Method and device for evaluating credibility of RFID reader-writer

By evaluating the multi-dimensional information of the RFID reader and writer and using the logarithmic probability regression model to dynamically adjust the identity authentication and access control policies, the problem of untrusted behavior of the RFID reader and writer is solved, and the security and response capabilities of the RFID system are improved.

CN120337952APending Publication Date: 2025-07-18CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510320332.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-18
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

In the prior art, the untrustworthiness of the behavior of RFID readers cannot be effectively evaluated, resulting in the inability to deal with malicious operations by static protection measures, which poses security risks.

Method used

By evaluating the multi-dimensional information of the RFID reader and writer, including service information, authentication logs and access logs, the logarithmic probability regression model is used to perform trust assessment, and the identity authentication and access control policies are dynamically adjusted.

Benefits of technology

Dynamic evaluation of RFID readers and writers' behavior is realized, improving the overall security of RFID system and its response speed and adaptability to unknown threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337952A_ABST
    Figure CN120337952A_ABST
Patent Text Reader

Abstract

The invention discloses a method and device for evaluating the credibility of an RFID reader-writer, and belongs to the technical field of network security, and the method comprises the steps: determining multi-dimensional information associated with a target RFID reader-writer when determining that a credibility evaluation condition is satisfied, the multi-dimensional information comprises target RFID reader-writer service information, target RFID reader-writer authentication log information and target RFID reader-writer access RFID tag log information; determining a feature variable corresponding to the multi-dimensional information based on the multi-dimensional information; performing quantitative processing based on the characteristic variable and a preset incidence relation between the characteristic variable and a credibility score, and determining the credibility score; and based on the credibility score and a preset evaluation rule, determining a credibility evaluation result of the target RFID reader-writer. In this way, whether the behavior of the RFID reader-writer is credible or not can be dynamically evaluated, and therefore the overall safety of an RFID system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular, to a method and device for evaluating the trustworthiness of an RFID reader / writer. Background Art

[0002] Radio Frequency Identification (RFID) technology is a non-contact automatic identification technology that uses radio frequency signals to automatically identify target objects and obtain relevant data. With the popularization of RFID technology, its security has gradually become the focus of attention.

[0003] However, traditional security measures often focus on static protection means. For example, in the interaction process between RFID tags and RFID readers / writers, encryption algorithms are applied to ensure the security and integrity of information transmission. However, this static protection measure cannot evaluate whether the behavior of the RFID reader / writer is trustworthy. Summary of the Invention

[0004] Embodiments of this application provide a method and device for evaluating the trustworthiness of an RFID reader / writer to evaluate whether the behavior of the RFID reader / writer is trustworthy in an RFID application scenario and improve the overall security of the RFID system.

[0005] In a first aspect, embodiments of this application provide a method for evaluating the trustworthiness of an RFID reader / writer, the method including:

[0006] When it is determined that the trustworthiness evaluation condition is satisfied, determining multi-dimensional information associated with the target RFID reader / writer, where the multi-dimensional information includes the target RFID reader / writer service information, the target RFID reader / writer authentication log information, and the target RFID reader / writer access RFID tag log information; where the target RFID reader / writer service information is used to characterize the service information supported by the target RFID reader / writer, the target RFID reader / writer authentication log information includes authentication records of two-way authentication between the target RFID reader / writer and an RFID tag or an RFID application server, and the target RFID reader / writer access RFID tag log information includes access records of the target RFID reader / writer accessing RFID tags;

[0007] Based on the multi-dimensional information, determining characteristic variables corresponding to the multi-dimensional information;

[0008] Based on the association relationship between the characteristic variables and the pre-set association between the characteristic variables and the trustworthiness score for quantization processing, determining the trustworthiness score;

[0009] Based on the trust score and a preset evaluation rule, determine the trust evaluation result of the target RFID reader-writer.

[0010] In some embodiments, the quantifying process to determine the trust score based on the association relationship between the feature variables and the preset feature variables and trust scores includes:

[0011] Input the feature variables corresponding to the multi-dimensional information into a logit regression model;

[0012] Based on the probability value calculated by the logit regression model, determine the trust score of the target RFID reader-writer.

[0013] In some embodiments, before inputting the feature variables corresponding to the multi-dimensional information into a pre-trained logit regression model, further include:

[0014] Perform a first preprocessing on the data in the multi-dimensional information to obtain the multi-dimensional information after the first preprocessing, where the first preprocessing includes one or more of data cleaning, data integration, data transformation, and data reduction;

[0015] Perform a second preprocessing on the feature variables corresponding to the multi-dimensional information after the first preprocessing, where the second preprocessing includes Z-Score normalization or min-max normalization.

[0016] In some embodiments, the logit regression model is trained through the following steps:

[0017] Collect multiple training samples, and input the training samples into the logit regression model to be trained for iterative training; wherein, each training sample includes the feature variables corresponding to the multi-dimensional information and a sample label; the parameter to be trained in the logit regression model to be trained is a weight vector;

[0018] Based on the log-likelihood estimation algorithm, construct a loss function;

[0019] In the iterative training process, select some training samples from the training samples, and based on the selected training samples, use the mini-batch gradient descent algorithm to calculate the gradient of the loss function with respect to the weight vector;

[0020] Based on the gradient and a preset learning rate, update the weight vector;

[0021] Based on the updated weight vector, check whether the preset convergence condition is satisfied. If satisfied, stop training and determine that the logit regression model training is completed; if not satisfied, perform the next round of iteration.

[0022] In some embodiments, the evaluation rule is the corresponding relationship between the scoring range and the trust level;

[0023] Determining the trustworthiness evaluation result of the target RFID reader based on the trustworthiness score and the preset evaluation rule includes:

[0024] Based on the corresponding relationship between the scoring range and the trust level, determining the trust level corresponding to the scoring range to which the trustworthiness score of the target RFID reader belongs;

[0025] Based on the trust level of the target RFID reader, determining the trustworthiness evaluation result of the target RFID reader.

[0026] In some embodiments, after determining the trustworthiness evaluation result of the target RFID reader, it further includes:

[0027] Based on the trustworthiness evaluation result of the target RFID reader and the corresponding relationship between the preset evaluation result and the adjustment strategy, determining the adjustment strategy of the target RFID reader;

[0028] Adjusting the target RFID reader based on the adjustment strategy, where the adjustment strategy includes an identity authentication strategy and an access control strategy.

[0029] In some embodiments, adjusting the target RFID reader based on the adjustment strategy includes:

[0030] If the adjustment strategy indicates no adjustment, maintaining the identity authentication strategy and the access control strategy currently used by the target RFID reader;

[0031] If the adjustment strategy indicates enhanced adjustment, enhancing the strategy levels of the identity authentication strategy and the access control strategy currently used by the target RFID reader;

[0032] Wherein, the identity authentication strategy includes some or all of the authentication method, the authentication frequency, and the encryption level; the access control strategy includes the access permission and / or the access duration.

