Article anti-counterfeiting verification method, device and equipment based on radio frequency identification anti-counterfeiting system

Through the radio frequency identification anti-counterfeiting system's item anti-counterfeiting verification method, using two-way identity authentication, dynamic quantum random numbers and multi-level anti-counterfeiting verification, the reproducibility and security problems of item anti-counterfeiting verification in the existing technology are solved, and the anti-counterfeiting effect of high accuracy and full-cycle traceability is achieved.

CN120671694AActive Publication Date: 2025-09-19SHENZHEN INTERESTED TECHNOLOGY CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202510724808.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-30
Publication Date
2025-09-19
Estimated Expiration
2045-05-30

AI Technical Summary

Technical Problem

Existing anti-counterfeiting verification technology for items has problems such as high reproducibility of static physical features, easy cracking of one-way feature comparison verification, low security of item information, and inability to trace counterfeit items.

Method used

An item anti-counterfeiting verification method based on the radio frequency identification anti-counterfeiting system is adopted, with two-way identity authentication performed through the radio frequency identification tag storage end and the application terminal, generating dynamic quantum random numbers and anti-counterfeiting verification timestamps, and using the tag-end private key for soft and hard signature processing, combined with multiple levels of anti-counterfeiting verification, including certificate issuance verification, data integrity verification, and timeliness verification.

Benefits of technology

It realizes the proactive and real-time anti-counterfeiting verification of items, improves the accuracy and security of verification, and conducts full-cycle evidence storage and traceability through blockchain, enhancing the security and traceability of items.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120671694A_ABST
    Figure CN120671694A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses an article anti-counterfeiting verification method, device and equipment based on a radio frequency identification anti-counterfeiting system. A specific embodiment of the method comprises the following steps: controlling a radio frequency identification tag storage end and an application terminal to carry out bidirectional identity verification to obtain a bidirectional identity verification information set; generating a dynamic quantum random number and an anti-counterfeiting verification timestamp; determining dynamic fingerprint generation mode information; generating label dynamic fingerprint information; performing software-hardware combination signature processing on the label dynamic fingerprint information to obtain signed label dynamic fingerprint information; performing multi-level anti-counterfeiting verification on the received label dynamic fingerprint information, the signed label dynamic fingerprint information and the label end signed certificate information to obtain anti-counterfeiting verification result information; and triggering an alarm to give an alarm and counterfeit tracking processing based on the block chain. According to the implementation mode, active article anti-counterfeiting verification and real-time updating can be achieved, full-period evidence storage tracing is conducted through the block chain, and the accuracy of article anti-counterfeiting verification is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present disclosure relate to the field of computer technology, and more particularly to an article anti-counterfeiting verification method, apparatus, and device based on a radio frequency identification anti-counterfeiting system. Background Art

[0002] Item anti-counterfeiting verification uses radio frequency identification technology to verify the authenticity of item labels to prevent the emergence of counterfeit items and improve the authenticity and safety of items. Radio frequency identification technology is a wireless communication technology that uses radio signals to identify specific tags to verify authenticity. For item anti-counterfeiting verification, the commonly used method is to digitally store the static physical characteristics of the item (for example, anti-counterfeiting code, dot matrix, texture, pattern) in a database. In response to the detection of the item label, the item label and the static physical characteristics in the database are compared and verified to obtain comparative verification information. The comparison result (authenticity result or archived picture or pattern) is then sent to the verification terminal, and the verification terminal analyzes the comparative verification information to determine the authenticity information of the item and stores it in the database.

[0003] However, it has been found in practice that when the above method is used to verify the anti-counterfeiting of items, the following technical problems often occur: due to the reproducibility of the static physical characteristics of the items, it is easy for one static physical feature to match multiple items, and only the static physical feature information of the item label and the database is compared and verified in a single direction, which leads to problems of passivity and illegal acquisition of item information, resulting in low accuracy of the anti-counterfeiting verification of the items and low security of the items; in addition, when counterfeit items are identified, it is impossible to trace the counterfeit items throughout their entire life cycle.

[0004] The above information disclosed in this Background section is only for enhancement of understanding of the background of the present disclosure concept and therefore it may contain information that does not form the prior art that is already known in this country to a person of ordinary skill in the art. Summary of the Invention

[0005] The content of this disclosure is used to briefly introduce concepts that will be described in detail in the detailed description section below. The content of this disclosure is not intended to identify key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.

