierarchical sub - hash value are exactly matched, the scanning and monitoring platform generates a data integrity certificate, which includes the main hash value, the verification timestamp, and the topological relationship diagram of the scanning devices participating in the verification.
[0041] The quantum dot spectral imager, terahertz waveguide array, and anti - quantum computing ASIC chips are deployed inside the scanning and monitoring platform, while the verification terminal deploys a high - precision multispectral scanning head, which can be coupled to the detector array through an optical fiber bundle to achieve the acquisition of the fluorescence particle distribution. The biometric verification module includes a fingerprint feature extraction pipeline and an iris texture matching engine, and realizes data throughput through an interface with the main processor.
[0042] In the static data tampering detection process, the distance algorithm is used to calculate the deviation degree of the particle distribution, and the point - pair mapping relationship is established through bidirectional nearest - neighbor search. When the deviation degree exceeds the 5μm threshold, a tampering mark is triggered.
[0043] In the dynamic data verification process, a causal dependency graph based on the operation sequence is established, and the timestamp tomogram is detected through depth - first search. Each dynamic data block is attached with the hash value of the predecessor block and the successor block pointer. When the detected timestamp jump exceeds the system clock accuracy, a parameter mutation alarm is triggered. The hierarchical verification of the hash tree deploys a hybrid tree structure. During verification, a hierarchical caching strategy is adopted, and the tree nodes are stored in the cache according to the access frequency, and the verification delay is reduced through the pre - fetching algorithm.
[0044] The weights of the static tampering mark and the dynamic mark are set independently. When the weighted sum exceeds 0.85, a level - three alarm is triggered. The octree spatial indexing technology is used for the annotation of the abnormal data segment, presenting the hierarchical depth, physical coordinates of the tampering points, and the topological relationship of the associated RFID chips. The threshold signature mechanism is used in the data integrity certificate generation process, which is jointly signed by multiple nodes in the verification network. The certificate contains the proof of anti - quantum computing to ensure that the certificate itself cannot be forged.
[0045] Refer to Figure 8 As shown, calculating the deviation degree between the real - time fluorescence particle distribution map and the original fluorescence particle distribution map, and triggering the static data tampering mark based on the deviation degree specifically includes: Project the real - time fluorescence particle distribution map and the original fluorescence particle distribution map onto the same coordinate system, compare the coordinates of each fluorescence particle point - by - point, calculate the modulus length of the displacement vector of each particle. The modulus length of the displacement vector is the Euclidean distance between the real - time coordinates and the original coordinates of the particle, and calculate the sum of the modulus lengths of all fluorescence particle displacement vectors, denoted as the total displacement; The fluorescence particles with the modulus length of the displacement vector exceeding the displacement threshold are marked as abnormal particles, screen all abnormal particles, and count the total number of abnormal particles; An OR operation is performed on the situation where the total displacement exceeds the displacement threshold and the situation where the total number of abnormal particles exceeds the abnormal quantity threshold. If either situation exists, it is determined that there is a risk of tampering with the static data, and a static data tampering flag is triggered. The displacement threshold is the standard deviation of the particle displacements in the historical tampering scenarios, with an initial value being the mean of the average distances between the original coordinates of all particles. The abnormal quantity threshold is the mean proportion of abnormal particles to the total number of particles in the historical tampering scenarios.
[0046] A composite detection unit is composed of a back-illuminated sensor and a laser interference positioning module, and the coordinate positioning accuracy is achieved through a nanoscale piezoelectric displacement stage. The SURF feature points of the fluorescent particles are extracted in the coordinate system to construct an initial matching set, and then the iterative closest point algorithm is used to optimize the transformation matrix, and finally the image registration accuracy is achieved.
[0047] In the displacement analysis stage, the coordinate pairs (x1, y1), (x2, y2) of each particle are packed into a 4D vector, and single-instruction multiple-data-stream processing is realized through the GPU texture memory prefetching technology. The Euclidean distance calculation uses the Newton iteration method to optimize the square root operation, shortening the calculation time of the modulus length of a single particle. The total displacement statistics module uses the Kahan summation algorithm to avoid the accumulation of floating-point errors, ensuring that the cumulative error is less than 0.01 μm. In the abnormal particle screening stage, a Bloom filter is deployed for rapid pre-screening, and then the particles with excessive displacement are accurately identified through segmented threshold comparison.