[0033] In a second aspect, an embodiment of the present application provides a device for evaluating the trustworthiness of an RFID reader, including:

[0034] A first determination module, configured to determine multi-dimensional information associated with a target RFID reader when it is determined that the trustworthiness evaluation conditions are met. The multi-dimensional information includes the target RFID reader service information, the target RFID reader authentication log information, and the target RFID reader access RFID tag log information. Among them, the target RFID reader service information is used to characterize the service information supported by the target RFID reader. The target RFID reader authentication log information includes authentication records of two-way authentication between the target RFID reader and an RFID tag or an RFID application server. The target RFID reader access RFID tag log information includes access records of the target RFID reader accessing RFID tags.

[0035] A second determination module, configured to determine characteristic variables corresponding to the multi-dimensional information based on the multi-dimensional information.

[0036] A scoring module, configured to perform quantization processing based on the association relationship between the characteristic variables and the pre-set association between characteristic variables and trustworthiness scores to determine a trustworthiness score.

[0037] An evaluation module, configured to determine a trustworthiness evaluation result of the target RFID reader based on the trustworthiness score and pre-set evaluation rules.

[0038] In some embodiments, the scoring module is specifically configured to:

[0039] Input the characteristic variables corresponding to the multi-dimensional information into a logit regression model.

[0040] Determine the trustworthiness score of the target RFID reader based on the probability value calculated by the logit regression model.

[0041] In some embodiments, it further includes:

[0042] A preprocessing module, configured to perform first preprocessing on the data in the multi-dimensional information to obtain preprocessed multi-dimensional information before the scoring module inputs the characteristic variables corresponding to the multi-dimensional information into a pre-trained logit regression model. The first preprocessing includes one or more of data cleaning, data integration, data transformation, and data reduction.

[0043] Perform second preprocessing on the characteristic variables corresponding to the preprocessed multi-dimensional information. The second preprocessing includes Z-Score normalization processing or min-max normalization processing.

[0044] In some embodiments, the logit regression model is trained through the following steps:

[0045] Collect multiple training samples and input the training samples into the logit regression model to be trained for iterative training; wherein, each training sample includes the feature variables corresponding to the multi-dimensional information and the sample labels; the parameter to be trained in the logit regression model to be trained is the weight vector;

[0046] Construct a loss function based on the log-likelihood estimation algorithm;

[0047] In the iterative training process, select some training samples from the training samples, and based on the selected training samples, use the mini-batch gradient descent algorithm to calculate the gradient of the loss function with respect to the weight vector;

[0048] Update the weight vector based on the gradient and the preset learning rate;

[0049] Based on the updated weight vector, check whether the preset convergence condition is satisfied. If it is satisfied, stop the training and determine that the logit regression model training is completed; if not, perform the next round of iteration.

[0050] In some embodiments, the evaluation rule is the correspondence between the scoring range and the trust level;

[0051] The evaluation module is specifically configured to determine the trust level corresponding to the scoring range to which the trust score of the target RFID reader / writer belongs based on the correspondence between the scoring range and the trust level;

[0052] Determine the trust evaluation result of the target RFID reader / writer based on the trust level of the target RFID reader / writer.

[0053] In some embodiments, it further includes:

[0054] An adjustment module, configured to determine the adjustment strategy of the target RFID reader / writer based on the trust evaluation result of the target RFID reader / writer and the corresponding relationship between the preset evaluation result and the adjustment strategy after the evaluation module determines the trust evaluation result of the target RFID reader / writer;

[0055] Adjust the target RFID reader / writer based on the adjustment strategy, wherein the adjustment strategy includes an identity authentication strategy and an access control strategy.

[0056] In some embodiments, the adjustment module is specifically configured to:

[0057] If the adjustment strategy indicates no adjustment, maintain the identity authentication strategy and the access control strategy currently used by the target RFID reader / writer;

[0058] If the adjustment strategy indicates enhanced adjustment, enhance the policy levels of the authentication policy and access control policy currently used by the target RFID reader / writer.

[0059] Among them, the authentication policy includes some or all of the authentication method, authentication frequency, and encryption level; the access control policy includes access rights and / or access duration.

[0060] In a third aspect, an embodiment of the present application provides an electronic device, including: at least one processor, and a memory communicatively connected to the at least one processor, where:

[0061] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the method for evaluating the trustworthiness of an RFID reader / writer described above.

[0062] In a fourth aspect, an embodiment of the present application provides a storage medium, when the computer program in the storage medium is executed by a processor of an electronic device, the electronic device can execute the method for evaluating the trustworthiness of an RFID reader / writer described above.

[0063] In a fifth aspect, an embodiment of the present application provides a computer program product, when the computer program product is called and executed by an electronic device, the electronic device is enabled to execute the method for evaluating the trustworthiness of an RFID reader / writer described above.

[0064] In the embodiment of the present application, when it is determined that the trustworthiness evaluation condition is satisfied, multi-dimensional information associated with the target RFID reader / writer is determined. The multi-dimensional information includes target RFID reader / writer service information, target RFID reader / writer authentication log information, and target RFID reader / writer access RFID tag log information. The target RFID reader / writer service information is used to characterize the service information supported by the target RFID reader / writer. The target RFID reader / writer authentication log information includes authentication records of two-way authentication between the target RFID reader / writer and an RFID tag or an RFID application server. The target RFID reader / writer access RFID tag log information includes access records of the target RFID reader / writer accessing RFID tags. Based on the multi-dimensional information, characteristic variables corresponding to the multi-dimensional information are determined. Based on the association relationship between the characteristic variables and the pre-set association between the characteristic variables and the trustworthiness score, quantization processing is performed to determine the trustworthiness score. Based on the trustworthiness score and the pre-set evaluation rules, the trustworthiness evaluation result of the target RFID reader / writer is determined. In this way, when it is determined that the trustworthiness evaluation condition is satisfied, the trustworthiness of the RFID reader / writer is scored, and the trustworthiness evaluation result of the RFID reader / writer is determined according to the trustworthiness score, which can realize dynamic evaluation of whether the behavior of the RFID reader / writer is trustworthy, thereby improving the overall security of the RFID system.

[0065] Other features and advantages of the present application will be described in the following specification. Moreover, they will be partly obvious from the specification or understood by implementing the present application. The objectives and other advantages of the present application can be achieved and obtained by the structures specifically pointed out in the written specification, claims, and drawings. Description of the Drawings

[0066] The drawings described herein are used to provide a further understanding of the present application and form a part of the present application. The schematic embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:

[0067] Figure 1 It is a diagram of an application scenario of a method for evaluating the trustworthiness of an RFID reader provided by an embodiment of the present application;

[0068] Figure 2 It is a flowchart of a method for evaluating the trustworthiness of an RFID reader provided by an embodiment of the present application;

[0069] Figure 3 It is a schematic diagram of the training process of a logit regression model provided by an embodiment of the present application;

[0070] Figure 4 It is a schematic diagram of the data preprocessing process based on the logit regression model in an RFID application scenario provided by an embodiment of the present application;

[0071] Figure 5 It is a schematic diagram of the process of a trustworthiness evaluation method based on the logit regression model in an RFID application scenario provided by an embodiment of the present application;

[0072] Figure 6 It is a schematic diagram of the structure of a device for evaluating the trustworthiness of an RFID reader provided by an embodiment of the present application;

[0073] Figure 7 It is a schematic diagram of the hardware structure of an electronic device for implementing a method for evaluating the trustworthiness of an RFID reader provided by an embodiment of the present application. Detailed Embodiments

[0074] To make the objectives and implementation manners of the present application clearer, the following will clearly and completely describe the exemplary embodiments of the present application with reference to the drawings in the exemplary embodiments of the present application. Obviously, the described exemplary embodiments are only a part of the embodiments of the present application, rather than all of the embodiments.