[0006] Some embodiments of the present disclosure provide methods, devices, and apparatuses for verifying item anti-counterfeiting based on a radio frequency identification anti-counterfeiting system to solve one or more of the technical problems mentioned in the background technology section above.

[0007] In a first aspect, some embodiments of the present disclosure provide an article anti-counterfeiting verification method based on an RFID anti-counterfeiting system, comprising: an RFID tag storage end, an application terminal, and an anti-counterfeiting verification platform end: controlling the RFID tag storage end and the application terminal to perform two-way identity authentication to obtain a two-way identity authentication information set; in response to determining that the two-way identity authentication information sets both represent successful authentication, controlling the application terminal to generate a dynamic quantum random number and an anti-counterfeiting verification timestamp; in response to detecting that the RFID tag storage end receives a challenge request information sent by the application terminal, determining dynamic fingerprint generation method information; in response to determining that the dynamic fingerprint generation method information is signature fingerprint generation method information, generating a dynamic quantum random number and an anti-counterfeiting verification timestamp according to the received dynamic quantum random number and anti-counterfeiting verification timestamp. and the stored tag-end identification information to generate tag dynamic fingerprint information; according to the tag-end private key physically stored at the above-mentioned RFID tag storage end, the above-mentioned tag dynamic fingerprint information is signed by combining software and hardware to obtain the signed tag dynamic fingerprint information; according to the verification platform public key of the above-mentioned anti-counterfeiting verification platform end, the received tag dynamic fingerprint information, the signed tag dynamic fingerprint information and the tag-end issuance certificate information are subjected to multi-level anti-counterfeiting verification to obtain anti-counterfeiting verification result information, wherein the multi-level anti-counterfeiting verification includes: issuance certificate verification, data integrity verification and timeliness verification; in response to determining that the above-mentioned anti-counterfeiting verification result information indicates a verification failure, an alarm is triggered, and the above-mentioned tag-end identification information is subjected to blockchain-based counterfeit tracking processing.

[0008] In a second aspect, some embodiments of the present disclosure provide an article anti-counterfeiting verification device based on a radio frequency identification anti-counterfeiting system, comprising: a two-way identity authentication unit, configured to control the radio frequency identification tag storage end and the application terminal to perform two-way identity authentication to obtain a two-way identity authentication information set; a control unit, configured to control the application terminal to generate a dynamic quantum random number and an anti-counterfeiting verification timestamp in response to determining that the two-way identity authentication information sets both represent successful verification; a first generation unit, configured to determine dynamic fingerprint generation method information in response to detecting that the radio frequency identification tag storage end receives a challenge request information sent by the application terminal; a second generation unit, configured to generate dynamic fingerprint generation method information in response to determining that the dynamic fingerprint generation method information is signature fingerprint generation method information, based on the received dynamic quantum random number, anti-counterfeiting verification timestamp and the stored tag end. Identification information, generates label dynamic fingerprint information; a soft and hard combined signature unit is configured to perform soft and hard combined signature processing on the above-mentioned label dynamic fingerprint information according to the label end private key physically stored at the above-mentioned radio frequency identification label storage end, and obtain the signed label dynamic fingerprint information; a multi-level anti-counterfeiting verification unit is configured to perform multi-level anti-counterfeiting verification on the received label dynamic fingerprint information, the signed label dynamic fingerprint information and the label end issuance certificate information according to the verification platform public key of the above-mentioned anti-counterfeiting verification platform end, and obtain anti-counterfeiting verification result information, wherein the above-mentioned multi-level anti-counterfeiting verification includes: issuance certificate verification, data integrity verification and timeliness verification; an alarm unit is configured to trigger an alarm in response to determining that the above-mentioned anti-counterfeiting verification result information indicates a verification failure, and perform blockchain-based counterfeit tracking processing on the above-mentioned label end identification information.

[0009] In a third aspect, some embodiments of the present disclosure provide an electronic device comprising: one or more processors; a storage device on which one or more programs are stored, and when the one or more programs are executed by one or more processors, the one or more processors implement the method described in any implementation manner in the first aspect.

[0010] In a fourth aspect, some embodiments of the present disclosure provide a computer-readable medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the method described in any implementation manner in the first aspect is implemented.