[0048] In the initial stage, cluster analysis is performed on the original particle spacing, and the average distance between classes is calculated as the reference threshold. In the running stage, an exponentially weighted moving average model is deployed, using the data of historical tampering scenarios (including environmental parameters such as temperature and humidity) as the training set, and the window size is adaptively adjusted to the last 50 operation records. The abnormal quantity threshold is dynamically calculated using the Bayesian probability model, and the estimated value of the proportion of abnormal particles is updated based on the Beta prior distribution.
[0049] In summary, the advantages of the present invention are as follows: A three-dimensional protection system is constructed through a dual anti-tampering mechanism of the physical layer of the fluorescent particle displacement and the cryptographic layer of the dynamic key, combined with the cross-verification of the hash tree, improving the anti-tampering ability.
[0050] The above shows and describes the basic principles, main features and advantages of the present invention. Those skilled in the art of this industry should understand that the present invention is not limited by the above embodiments. What is described in the above embodiments and the specification is only the principle of the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements all fall within the scope of the present invention claimed. The scope of protection claimed by the present invention is defined by the appended claims and their equivalents.
Claims
1. Tamper-proof data storage system with dual-mode integration of barcode and RFID, characterized in that Including: Data processing module: Connect the barcode and RFID to the scanning and monitoring platform, upload the complete data to be stored to the scanning and monitoring platform and split it into static data and dynamic data, write the static data into the barcode module, generate a barcode data label to automatically lock the internal data writing function of the barcode module, and only allow modification of the data label surface; Barcode encryption module: Generate randomly distributed initial fluorescent particles on the surface of the barcode data label through the scanning and monitoring platform, generate a unique initial optical fingerprint with a timestamp. If the barcode module is scanned and read again after the timestamp corresponding to the initial optical fingerprint, the scanning and monitoring platform records the timestamp of each scan and the number of the scanning device. If an attempt is made to write to or modify the barcode module after the scan and read, the distribution position of the initial fluorescent particles is modified, and the modified target optical fingerprint, timestamp, and scanning device number are summarized to obtain an abnormal optical fingerprint and an alarm is issued; RFID encryption module: Write the dynamic data into the RFID module, and preset an encryption chip in the RFID module. Generate a dynamic key for each communication. In the production or circulation link where data needs to be uploaded, input the real-time dynamic key. If the dynamic key is accurate, data can be written to or modified in the RFID module and the timestamp is recorded. If the dynamic key is incorrect, data operations on the RFID module are not allowed and the timestamp is recorded; Barcode and RFID dual-mode fusion module: Based on the static data and dynamic data, cross-verify the hash values to determine that the overall data has not been tampered with.
2. The anti-tampering data storage system integrating barcodes and RFID in dual-mode according to claim 1, wherein The specific process of uploading the complete data to be stored to the scanning and monitoring platform and splitting it into static data and dynamic data includes: The scanning and monitoring platform constructs a hash tree for the complete data to be stored, generates a main hash value and hierarchical sub-hash values, and embeds the main hash value inside the static data; Screen the basic attributes, unique identifiers, main hash values, and circulation track benchmark parameters in the data to be stored as static data, and use the environmental dynamic parameters and operation log update records as dynamic data; Based on the historical data processing process, statistically calculate the historical update frequencies of each field in the static data and dynamic data, set the static data update frequency threshold to 1 time within the entire life cycle, and the dynamic data update frequency threshold to more than 1 time; Embed the logical address pointer of the dynamic data storage block of the dynamic data storage block inside the static data to form a one-way index from the static data to the dynamic data. The logical address pointer of the dynamic data storage block of the dynamic data storage block includes the encoding and storage location of the RFID chip; Write the static data digest value inside the dynamic data to form a reverse index from the dynamic data to the static data. The static data digest value is the main hash value of the static data, the generated timestamp, and the associated barcode serial number.
3. The anti-tampering data storage system integrating barcodes and RFID in dual mode according to claim 2, characterized in that, The specific process of the scanning and monitoring platform constructing a hash tree for the complete data to be stored and generating a main hash value and hierarchical sub-hash values includes: Based on the total number of all bytes of the data to be stored, divide the data to be stored into multiple units to form data blocks, perform a hash operation on each data block to obtain the leaf node hash value; Concatenate the hash values of two adjacent leaf nodes, perform a hash operation on the concatenated string to generate the hash value of the secondary node, and repeat the concatenation and hash operations until a single root node is generated as the main hash value; Attach the generation timestamp and RFID chip code to the sub-hash values of each level, combine and encapsulate the main hash value with the sub-hash values of each level to form a hash tree structure data packet. The hash tree structure data packet includes a level identifier, a hash value, a timestamp, and an RFID chip code.