[0075] It should be noted that in the description of the embodiments of the present application, terms such as "first" and "second" are used to distinguish similar objects, and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present application described here can be implemented in an order other than those illustrated or described here.

[0076] In the description of the embodiments of the present application, unless otherwise specified, "a plurality of" means two or more. "And / or" describes the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after.

[0077] The terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.

[0078] The term "module" refers to any known or later-developed hardware, software, firmware, artificial intelligence, fuzzy logic, or a combination of hardware or / and software code that can perform functions related to that element.

[0079] The following describes the exemplary embodiments of the present application in conjunction with the accompanying drawings. Various details of the embodiments of the present application are included to facilitate understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described here without departing from the scope of the disclosure of the present application. Similarly, for the sake of clarity and conciseness, the description below omits the description of well-known functions and structures. It should be noted that in the embodiments of the present application, certain industry-existing solutions such as certain software, components, models, etc. may be mentioned, and they should be considered exemplary. The purpose is only to illustrate the feasibility of implementing the technical solutions of the present application, but it does not mean that the applicant has already or necessarily used this solution.

[0080] In the technical solution of the present application, the acquisition, transmission, storage, use, etc. of data all comply with the requirements of relevant national laws and regulations.

[0081] Before introducing the method for evaluating the trustworthiness of an RFID reader provided by the embodiments of the present application, for the sake of easy understanding, first, the technical background of the embodiments of the present application will be introduced in detail below.

[0082] RFID technology is a non-contact automatic identification technology that uses radio frequency signals to automatically identify target objects and obtain relevant data. With the popularization of RFID technology, its security has gradually become the focus of attention.

[0083] However, traditional security measures often focus on static protection means. For example, during the interaction between RFID tags and RFID readers, encryption algorithms are applied to ensure the security and integrity of information transmission. However, this static protection measure cannot evaluate whether the behavior of the RFID reader is trustworthy. Because if an RFID reader is compromised, even if strong encryption technology is used, it may still perform malicious operations without being detected. For example, once an RFID reader is controlled by an attacker and the RFID reader has certain legitimate access rights, it can use these rights to perform unauthorized access, and traditional static security measures are powerless against this.

[0084] In view of this, to solve the problem that the static protection measures in the prior art cannot evaluate whether the behavior of the RFID reader is trustworthy, the embodiments of the present application provide a method and device for evaluating the trustworthiness of the RFID reader. Some preferred embodiments of the present application are described below with reference to the accompanying drawings of the specification.

[0085] To facilitate the understanding of the present application, in the technical terms involved in the present application:

[0086] Radio Frequency Identification (RFID): RFID radio frequency identification is a non-contact automatic identification technology that uses radio frequency signals to automatically identify target objects and obtain relevant data.

[0087] Transport Layer Security (TLS): TLS is a transport layer security protocol based on the Transmission Control Protocol (TCP), mainly used to provide confidentiality, data integrity, and data source verification functions between client / server application programs. The implementation of its functions mainly depends on three types of algorithms: hash function Hash, symmetric encryption, and asymmetric encryption. The TLS protocol consists of two layers: the TLS Record Protocol (TLSRecord) and the TLS Handshake Protocol (TLS Handshake), and its predecessor is the Secure Sockets Layer (SSL) protocol.

[0088] Electronic Product Code (EPC): The EPC electronic product coding system is a new generation of coding standard that is compatible with the European Article Numbering (EAN) and the Uniform Code Council (UCC) in the United States. It is an important part of the global unified identification system. Each RFID tag has a globally unique EPC code, and the reader can read the EPC tag information through the radio frequency identification system.

[0089] Electronic Product Code Information Service (EPCIS): The EPC Information Service (EPCIS) is an important part of the EPC network. The EPCIS standard mainly defines a data model and two interfaces. The EPCIS data model uses a standard method to represent the visual information of entity objects, covering the EPC time, status, reading point, transaction information, and other relevant additional information of the object (which can be summarized as what, where, when, and why). As the attributes of entity objects in the real world, such as status and location, change (referred to as "events"), the EPCIS collection interface is responsible for generating the object information described in the model. EPCIS performs EPCIS standard conversion on the data transmitted by the middleware and exchanges data with other systems within the enterprise or external systems through secure methods such as authentication or authorization, such as package tracking, product identification, promotion management, and luggage tracking.

[0090] Object Name Service (ONS): The ONS object name resolution service adopts the basic principle of the Domain Name System (DNS) to map an EPC to one or more IP / URIs (Uniform Resource Identifier). Through these IP / URIs, we can find other detailed information about this product on the EPCIS or Web server.

[0091] Figure 1 This is an application scenario diagram of a method for evaluating the trustworthiness of an RFID reader provided in the embodiments of this application, mainly including five components: RFID tags, RFID readers, RFID application gateways, RFID application servers of relying party services, and RFID trust evaluation engines.

[0092] The method for evaluating the trustworthiness of an RFID reader provided in this application is applied to an electronic device, which can be a device such as an RFID application server. The RFID reader trust evaluation engine is deployed in the electronic device to implement the process of evaluating the trustworthiness of the RFID reader.

[0093] Among them, the functions of each component are briefly described as follows:

[0094] RFID tag, each RFID tag has a globally unique EPC electronic product code, which is used to carry Internet of Things item or environmental perception information.

[0095] RFID reader / writer, which is used for non-contact interaction with RFID tags through radio frequency signals. The RFID reader / writer and the RFID tag implement two-way authentication and transmission encryption in the challenge-response mode based on the national secret SM7 symmetric cipher, implement data encryption for the storage areas of the RFID reader / writer and the tag based on the national secret SM1 / SM4 symmetric cipher, generate message digests based on the national secret SM3 hash function, and generate and verify digital signatures based on the national secret SM2 asymmetric cipher.

[0096] RFID application gateway, which is used to implement two-way authentication with the RFID application server and the RFID reader / writer respectively through the TLS protocol, and establish a secure communication channel. It conducts access control rule compliance detection and management control on the information interaction between the RFID reader / writer and the RFID tag.

[0097] RFID application server, which is used to provide ONS object name resolution service, EPCIS information service and RFID application services in specific fields, call the RFID trust evaluation engine, and determine the trust evaluation result of the target RFID reader / writer according to the trust score and the pre-set evaluation rules.