[0011] The above-described embodiments of the present disclosure have the following beneficial effects: The item anti-counterfeiting verification methods of some embodiments of the present disclosure can proactively perform item anti-counterfeiting verification and real-time updates, as well as perform full-cycle evidence storage and traceability via blockchain, thereby improving the accuracy of item anti-counterfeiting verification. Specifically, the low accuracy of related item anti-counterfeiting verification, low item security, and inability to fully trace counterfeit items are caused by the following reasons: the reproducibility of static physical features of items can easily result in a single static physical feature being matched to multiple items, and the fact that only a single-directional feature comparison and verification of static physical feature information between the item tag and the database results in passivity and illegal acquisition of item information, resulting in low accuracy and low item security. Furthermore, when counterfeit items are identified, full-cycle traceability of the counterfeit items is impossible. Based on this, the item anti-counterfeiting verification methods of some embodiments of the present disclosure can first control the RFID tag storage terminal and the application terminal to perform bidirectional authentication to obtain a bidirectional authentication information set. Bidirectional authentication can prevent third-party attackers from using fake tag information to launch attacks while ensuring communication security, thereby improving anti-attack performance. Secondly, in response to determining that both sets of bidirectional identity authentication information indicate successful authentication, the application terminal is controlled to generate a dynamic quantum random number and an anti-counterfeiting verification timestamp. The dynamic quantum random number is truly random and unpredictable, generating a unique random value for each authentication, ensuring non-repeatability during the authentication process. The anti-counterfeiting verification timestamp is real-time and used for time validity verification during the authentication process to prevent duplicate submissions and replay attacks. Thirdly, in response to detecting that the RFID tag storage terminal receives the challenge request information sent by the application terminal, dynamic fingerprint generation method information is determined. Dynamically determining fingerprint generation using different methods can prevent the leakage of fixed generation methods and improve anti-counterfeiting verification and attack resistance. Next, in response to determining that the dynamic fingerprint generation method information is a signature fingerprint generation method, tag dynamic fingerprint information is generated based on the received dynamic quantum random number, anti-counterfeiting verification timestamp, and stored tag terminal identification information. Due to the real-time and non-forgeable nature of the dynamic quantum random number and anti-counterfeiting verification timestamp, the tag dynamic fingerprint information can effectively verify data integrity and immutability. Subsequently, the tag dynamic fingerprint information is processed by combining software and hardware signature according to the tag end private key physically stored in the RFID tag storage end to obtain the signed tag dynamic fingerprint information.Here, the physically stored tag-side private key is protected by PUF (Physical Unclonable Functions) or SE (Secure Element), which can automatically trigger self-destruction when a physical attack is detected, thereby improving the security and anti-leakage capability of the private key. By combining software and hardware, the signature calculation amount can be reduced to improve signature efficiency and resource consumption. Then, according to the verification platform public key of the above-mentioned anti-counterfeiting verification platform, the received tag dynamic fingerprint information, the signed tag dynamic fingerprint information and the tag-side issuance certificate information are subjected to multi-level anti-counterfeiting verification to obtain anti-counterfeiting verification result information, wherein the multi-level anti-counterfeiting verification includes: issuance certificate verification, data integrity verification and timeliness verification. Here, the issuance certificate verification can prevent the reuse of certificates by embedding the tag-side issuance certificate information and the tag-side identification information, and the multi-level anti-counterfeiting verification can improve the accuracy of anti-counterfeiting verification and determine the security of the tag information stored in the RFID tag memory. Finally, in response to determining that the anti-counterfeiting verification result information indicates a verification failure, an alarm is triggered, and the tag-end identification information is subjected to blockchain-based counterfeit tracking. This improves the accuracy of the anti-counterfeiting alarm, and blockchain-based evidence storage and traceability are performed. Thus, this method for verifying the anti-counterfeiting of items based on an RFID anti-counterfeiting system can proactively verify and update the item's anti-counterfeiting status in real time through two-way identity authentication and dynamic quantum random numbers, as well as perform full-cycle evidence storage and traceability via blockchain, thereby improving the accuracy of item anti-counterfeiting verification. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] The above and other features, advantages, and aspects of the various embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and that components and elements are not necessarily drawn to scale.