4. The anti-tampering data storage system integrating barcodes and RFID in dual mode according to claim 3, characterized in that, The modification of the distribution position of the initial fluorescent particles specifically includes: Based on the size of the barcode data label surface, establish a plane coordinate system with the lower left corner point of the label surface as the origin, obtain the static data type written inside the barcode module, set the basic attributes and unique identifier as the horizontal axis change amount. When attempting to modify the basic attributes, the randomly distributed fluorescent particles will move in the positive direction of the horizontal axis. When attempting to modify the unique identifier, the randomly distributed fluorescent particles will move in the negative direction of the horizontal axis. Set the main hash value and the circulation trajectory reference parameter as the vertical axis change amount. When attempting to modify the main hash value, the randomly distributed fluorescent particles will move in the positive direction of the vertical axis. When attempting to modify the circulation trajectory reference parameter, the randomly distributed fluorescent particles will move in the negative direction of the vertical axis. If there is displacement in both the horizontal and vertical axes, trigger a multi-dimensional tampering mark and record the vector trajectory; When attempting to write to or modify the barcode module after scanning and reading, the scanning monitoring platform will record the data type of the write or modification. According to the specific data type of the data written or modified, make the fluorescent particles perform corresponding physical displacements on the barcode data label surface to obtain the distribution position of the modified target fluorescent particles and generate the target optical fingerprint.
5. The anti-tampering data storage system with dual-mode integration of barcode and RFID according to claim 4, characterized in that, The summarization of the modified target optical fingerprint, timestamp, and scanning device number to obtain the abnormal optical fingerprint and issue an alarm specifically includes: The optical sensor inside the scanning monitoring platform scans the distribution position of the original fluorescent particles to form an original fluorescent particle distribution map, and aligns the lower left corner of the original fluorescent particle distribution map with the coordinate system origin, so that the original fluorescent particle distribution map is mapped inside the coordinate system, and obtains the coordinates of each point of the original fluorescent particle distribution map, denoted as the original coordinates; The optical sensor inside the scanning monitoring platform scans the distribution position of the target fluorescent particles after physical displacement to form a displacement fluorescent particle distribution map, projects the displacement fluorescent particle distribution map into the coordinate system with reference fingerprint data according to the same projection operation, denoted as the target coordinates, and connects the original coordinates and the corresponding target coordinates to form a displacement vector; After each displacement operation, summarize the original coordinates, target coordinates, and displacement vector to form a traceable particle operation chain, write it into the barcode module and trigger an abnormal alarm; After the abnormal alarm is issued, the operator verifies whether the current writing or modification operation is a tampering operation. If it is a tampering operation, data destruction processing is performed according to the enterprise's internal regulations on information leakage and tampering. If it is a non-tampering misoperation, according to the displacement vector parameters recorded in the particle operation chain, the fluorescent particles are driven back to the original coordinates by reverse laser pulses, and the distribution state of the fluorescent particles after returning is re-scanned to obtain the reset fluorescent particle distribution map. The reset fluorescent particle distribution map is projected into the coordinate system through the same projection operation and recorded as the reset coordinates. Compare the coincidence degree of the original coordinates and the reset coordinates. If the coincidence degree is greater than or equal to 99%, clear the record of this abnormal alarm and generate a reset confirmation voucher. The reset confirmation voucher includes the reset timestamp, the operator's biometric characteristics, and the optical fingerprint comparison map before and after reset. If the coincidence degree is less than 99%, repeat the operation of returning the fluorescent particles.
6. The anti-tampering data storage system with dual-mode integration of barcode and RFID according to claim 5, characterized in that, And a cryptographic chip is pre-installed in the RFID module. The generation of a dynamic key each time communication occurs specifically includes: The operator wears a biometric collection device to complete biometric sampling to generate the operator ID, and all operator IDs are aggregated to form a biometric sample library. The cryptographic chip has a built-in key center. After generating the initial key in the key center, the biometric sample library is embedded inside the initial key to form a dynamic key, and the key center signs the dynamic key. The key center consists of biometric recognition, dynamic key generation, digital signature verification, an encrypted communication channel, and a self-destruction mechanism. All the data written in the RFID module is encrypted and protected by the encrypted communication channel of the key center. After the operator triggers an RFID writing request, the scanning monitoring platform uses a biosensor to obtain real-time biometric characteristics and compares and verifies them with all the operator IDs in the biometric sample library. After the verification is passed, the scanning monitoring platform activates the decryption module in the encrypted communication channel in the key center, allowing the operator to write and modify the data inside the RFID module through the decryption module. When the verification fails, the operator is not allowed to perform data operations on the RFID module.