[0098] RFID trust evaluation engine, which is used to collect and analyze cross-platform multi-dimensional information such as RFID reader / writer information, RFID tag information, RFID reader / writer service information, RFID reader / writer authentication log information, and RFID reader / writer access RFID tag log information, and perform quantitative processing based on the correlation relationship between the characteristic variables corresponding to the multi-dimensional information and the pre-set characteristic variables and trust scores; output the trust score.

[0099] It should be noted that the application scenarios described in the embodiments of the present application are for more clearly explaining the technical solutions of the embodiments of the present invention, and do not constitute a limitation on the technical solutions provided by the embodiments of the present invention. Those of ordinary skill in the art know that with the emergence of new application scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.

[0100] After introducing the application scenarios of the embodiments of the present application, the method for evaluating the trustworthiness of RFID readers / writers is applied to Figure 1 the application architecture shown below as an example to illustrate the method for evaluating the trustworthiness of RFID readers / writers proposed in the present application.

[0101] Figure 2The flowchart of a method for evaluating the trustworthiness of an RFID reader provided by an embodiment of the present application, and the method includes the following steps.

[0102] In step 201, when it is determined that the trustworthiness evaluation condition is met, multi-dimensional information associated with the target RFID reader is determined. The multi-dimensional information includes target RFID reader service information, target RFID reader authentication log information, and target RFID reader access RFID tag log information. Among them, the target RFID reader service information is used to characterize the service information supported by the target RFID reader. The target RFID reader authentication log information includes authentication records of two-way authentication between the target RFID reader and the RFID tag or the RFID application server. The target RFID reader access RFID tag log information includes access records of the target RFID reader accessing the RFID tag.

[0103] Specifically, determining that the trustworthiness evaluation condition is met can be when a preset evaluation period is reached. For example, the preset evaluation period is every 24 hours, every week, or every month, etc. In this way, by setting a fixed evaluation period, when the preset evaluation period is reached, the trustworthiness evaluation process is automatically triggered. It can ensure regular review of the trustworthiness of the target RFID reader and timely discovery of potential risks or problems. Determining that the trustworthiness evaluation condition is met can also be triggered by receiving an evaluation instruction from a businessperson. In this way, when a special situation or potential security threat occurs, the evaluation can be carried out immediately without waiting for the next scheduled evaluation period. Of course, in addition to the preset evaluation period and the manual instruction of the businessperson, determining that the trustworthiness evaluation condition is met can also be triggered by other means, such as after network configuration changes, hardware upgrades, or software updates, when new important data is input into the system (such as newly added historical interaction records, new security intelligence, etc.). Specifically, it can be set by technicians according to the actual situation, and the present application does not limit this.

[0104] In specific implementation, when it is determined that the trustworthiness evaluation conditions are met, multi-dimensional information associated with the target RFID reader is determined. Among them, the target RFID reader service information is used to characterize the service information supported by the target RFID reader. For example, the service types supported by the target RFID reader, such as inventory management, asset tracking, logistics monitoring, etc., and the supported functional characteristics, including read / write distance, data transmission rate, whether encryption is supported, etc. The target RFID reader authentication log information includes the authentication records of the two-way authentication between the target RFID reader and the RFID tag or the RFID application server. Among them, the authentication records are, for example, authentication timestamps, authentication results (identifications of success or failure), authentication participant information, adopted authentication methods, etc. The target RFID reader access RFID tag log information includes the access records of the target RFID reader accessing the RFID tag. Among them, the access records are, for example, access timestamps, IDs of the accessed tags, access types (read, write), access results, etc. In addition, RFID reader information can also be determined, such as RFID reader ID, status information (online, offline), specification model, deployment location information, etc., and RFID tag information, such as tag ID, stored data information, tag type, etc.

[0105] By integrating this multi-dimensional information, the operating conditions and security level of the RFID reader can be comprehensively understood, providing a basis for evaluating the trustworthiness of the RFID reader.

[0106] In step 202, based on the multi-dimensional information, characteristic variables corresponding to the multi-dimensional information are determined.

[0107] In specific implementation, the characteristic variables corresponding to the multi-dimensional information include, but are not limited to, the target RFID reader service ID, the target RFID reader authentication log ID, the target RFID reader access RFID tag log ID, as well as the RFID reader ID, the RFID tag ID, etc.

[0108] In step 203, based on the association relationship between the characteristic variables and the pre-set association between the characteristic variables and the trustworthiness score, a quantification process is performed to determine the trustworthiness score.

[0109] In specific implementation, the characteristic variables corresponding to the multi-dimensional information can be input into the logit regression model; based on the probability value calculated by the logit regression model, the trustworthiness score of the target RFID reader is determined.

[0110] In specific implementation, before inputting the feature variables corresponding to multi-dimensional information into a pre-trained logit regression model, the data in the multi-dimensional information can be subjected to a first preprocessing to obtain the multi-dimensional information after the first preprocessing, where the first preprocessing includes one or more of data cleaning, data integration, data transformation, and data reduction; in this way, through the first preprocessing, the standardization and integrity of the data in the multi-dimensional information after data preprocessing can be improved.

[0111] In specific implementation, the feature variables corresponding to the multi-dimensional information after the first preprocessing are subjected to a second preprocessing, where the second preprocessing includes Z-Score normalization processing or min-max normalization processing. Among them, Z-Score normalization processing converts the feature variables corresponding to the multi-dimensional information after preprocessing into a standard normal distribution with a mean of 0 and a standard deviation of 1, and min-max normalization processing scales the feature variables corresponding to the multi-dimensional information after preprocessing to feature variables between a specified minimum value and a maximum value. The minimum value can be 0 and the maximum value can be 1. In this way, through the second preprocessing, it helps to improve the quality, standardization, and integrity of the data, thereby enhancing the performance and accuracy of the model. By determining the feature variables corresponding to the multi-dimensional information in any one of the above two ways, the accuracy and flexibility of determining the feature variables corresponding to the multi-dimensional information are improved.

[0112] In specific implementation, the logit regression model can be trained through the following steps. Figure 3 The following is a schematic diagram of the training process of a logit regression model provided by an embodiment of the present application, including the following steps:

[0113] In step 301, a plurality of training samples are collected, and the training samples are input into the logit regression model to be trained for iterative training; among them, each training sample includes the feature variables corresponding to the multi-dimensional information and the sample label; the parameter to be trained in the logit regression model to be trained is the weight vector.

[0114] In specific implementation, multi-dimensional information such as RFID reader information, RFID tag information, RFID reader service information, RFID reader authentication log information, and RFID reader access RFID tag log information is collected, and the collected multi-dimensional information is subjected to data preprocessing. The data preprocessing includes data cleaning (missing value processing, outlier processing), data integration, data transformation (data standardization, normalization, and feature extraction), data reduction (feature selection, data dimensionality reduction), etc.