[0013] Figure 1 is a timing diagram of communication transmission between an RFID tag storage terminal, an application terminal, and an anti-counterfeiting verification platform terminal included in the RFID anti-counterfeiting system in some embodiments of the article anti-counterfeiting verification method based on the RFID anti-counterfeiting system disclosed herein;

[0014] Figure 2 is a flow chart of some embodiments of an article anti-counterfeiting verification method based on a radio frequency identification anti-counterfeiting system according to the present disclosure;

[0015] Figure 3 is a flow chart of communication between various controllers included in a label signature software end and a label signature hardware end in some embodiments of an article anti-counterfeiting verification method based on an RFID anti-counterfeiting system according to the present disclosure;

[0016] Figure 4 is a flowchart of switching between various states included in a master control state machine in some embodiments of the article anti-counterfeiting verification method based on the radio frequency identification anti-counterfeiting system according to the present disclosure;

[0017] Figure 5 1 is a schematic structural diagram of some embodiments of an article anti-counterfeiting verification device based on a radio frequency identification anti-counterfeiting system according to the present disclosure;

[0018] Figure 6 It is a structural diagram of an electronic device suitable for implementing some embodiments of the present disclosure. DETAILED DESCRIPTION

[0019] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as being limited to the embodiments described herein. On the contrary, these embodiments are provided to provide a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are for illustrative purposes only and are not intended to limit the scope of protection of the present disclosure.

[0020] It should also be noted that, for ease of description, only the parts related to the invention are shown in the drawings. In the absence of conflict, the embodiments and features in the embodiments of the present disclosure may be combined with each other.

[0021] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.

[0022] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, they should be understood as "one or more".

[0023] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only used for illustrative purposes and are not used to limit the scope of these messages or information.

[0024] The present disclosure will be described in detail below with reference to the accompanying drawings and in conjunction with embodiments.

[0025] Figure 1 The figure shows the communication process between the RFID tag storage terminal 101, the application terminal 102, and the anti-counterfeiting verification platform terminal 103, which are included in the RFID anti-counterfeiting system. The RFID tag storage terminal 101 is in communication with the application terminal. The application terminal 102 is in communication with the anti-counterfeiting verification platform terminal 103.

[0026] Figure 2 The flowchart 200 of some embodiments of the method for verifying the anti-counterfeiting of an article based on a radio frequency identification anti-counterfeiting system according to the present disclosure is shown. The method for verifying the anti-counterfeiting of an article based on a radio frequency identification anti-counterfeiting system includes the following steps:

[0027] Step 201: Control the radio frequency identification tag storage terminal and the application terminal to perform two-way identity authentication to obtain a two-way identity authentication information set.

[0028] In some embodiments, the executing entity (e.g., an electronic device) of the anti-counterfeiting verification method for items based on the RFID anti-counterfeiting system can control the RFID tag storage end and the application terminal to perform two-way identity authentication to obtain a two-way identity authentication information set. The two-way identity authentication information in the two-way identity authentication information set can represent the information used by the RFID tag storage end to verify the identity of the application terminal, as well as the information used by the application terminal to verify the identity of the RFID tag storage end. It should be noted that in the two-way identity authentication, the RFID tag storage end and the application terminal each perform identity authentication on the other party, which can ensure that the identity of the other party is legitimate, prevent unauthorized devices from accessing the system, and effectively prevent malicious devices or unauthorized tags from accessing the system, thereby protecting the security of the system.

[0029] In some optional implementations of some embodiments, controlling the radio frequency identification tag storage terminal and the application terminal to perform bidirectional identity authentication to obtain a bidirectional identity authentication information set may include the following steps:

[0030] The first step is to control the RFID tag storage terminal to generate a tag elliptic curve private key and a tag elliptic curve public key. The tag elliptic curve private key can be a randomly generated prime number less than the order of the circular curve group. The tag elliptic curve public key can be a string obtained by adding and multiplying the tag elliptic curve private key and the base point of the elliptic curve.

[0031] The second step is to determine the point product of the above-mentioned tag elliptic curve private key and the application elliptic curve public key sent by the above-mentioned application terminal as the tag shared key.

[0032] The third step is to determine the exclusive OR operation of the tag shared key and the storage end identification information to obtain the first tag verification information. The storage end identification information can be the EPC that represents the unique identifier of the RFID tag storage end.