7. The anti-tampering data storage system with dual-mode integration of barcode and RFID according to claim 6, characterized in that, The cross-verification of the hash value based on static data and dynamic data to determine that the overall data has not been tampered with specifically includes: The surface of the barcode data label is scanned multispectrally by a scanning device to obtain a real-time fluorescent particle distribution map, and the original fluorescent particle distribution map of the current static data is extracted. The real-time fluorescent particle distribution map and the original fluorescent particle distribution map are projected into the coordinate system, and the deviation degree between the real-time fluorescent particle distribution map and the original fluorescent particle distribution map is calculated. A static data tampering mark is triggered based on the deviation degree. The scanning monitoring platform reads the operator's biometric characteristics inside the reset confirmation voucher and synchronously sends a dynamic key verification request to the RFID module. When the operator's biometric characteristics inside the reset confirmation voucher match the operator ID in the biometric sample library during the dynamic key verification, the dynamic data decryption channel in the RFID chip is activated. Extract the logical address pointer of the dynamic data storage block in the decryption channel. According to the one-way index from static data to dynamic data, locate the storage location of the RFID chip and extract the dynamic data main hash value written in the corresponding storage location. Perform the first hash comparison between the extracted dynamic data main hash value and the main hash value stored internally in the static data. When the compared hash values are the same, compare the sub-hash values with the hash values at the corresponding levels in the hash tree structure data packet level by level according to the hash tree level identifier. Based on the static data digest value, obtain the generation timestamp and the associated barcode serial number. Verify the time continuity of the dynamic data operation log through the timestamp sequence. When an isolated timestamp or parameter mutation is detected in the dynamic data, trigger the dynamic data tampering mark. Perform a logical OR operation on the static data tampering mark and the dynamic data tampering mark. When either mark is activated, generate a data integrity alarm signal and mark the hierarchical position of the abnormal data segment in the hash tree in the alarm information. When the main hash value and each level of sub-hash values match completely, the scanning monitoring platform generates a data integrity certificate, which includes the main hash value, the verification timestamp, and the topological relationship diagram of the scanning devices participating in the verification.
8. The anti-tampering data storage system with dual-mode integration of barcode and RFID according to claim 7, wherein The specific method of triggering the static data tampering mark based on the deviation degree between the calculated real-time fluorescence particle distribution map and the original fluorescence particle distribution map includes: Project the real-time fluorescence particle distribution map and the original fluorescence particle distribution map onto the same coordinate system, compare the coordinates of each fluorescence particle point by point, calculate the modulus length of the displacement vector of each particle, where the modulus length of the displacement vector is the Euclidean distance between the real-time coordinates and the original coordinates of the particle, and statistically sum up the modulus lengths of all fluorescence particle displacement vectors, denoted as the total displacement. The fluorescence particles with the modulus length of the displacement vector exceeding the displacement threshold are marked as abnormal particles. Screen all abnormal particles and count the total number of abnormal particles. Perform an OR operation on the situation where the total displacement exceeds the displacement threshold and the situation where the total number of abnormal particles exceeds the abnormal quantity threshold. If either situation exists, it is determined that there is a risk of static data tampering and the static data tampering mark is triggered. The displacement threshold is the standard deviation of the particle displacement in the historical tampering scenario, with an initial value of the mean of the average distances between all particle original coordinates. The abnormal quantity threshold is the mean proportion of abnormal particles in the total particles in the historical tampering scenario.
Citation Information
Cited By
Information tamper-proof storage system based on optical characteristics of microfluid
CN121234422A
Drug monitoring and tracing method and system based on tracing label
CN121639230A
A medicine monitoring and tracing method and system based on a tracing label
CN121639230B
A one-way import method for external files based on offline media fingerprint binding
CN122548799A
An external file one-way import method based on offline media fingerprint binding
CN122548799B