[0115] In specific implementation, corresponding feature variables are generated based on the collected multi-dimensional information. The feature variables may include, but are not limited to, RFID reader ID, RFID tag ID, RFID application service ID, RFID reader authentication log information ID, RFID reader access RFID tag log information ID, etc. And the feature variables are processed by Z-Score normalization or min-max normalization, and a label is assigned to each training sample. The label is used to characterize the trustworthiness (trusted or untrusted) of the RFID reader. Wherein, for the convenience of calculation, each training sample also includes a field with a value of 1 at the end.

[0116] In step 302, a loss function is constructed based on the logarithmic maximum likelihood estimation algorithm.

[0117] In specific implementation, to alleviate model overfitting, regularization can also be introduced, such as introducing L2 regularization, that is, ridge regression.

[0118] In step 303, during the iterative training process, a part of the training samples are selected from the training samples. Based on the selected training samples, the small-batch gradient descent algorithm is used to calculate the gradient of the loss function with respect to the weight vector.

[0119] In specific implementation, the entire training sample is divided into multiple small-batch data. Each small-batch data contains multiple training samples, and each training sample contains feature variables and labels (trustworthiness scores). Among them, the small-batch gradient descent method is an improved gradient descent method. It randomly selects a small-batch sample (instead of all samples) from the training data each time to calculate the gradient, which can achieve a balance between computational efficiency and stability. This gradient indicates how to adjust the parameters to make the loss function value decrease fastest.

[0120] In step 304, the weight vector is updated based on the gradient and the preset learning rate.

[0121] In specific implementation, based on the calculated gradient and the learning rate, the model parameters are updated to reduce the loss function value, making the loss function gradually decrease, thereby improving the performance of the model on the training data. Wherein, the learning rate is used to control the amplitude of each update. Here, the initial value of the weight vector can be randomly selected from a normal distribution with a mean of 0 and a standard deviation of 1.

[0122] In step 305, based on the updated weight vector, it is checked whether the preset convergence condition is satisfied. If satisfied, the training is stopped and it is determined that the logistic regression model training is completed; if not satisfied, the next round of iteration is performed.

[0123] In specific implementation, after each update of the weight vector, it is necessary to check whether the preset convergence condition is met. The convergence condition can be, for example, reaching the maximum number of iterations, the magnitude of the gradient vector approaching a preset value, the change amount of the weight vector being less than a preset threshold, etc.

[0124] In specific implementation, during each iteration process, the samples are input into the model to generate predicted outputs, which are used to calculate the loss function and the gradient, thereby guiding the update of the weight vector. The ultimate goal is to minimize the loss function and improve the prediction ability of the model. When the preset convergence condition is met, it is determined that the training of the logistic regression model is completed.

[0125] In specific implementation, the "K-fold cross-validation method" (K is often taken as 10) can also be used to test and optimize the learned logistic regression model. The validation set is used to optimize and deploy hyperparameters to optimize the learned model.

[0126] In step 204, based on the trustworthiness score and the preset evaluation rule, the trustworthiness evaluation result of the target RFID reader / writer is determined.

[0127] In specific implementation, the evaluation rule is the correspondence between the score range and the trustworthiness level. Therefore, based on the correspondence between the score range and the trustworthiness level, the trustworthiness level corresponding to the score range to which the trustworthiness score of the target RFID reader / writer belongs can be determined; based on the trustworthiness level of the target RFID reader / writer, the trustworthiness evaluation result of the target RFID reader / writer is determined.

[0128] For example, since the logistic regression model outputs probability values usually between 0 and 1, taking the trustworthiness level divided into three levels: high, medium, and low as an example, the preset correspondence between the score range and the trustworthiness level can be that when the score range is greater than 0.75 and less than or equal to 1.0, the trustworthiness level is high; when the score range is greater than 0.5 and less than or equal to 0.75, the trustworthiness level is medium; when the score range is less than or equal to 0.5, the trustworthiness level is low.

[0129] In specific implementation, the evaluation result with the trustworthiness level of "high" can be set as highly trustworthy, which means that there is no need to re-authenticate the RFID reader / writer to be tested; the evaluation result with the trustworthiness level of "medium" is medium trustworthy, which means that there is a certain risk and monitoring needs to be strengthened; the evaluation result with the trustworthiness level of "low" is untrustworthy, which means that there may be potential safety hazards and the RFID reader / writer to be tested needs to be re-authenticated.

[0130] Suppose the trustworthiness score of RFID reader / writer A is 0.83, and 0.83 is greater than 0.75 and less than 1.0, then the corresponding trustworthiness level is "high". Therefore, RFID reader / writer A is highly trustworthy and there is no need to re-authenticate RFID reader / writer A.

[0131] In this way, when it is determined that the trust evaluation conditions are met, the trust score of the RFID reader is obtained, and the trust evaluation result of the RFID reader is determined according to the trust score, so as to dynamically evaluate whether the behavior of the RFID reader is trustworthy, thereby improving the overall security of the RFID system. This dynamic evaluation mechanism not only helps to enhance the system's defense ability, but also improves the response speed and adaptability to unknown threats.

[0132] In specific implementation, after determining the trust evaluation result of the target RFID reader, corresponding management measures need to be further taken according to the evaluation result. The adjustment strategy of the target RFID reader can be determined based on the corresponding relationship between the trust evaluation result of the target RFID reader and the pre-set evaluation result and adjustment strategy. Based on the adjustment strategy, the target RFID reader is adjusted, where the adjustment strategy includes an identity authentication strategy and an access control strategy.

[0133] For example, when the evaluation result is highly trustworthy and moderately trustworthy, the current adjustment strategy of the target RFID reader can be maintained. When the evaluation result is untrustworthy, a strengthened adjustment strategy can be adopted for the target RFID reader. Of course, in some application scenarios, when the evaluation result is highly trustworthy, a relaxed adjustment strategy can also be adopted for the target RFID reader.

[0134] In specific implementation, if the adjustment strategy indicates no adjustment, the identity authentication strategy and access control strategy currently used by the target RFID reader are maintained;

[0135] If the adjustment strategy indicates a strengthened adjustment, the strategy levels of the identity authentication strategy and access control strategy currently used by the target RFID reader are enhanced; among them, the identity authentication strategy includes some or all of the authentication method, authentication frequency, and encryption level; the access control strategy includes access rights and / or access duration.

[0136] In specific implementation, the identity authentication strategy is updated: the identity authentication strategy between the target RFID reader and the RFID tag or application server is adjusted according to the trust score. For untrusted readers, increase the authentication frequency, enable a more stringent two-way authentication method, or update the encryption key and certificate; for moderately trusted / highly trusted readers, maintain the existing authentication strategy. For untrusted readers, reduce the access rights (restrict access to sensitive resources) and shorten the access duration; for moderately trusted / highly trusted readers, maintain the existing authentication strategy.

[0137] In specific implementation, in some application scenarios, when the evaluation result is highly credible, a lenient adjustment strategy can also be adopted for the target RFID reader / writer. When the adjustment strategy indicates lenient adjustment, the strategy levels of the current identity authentication strategy and access control strategy used by the target RFID reader / writer can be weakened. For example, for a highly credible reader / writer, the access permission can be increased (allowing more resource access), the access duration can be increased, etc., the authentication frequency can be reduced, and a more lenient two-way authentication method can be enabled, etc.