[0033] In a fourth step, a hash operation is performed on the tag shared key, the storage end identification information, and the applied elliptic curve public key to obtain second tag verification information. The second tag verification information may be verification information obtained by first concatenating the shared key, the storage end identification information, and the applied elliptic curve public key and then inputting the resultant hash function.

[0034] The fifth step is to control the anti-counterfeiting verification platform to determine the point product of the tag elliptic curve public key and the application elliptic curve private key received from the RFID tag storage terminal as the anti-counterfeiting shared key.

[0035] Step 6: Determine the XOR operation of the first label verification information and the anti-counterfeiting shared key to obtain the anti-counterfeiting label verification information.

[0036] The seventh step is to determine whether there is storage end identification information corresponding to the anti-counterfeiting label verification information in the anti-counterfeiting verification platform.

[0037] In the eighth step, in response to determining that there is storage end identification information corresponding to the anti-counterfeiting label verification information, a hash operation is performed on the anti-counterfeiting shared key, the storage end identification information and the applied elliptic curve public key to obtain third label verification information.

[0038] In step 9, in response to determining that the third tag verification information is the same as the second tag verification information received by the application terminal, the information stored by the RFID tag to confirm the identity authentication of the application terminal is determined as the first two-way identity authentication information.

[0039] Optionally, the above method may further include the following steps:

[0040] The first step is to control the application terminal to determine the tag excitation information corresponding to the storage end identification information. The tag excitation information may be information that uses a PUF module to input the storage end identification information into a PUF function for excitation.

[0041] The second step is to determine the exclusive OR operation of the storage end identification information and the tag excitation information to obtain the first application verification information.

[0042] The third step is to determine the exclusive OR operation of the above application shared key and the tag excitation response information corresponding to the above tag excitation information to obtain the second application verification information.

[0043] The fourth step is to control the application terminal to determine an exclusive OR operation between the received first application verification information and the storage terminal identification information to obtain the first application information to be verified.

[0044] In step 5, the first application information to be verified is input into an unclonable function to obtain second application information to be verified. The unclonable function may be a PUF function.

[0045] Step 6: Determine the XOR operation of the received second application verification information and the above-mentioned tag shared key to obtain third application verification information.

[0046] In step 7, in response to determining that the third application verification information is the same as the second application information to be verified, the information of the identity verification confirmed by the application terminal at the RFID tag storage terminal is determined as the second two-way identity verification information.

[0047] In the eighth step, the first two-way identity authentication information and the second two-way identity authentication information are determined as the two-way identity authentication information set.

[0048] Step 202 : In response to determining that both the two-way identity authentication information sets indicate successful authentication, the application terminal is controlled to generate a dynamic quantum random number and an anti-counterfeiting verification timestamp.

[0049] In some embodiments, the execution entity may, in response to determining that both sets of bidirectional identity authentication information indicate successful authentication, control the application terminal to generate a dynamic quantum random number and an anti-counterfeiting verification timestamp. The RFID anti-counterfeiting system may be an active anti-counterfeiting verification system that performs anti-counterfeiting verification on tag information obtained using an RFID method and is suitable for applications such as luxury goods, digital assets, industrial components, medical fields, finance, and physical items. The RFID anti-counterfeiting system may include an RFID tag storage terminal, an application terminal, and an anti-counterfeiting verification platform terminal. The RFID tag storage terminal may be an RFID (Radio Frequency Identification) chip that stores the tag information of an item. The application terminal may be a server terminal that communicates with the RFID tag storage terminal and transmits a random number and a timestamp. For example, the application terminal may be a mobile phone. The anti-counterfeiting verification platform terminal may be a server that verifies the authenticity of the tag information stored in the RFID tag storage terminal, tracks and traces the tag information throughout its lifecycle, and stores the tag storage terminal identification information, tag terminal public key, and tag terminal issuance certificate information of each RFID tag storage terminal in the form of a database. The dynamic quantum random number can be a 128-bit, unpredictable random number generated by quantum superposition and entanglement in quantum mechanics, in compliance with the randomness detection specifications issued by the State Cryptography Administration. The dynamic quantum random number can be generated using a QRNG (Quantum Random Number Generator). The location verification timestamp can record the time when the anti-counterfeiting verification was initiated.