[0138] For example, the current identity authentication strategy and access control strategy of RFID reader / writer B are: authentication frequency: authenticate once every two accesses, encryption level: AES-256, access permission level: daily access time limit: 8 hours. If the evaluation result of RFID reader / writer B is untrusted, a strengthened adjustment strategy will be adopted for RFID reader / writer B. Then the adjusted identity authentication strategy and access control strategy are: authentication frequency: authenticate for each access, encryption level: increased to a higher encryption level, such as AES-384, access permission level: 2, daily access time limit: 5 hours.

[0139] In specific implementation, the RFID application server: is also used to update the identity authentication strategy and access control strategy of the RFID reader / writer and send them to the RFID application gateway for specific execution, so as to achieve continuous dynamic security authentication and access control.

[0140] In this way, based on the trustworthiness evaluation result, the adjustment strategy of the target RFID reader / writer is dynamically adjusted. For those RFID reader / writers whose trustworthiness scores do not meet the standard, the system will trigger the process of updating their identity authentication strategy and access control strategy. Through these adjustments, it is ensured that only fully verified reader / writers can access sensitive information or perform critical operations, thereby improving the security of the entire RFID system. This dynamic evaluation mechanism not only helps to enhance the system's defense ability but also improves the response speed and adaptability to unknown threats.

[0141] Next, the present application will be introduced in detail in two parts: data preprocessing based on the logit regression model in the RFID application scenario and the trustworthiness evaluation method based on the logit regression model in the RFID application scenario.

[0142] Figure 4 FIG. is a schematic flowchart of data preprocessing based on the logit regression model in an RFID application scenario provided by an embodiment of the present application, including the following steps:

[0143] In step 401, the RFID application server obtains metadata such as authoritative and reliable RFID reader public key certificates and RFID application gateway public key certificates from the metadata service; the RFID application gateway implements two-way authentication with the RFID application server and the RFID reader respectively through the TLS protocol and establishes a secure communication channel; the RFID application server issues the RFID reader identity authentication policy and access control policy to the RFID application gateway.

[0144] In step 402, the RFID reader and the RFID tag implement challenge-response mode two-way authentication and transmission encryption based on the national secret SM7 symmetric cipher, implement data encryption for the storage areas of the RFID reader and the tag based on the national secrets SM1 / SM4 symmetric ciphers, generate message digests based on the national secret SM3 hash function, and generate and verify digital signatures based on the national secret SM2 asymmetric cipher.

[0145] In step 403, the RFID application server aggregates cross-platform multi-source information such as the RFID reader information, RFID tag information, RFID service information, RFID reader authentication log information, and RFID reader access RFID tag log information collected, and performs necessary data preprocessing. The data preprocessing includes data cleaning (missing value processing, outlier processing), data integration, data transformation (data standardization, normalization, and feature extraction), data reduction (feature selection, data dimensionality reduction), etc.

[0146] In step 404, the selected feature variables after data preprocessing may include but are not limited to the RFID reader ID, RFID tag ID, RFID application service ID, RFID reader authentication log information ID, RFID reader access RFID tag log information ID, etc.; perform Z-Score normalization (convert the data into a standard normal distribution with a mean of 0 and a standard deviation of 1) or min-max normalization (scale the data to between a specified minimum and maximum value (usually 0 and 1)) on the selected feature variables.

[0147] In step 405, assume that there are n finally selected feature variables and the number of training samples is m; manually or automatically through auxiliary tools, label each of the m training samples with y (1 or 0); each training sample data has n feature variable values, and add an element that is always 1 at the end, thus constructing a data set D with m rows and (n + 1) columns from the m training samples; the m labels corresponding to the m training samples form a label vector Y with m rows and 1 column.

[0148] Figure 5 The flowchart of a trustworthiness evaluation method based on a logit regression model in an RFID application scenario provided by an embodiment of this application includes the following steps:

[0149] Step 1: The "Sigmoid" function corresponding to the logit regression model of this application is expressed as:

[0150]

[0151] x is an n-row and 1-column vector corresponding to n feature variable training samples, w is an n-row and 1-column weight vector, b is the bias, and T represents the transpose;

[0152] β = (w; b).

[0153] Step 2: Given the dataset D and the label vector Y, applying the log-likelihood method to the aforementioned "Sigmoid" function to estimate the weight column vector β is equivalent to minimizing the following function:

[0154]

[0155] Here, the log-likelihood method is a commonly used parameter estimation method, and its goal is to find the parameter values that maximize the probability of the observed data. Here, it is equivalent to minimizing a specific function, which measures the difference between the model prediction and the actual label.

[0156] Step 3: To alleviate model overfitting, L2 regularization, i.e., ridge regression, is introduced, and the function to be minimized becomes:

[0157] where the regularization parameter α satisfies 0 < α < 1.

[0158] Here, L2 regularization (ridge regression) is introduced to alleviate the model overfitting problem. Overfitting refers to the situation where the model performs well on the training data but poorly on new data. L2 regularization makes the model more general by adding a regularization term to the loss function to penalize large weight values.

[0159] Step 4: L(β) is a high-order differentiable continuous convex function with respect to β. According to the convex optimization theory, the gradient descent method can be used to solve its numerical optimal solution: The mini-batch gradient descent method is used to calculate the gradient: Each time the gradient is calculated, randomly select Batch-num from m instead of all participating in the gradient calculation. Here, the mini-batch gradient descent method is a compromise between the batch gradient descent method and the stochastic gradient descent method, and has the advantages of balancing computational efficiency and stability and being suitable for processing large-scale datasets.

[0160]

[0161] Here, the mini-batch gradient descent method is a compromise between the batch gradient descent method and the stochastic gradient descent method, and has the advantages of balancing computational efficiency and stability and being suitable for processing large-scale datasets.

[0162] Step 5: The initial value of the weight vector β with (n + 1) rows and 1 column can be a random number from a normal distribution with a mean of 0 and a standard deviation of 1, and k = 0; its iterative formula for the (k + 1)-th step is:

[0163] where η is the step size or learning rate, and 0 < η < 1.

[0164] Here, in each iteration, the weight vector β is updated according to the current gradient and the learning rate η.

[0165] Step 6: The iterative convergence conditions of the gradient descent method generally include that the magnitude of the gradient vector is close to 0, the change amount of the weight vector is less than a preset threshold, or the preset number of iteration thresholds is reached; when the iterative convergence conditions are met, the weight vector β corresponding to the optimal solution of L(β) can be obtained, and the learning of the logit regression model is completed.