[0050] Step 203 : In response to detecting that the RFID tag storage terminal receives the challenge request information sent by the application terminal, dynamic fingerprint generation method information is determined.

[0051] In some embodiments, the execution entity may determine dynamic fingerprint generation method information in response to detecting that the RFID tag storage terminal receives challenge request information sent by the application terminal. The challenge request information may be request information for a signature request data packet sent by the application terminal to the RFID tag storage terminal. The dynamic fingerprint generation method information may be information on a method for generating tag information stored in the RFID tag storage terminal. The dynamic fingerprint generation method information may include, but is not limited to, at least one of the following: signature anti-counterfeiting method information, identity authentication method information, data encryption method information, blockchain anti-counterfeiting method information, and hardware anti-counterfeiting method information.

[0052] Step 204 : In response to determining that the dynamic fingerprint generation mode information is the signature fingerprint generation mode information, the tag dynamic fingerprint information is generated according to the received dynamic quantum random number, the anti-counterfeiting verification timestamp and the stored tag end identification information.

[0053] In some embodiments, the execution entity may generate tag dynamic fingerprint information in response to determining that the dynamic fingerprint generation method information is signature fingerprint generation method information, based on the received dynamic quantum random number, anti-counterfeiting verification timestamp, and stored tag end identification information. The signature fingerprint generation method information may be generation method information for generating fingerprint information through a signature algorithm. The tag dynamic fingerprint information may be information that characterizes the uniqueness of the tag information, the authenticity, integrity, and non-repudiation of the verification data. The tag end identification information may be identification information that uniquely identifies the storage end of the radio frequency identification tag. The tag end identification information may be an EPC (Electronic Product Code).

[0054] As an example, the execution entity may first concatenate the dynamic quantum random number, the location verification timestamp, and the tag identification information to obtain a concatenated string. The concatenated string is then input into a national secret algorithm to obtain the tag's dynamic fingerprint information. The national secret algorithm may be an SM3 (cryptographic hash function) algorithm.

[0055] Step 205 , performing a software and hardware signature process on the tag dynamic fingerprint information according to the tag end private key physically stored in the RFID tag storage end, and obtaining the signed tag dynamic fingerprint information.

[0056] In some embodiments, the execution subject may perform a combination of software and hardware signature processing on the tag dynamic fingerprint information based on the tag end private key physically stored in the RFID tag storage end to obtain the signed tag dynamic fingerprint information. The tag end private key may be the private key in the key pair generated by the RFID tag storage end through the secp256k1 elliptic curve. The secp256k1 may be a type of elliptic curve. The signed tag dynamic fingerprint information may be the signed fingerprint information generated by the tag end private key and the signature algorithm. The signed tag dynamic fingerprint information may be sent from the RFID tag storage to the application terminal, and the application terminal may send the signed tag dynamic fingerprint information to the anti-counterfeiting verification platform end.

[0057] As an example, the execution entity can input the tag-side private key and the tag dynamic fingerprint information into a hardware-software-integrated SM9 (identification cryptography algorithm) national secret algorithm to obtain the signed tag dynamic fingerprint information. The hardware-software-integrated SM9 national secret algorithm can be based on the SoPC (System on a Programmable Chip) architecture and implemented on an FPGA (Field Programmable Gate Array) to generate and verify the digital signature. The software portion of the hardware-software-integrated SM9 (identification cryptography algorithm) national secret algorithm optimizes the SM9 algorithm by introducing Jacobi coordinates to avoid modular inversion operations and an improved modular exponentiation calculation based on NAF (Non-Adjacent Form) to reduce software calculation time. The hardware can implement a partial prime field multiple point calculation unit, a secondary expansion field multiple point calculation unit, and reuse hardware components that shorten the design cycle by incorporating bilinear pairing calculations. The prime field multiple point calculation unit uses the Montgomery ladder algorithm to improve resistance to side-channel attacks, and performs calculations in parallel using two prime field calculation units to increase calculation speed. The secondary expansion range multiple point calculation unit performs calculations through the secondary expansion range calculation unit.