[0166] Step 7: Use the "K-fold cross-validation method" (K is usually taken as 10) to test and optimize the learned logit model; use the validation set to optimize and allocate hyperparameters (α, η, Batch-num) to optimize the learned model. The RFID application server calls the trust evaluation engine based on the logit regression model, and determines the trustworthiness evaluation result of the target RFID reader according to the evaluation rules preset for the output trust score. Based on the corresponding relationship between the trustworthiness evaluation result, the preset evaluation result and the adjustment strategy, determine the adjustment strategy of the target RFID reader. Based on the adjustment strategy, adjust the identity authentication strategy and access control strategy of the RFID reader, and send them to the RFID application gateway for specific execution, so as to achieve continuous dynamic security authentication and access control.

[0167] In this way, the trustworthiness evaluation method based on the logit regression model, L2 regularization, and mini-batch gradient descent method aggregates and analyzes cross-platform multi-source information such as RFID reader information, RFID tag information, RFID application service information, RFID reader authentication log information, and RFID reader access RFID tag log information, and outputs a trust score, which can realize dynamic evaluation of whether the behavior of the RFID reader is trustworthy, thereby improving the overall security of the RFID system.

[0168] Based on the same technical concept, the embodiment of the present application also provides a device for evaluating the trustworthiness of an RFID reader. The principle of the device for evaluating the trustworthiness of an RFID reader to solve problems is similar to the above method for evaluating the trustworthiness of an RFID reader. Therefore, the implementation of the device for evaluating the trustworthiness of an RFID reader can refer to the implementation of the method for evaluating the trustworthiness of an RFID reader, and the repeated parts will not be described again.

[0169] Figure 6The figure is a schematic structural diagram of a device for evaluating the trustworthiness of an RFID reader provided by an embodiment of the present application, including a first determination module 601, a second determination module 602, a scoring module 603, and an evaluation module 604.

[0170] The first determination module 601 is configured to determine multi-dimensional information associated with a target RFID reader when it is determined that the trustworthiness evaluation condition is met. The multi-dimensional information includes the target RFID reader service information, the target RFID reader authentication log information, and the target RFID reader access RFID tag log information. Among them, the target RFID reader service information is used to characterize the service information supported by the target RFID reader. The target RFID reader authentication log information includes authentication records of two-way authentication between the target RFID reader and an RFID tag or an RFID application server. The target RFID reader access RFID tag log information includes access records of the target RFID reader accessing RFID tags.

[0171] The second determination module 602 is configured to determine characteristic variables corresponding to the multi-dimensional information based on the multi-dimensional information.

[0172] The scoring module 603 is configured to perform quantization processing based on the association relationship between the characteristic variables and the pre-set association between the characteristic variables and the trustworthiness score, and determine the trustworthiness score.

[0173] The evaluation module 604 is configured to determine the trustworthiness evaluation result of the target RFID reader based on the trustworthiness score and the pre-set evaluation rules.

[0174] In some embodiments, the scoring module 603 is specifically configured to:

[0175] Input the characteristic variables corresponding to the multi-dimensional information into a logit regression model.

[0176] Determine the trustworthiness score of the target RFID reader based on the probability value calculated by the logit regression model.

[0177] In some embodiments, it further includes:

[0178] A preprocessing module 605 is configured to perform first preprocessing on the data in the multi-dimensional information to obtain the multi-dimensional information after the first preprocessing before the scoring module 603 inputs the characteristic variables corresponding to the multi-dimensional information into a pre-trained logit regression model. The first preprocessing includes one or more of data cleaning, data integration, data transformation, and data reduction.

[0179] Perform a second preprocessing on the feature variables corresponding to the first preprocessed multi-dimensional information, where the second preprocessing includes Z-Score normalization or min-max normalization.

[0180] In some embodiments, the logit regression model is trained through the following steps:

[0181] Collect a plurality of training samples, and input the training samples into the logit regression model to be trained for iterative training; wherein, each training sample includes the feature variables corresponding to the multi-dimensional information and a sample label; the parameter to be trained in the logit regression model to be trained is a weight vector.

[0182] Construct a loss function based on the log-likelihood estimation algorithm.

[0183] In the iterative training process, select a part of the training samples from the training samples, and based on the selected training samples, use the mini-batch gradient descent algorithm to calculate the gradient of the loss function with respect to the weight vector.

[0184] Update the weight vector based on the gradient and a preset learning rate.

[0185] Based on the updated weight vector, check whether a preset convergence condition is satisfied. If it is satisfied, stop training and determine that the training of the logit regression model is completed; if not, perform the next round of iteration.

[0186] In some embodiments, the evaluation rule is the correspondence between a scoring range and a confidence level.

[0187] The evaluation module 604 is specifically configured to determine the confidence level corresponding to the scoring range to which the confidence score of the target RFID reader / writer belongs based on the correspondence between the scoring range and the confidence level.

[0188] Determine the confidence evaluation result of the target RFID reader / writer based on the confidence level of the target RFID reader / writer.

[0189] In some embodiments, it further includes:

[0190] An adjustment module 606, configured to determine an adjustment strategy for the target RFID reader / writer based on the confidence evaluation result of the target RFID reader / writer and the corresponding relationship between the preset evaluation result and the adjustment strategy after the evaluation module determines the confidence evaluation result of the target RFID reader / writer.

[0191] Adjust the target RFID reader / writer based on the adjustment strategy, where the adjustment strategy includes an identity authentication strategy and an access control strategy.

[0192] In some embodiments, the adjustment module 606 is specifically configured to:

[0193] If the adjustment policy indicates no adjustment, maintain the current authentication policy and access control policy used by the target RFID reader;

[0194] If the adjustment policy indicates enhanced adjustment, enhance the policy levels of the current authentication policy and access control policy used by the target RFID reader;

[0195] Wherein, the authentication policy includes some or all of the authentication method, authentication frequency, and encryption level; the access control policy includes access rights and / or access duration.

[0196] After introducing the method and apparatus for evaluating the trust level of an RFID reader according to the exemplary embodiments of the present application, next, an electronic device according to another exemplary embodiment of the present application is introduced.

[0197] Next, refer to Figure 7 to describe the electronic device 130 implemented according to this embodiment of the present application. Figure 7 The electronic device 130 shown is merely an example and should not impose any limitations on the functions and usage scope of the embodiments of the present application.

[0198] As Figure 7 shown, the electronic device 130 is presented in the form of a general-purpose electronic device. The components of the electronic device 130 may include, but are not limited to: at least one of the above-mentioned processors 131, at least one of the above-mentioned memories 132, and a bus 133 connecting different system components (including the memory 132 and the processor 131).

[0199] The bus 133 represents one or more of several types of bus structures, including a memory bus or memory controller, a peripheral bus, a processor, or a local bus using any of the multiple bus structures.

[0200] The memory 132 may include a readable medium in the form of volatile memory, such as a random access memory (RAM) 1321 and / or a cache memory 1322, and may further include a read-only memory (ROM) 1323.

[0201] The memory 132 may further include a program / utility 1325 having a set (at least one) of program modules 1324. Such program modules 1324 include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment.

[0202] The electronic device 130 can also communicate with one or more external devices 134 (such as a keyboard, a pointing device, etc.), and can also communicate with one or more devices that enable a user to interact with the electronic device 130, and / or communicate with any device (such as a router, a modem, etc.) that enables the electronic device 130 to communicate with one or more other electronic devices. Such communication can be carried out through the input / output (I / O) interface 135. Moreover, the electronic device 130 can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 136. As shown in the figure, the network adapter 136 communicates with other modules for the electronic device 130 through the bus 133. It should be understood that although not shown in the figure, other hardware and / or software modules can be used in combination with the electronic device 130, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0203] In an exemplary embodiment, a storage medium is further provided. When the computer program in the storage medium is executed by the processor of the electronic device, the electronic device can execute the method for evaluating the trustworthiness of the RFID reader / writer as described above. Optionally, the storage medium can be a non-transitory computer-readable storage medium. For example, the non-transitory computer-readable storage medium can be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, and an optical data storage device, etc.

[0204] In an exemplary embodiment, the electronic device of the present application can at least include at least one processor and a memory communicatively connected to the at least one processor. Among them, the memory stores a computer program executable by the at least one processor. When the computer program is executed by the at least one processor, the at least one processor can execute the steps of any method for evaluating the trustworthiness of the RFID reader / writer provided in the embodiments of the present application.

[0205] In an exemplary embodiment, a computer program product is further provided. When the computer program product is executed by the electronic device, the electronic device can implement any exemplary method provided by the present application.

[0206] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.

[0207] Obviously, those skilled in the art can make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalent technologies, this application is also intended to include these modifications and variations.

Claims

1. A method for evaluating the trustworthiness of an RFID reader, characterized in that, The method includes: When it is determined that the trustworthiness evaluation conditions are met, determining multi-dimensional information associated with the target RFID reader, where the multi-dimensional information includes the target RFID reader service information, the target RFID reader authentication log information, and the target RFID reader access RFID tag log information; wherein, the target RFID reader service information is used to characterize the service information supported by the target RFID reader, the target RFID reader authentication log information includes the authentication records of the two-way authentication between the target RFID reader and the RFID tag or the RFID application server, and the target RFID reader access RFID tag log information includes the access records of the target RFID reader accessing the RFID tag; Based on the multi-dimensional information, determining the characteristic variables corresponding to the multi-dimensional information; Performing quantization processing based on the association relationship between the characteristic variables and the pre-set association relationship between the characteristic variables and the trustworthiness score, and determining the trustworthiness score; Based on the trustworthiness score and the pre-set evaluation rules, determining the trustworthiness evaluation result of the target RFID reader.

2. The method according to claim 1, wherein The performing quantization processing based on the association relationship between the characteristic variables and the pre-set association relationship between the characteristic variables and the trustworthiness score, and determining the trustworthiness score includes: Inputting the characteristic variables corresponding to the multi-dimensional information into the logit regression model; Based on the probability value calculated by the logit regression model, determining the trustworthiness score of the target RFID reader.

3. The method according to claim 2, wherein Before inputting the characteristic variables corresponding to the multi-dimensional information into the pre-trained logit regression model, it further includes: Performing first preprocessing on the data in the multi-dimensional information to obtain the multi-dimensional information after the first preprocessing, where the first preprocessing includes one or more of data cleaning, data integration, data transformation, and data reduction; Performing second preprocessing on the characteristic variables corresponding to the multi-dimensional information after the first preprocessing, where the second preprocessing includes Z-Score normalization processing or min-max normalization processing.

4. The method according to claim 2, wherein The logit regression model is trained through the following steps: Collecting a plurality of training samples, and inputting the training samples into the logit regression model to be trained for iterative training; wherein, each training sample includes the characteristic variables corresponding to the multi-dimensional information and the sample label; the parameter to be trained in the logit regression model to be trained is the weight vector; Based on the log-likelihood estimation algorithm, constructing a loss function; During the iterative training process, selecting a part of the training samples from the training samples, and based on the selected training samples, using the mini-batch gradient descent algorithm to calculate the gradient of the loss function with respect to the weight vector; Based on the gradient and the preset learning rate, updating the weight vector; Based on the updated weight vector, checking whether the preset convergence condition is met. If it is met, stop training and determine that the logit regression model training is completed; if not, perform the next round of iteration.

5. The method according to claim 1, wherein The evaluation rules are the corresponding relationship between the score range and the trustworthiness level; Determining the trustworthiness evaluation result of the target RFID reader based on the trustworthiness score and a preset evaluation rule includes: Determining the trustworthiness level corresponding to the score range to which the trustworthiness score of the target RFID reader belongs based on the correspondence between the score range and the trustworthiness level; Determining the trustworthiness evaluation result of the target RFID reader based on the trustworthiness level of the target RFID reader.

6. The method according to claim 1, wherein After determining the trustworthiness evaluation result of the target RFID reader, it further includes: Determining the adjustment strategy of the target RFID reader based on the trustworthiness evaluation result of the target RFID reader and the preset correspondence between the evaluation result and the adjustment strategy; Adjusting the target RFID reader based on the adjustment strategy, where the adjustment strategy includes an identity authentication strategy and an access control strategy.

7. The method according to claim 6, wherein Adjusting the target RFID reader based on the adjustment strategy includes: If the adjustment strategy indicates no adjustment, maintaining the identity authentication strategy and the access control strategy currently used by the target RFID reader; If the adjustment strategy indicates enhanced adjustment, enhancing the strategy levels of the identity authentication strategy and the access control strategy currently used by the target RFID reader; Among them, the identity authentication strategy includes some or all of the authentication method, authentication frequency, and encryption level; the access control strategy includes access permissions and / or access duration.

8. An apparatus for evaluating the trustworthiness of an RFID reader, characterized in that, It includes: A first determination module, configured to determine multi-dimensional information associated with the target RFID reader when it is determined that the trustworthiness evaluation condition is met. The multi-dimensional information includes the service information of the target RFID reader, the authentication log information of the target RFID reader, and the access RFID tag log information of the target RFID reader. Among them, the service information of the target RFID reader is used to characterize the service information supported by the target RFID reader, the authentication log information of the target RFID reader includes the authentication records of the two-way authentication between the target RFID reader and the RFID tag or the RFID application server, and the access RFID tag log information of the target RFID reader includes the access records of the target RFID reader accessing the RFID tag; A second determination module, configured to determine the characteristic variables corresponding to the multi-dimensional information based on the multi-dimensional information; A scoring module, configured to perform quantization processing based on the association relationship between the characteristic variables and the preset association relationship between the characteristic variables and the trustworthiness score to determine the trustworthiness score; An evaluation module, configured to determine the trustworthiness evaluation result of the target RFID reader based on the trustworthiness score and a preset evaluation rule.

9. An electronic device, characterized in that, It includes: At least one processor, and a memory communicatively connected to the at least one processor, where: The memory stores a computer program executable by the at least one processor. The computer program is executed by the at least one processor, so that the at least one processor can execute the method according to any one of claims 1-7.

10. A storage medium, characterized in that, When the computer program in the storage medium is executed by a processor of an electronic device, the electronic device can execute the method according to any one of claims 1-7.