[0058] In the process of adopting technical solutions to solve the above-mentioned technical problem 1, the following technical problem 2 is often accompanied: Since the stability processing of the response of the physical unclonable function is affected by the resources and computing power of the RFID tag storage end, there is an instability problem, resulting in low security of private key storage. In response to the above-mentioned technical problem 2, the conventional solution is generally: using a fuzzy extractor to obtain the storage of the stable output of the physical unclonable function. However, the above-mentioned conventional solution still has the following problems: Since the RFID tag storage end is a chip with limited resources and easy to carry, and the stable output based on the fuzzy extractor has a large number of uniform speeds, it is not suitable for the storage end with limited computing power, area and power, and ignores the distance between PUF chips, which increases the error correction burden, resulting in low stability of the RFID tag storage end, low storage security and a large amount of waste of storage resources. The inventors took into account the shortcomings of the above-mentioned conventional solutions and combined them with the advantages / technical status of the physical storage technology of the private key owned by the inventor's company, we decided to adopt the following solution:

[0059] In some optional implementations of some embodiments, the physically stored tag-side private key may be stored through the following steps:

[0060] In the first step, the initial power-on state information and storage end identification information of the activated RFID tag memory are input into the physical unclonable functional component to obtain initial response information. The initial power-on state information in the activated state may be a random power-on value of the RFID tag memory at power-on to represent the power-on state. The physical unclonable functional component may be a hardware PUF component. The initial response information may be response information from the hardware PUF component after receiving the initial power-on state information and storage end identification information, including information on transistor threshold voltage variation differences and interconnect delays within the PUF hardware. Because the PUF utilizes the unclonability of the hardware's physical structure, the initial response information is physically unique.

[0061] The second step is to determine a set of memory cell adjacent response stability values ​​for the memory cell set included in the physical unclonable functional component. The memory cells in the memory cell set can be basic units of a memory circuit, memory cells used to store 1 bit of data, and composed of multiple transistors. The memory cell adjacent response stability values ​​in the memory cell adjacent response stability value set can represent the extent to which a memory cell is affected by capacitive crosstalk from adjacent memory cells. The larger the memory cell adjacent response stability value, the greater the impact from the adjacent memory cell. In practice, the execution entity can perform the following determination steps for each memory cell in the memory cell set: First, determine the combined response error probability of a memory cell experiencing a response error and at least two adjacent cells experiencing response errors within a fixed window centered on the memory cell. The fixed window can be a window comprising 5 bits. Then, determine the response error probability of at least two adjacent cells experiencing a response error within the fixed window centered on the memory cell. Finally, determine the ratio of the combined response error probability to the response error probability as the memory cell adjacent response stability value.

[0062] In the third step, the storage unit set is subjected to stability screening based on the adjacent response stability value set of the storage unit to obtain a stable storage unit set. The stable storage units in the stable storage unit set may be storage units whose adjacent response stability values ​​are less than or equal to a preset response stability threshold. The preset response stability threshold may be 0.3.

[0063] As an example, the execution subject may select at least one storage unit adjacent response stability value that is less than or equal to a preset response stability threshold from the storage unit adjacent response stability value set as a stable storage unit set.

[0064] Step 4: Input the random seed corresponding to the initial response into a hash function to generate a hash string. The random seed may be a 64-bit strongly random binary sequence randomly selected from the initial response. The hash function may be a key derivation function.

[0065] The fifth step is to encode the above-mentioned hash string and the preset error correction code to obtain error correction code encoding information. The above-mentioned preset error correction code can be a BCH (Bose Chaudhuri Hocquenghem, error correction code) and a repeated error correction code obtained by repeating a preset number of times for each storage unit in the storage unit set. The above-mentioned BCH can be (127, 85, 13). 127 can represent the total length of the codeword, 85 can represent the information length, and the above-mentioned 13 can represent the error correction capability. The above-mentioned repeated error correction code can be (5, 1, 5). The first 5 represents the output codeword length, 1 represents the input information length, and the second 5 represents the Hamming distance, that is, the full codeword difference, without error correction capability redundant design. The above-mentioned error correction code encoding information can be the encoding information obtained by inputting the above-mentioned hash string and the preset error correction code into the generation Gen function in the reverse fuzzy extractor based on the error correction code offset mechanism.

[0066] The sixth step is to determine an exclusive OR operation between the error correction code information and the initial response information corresponding to the stable storage unit set to obtain response auxiliary information.

[0067] Step 7: Decode the initial response information and the auxiliary response information to obtain a decoded response random number. The decoded response random number can be a random number obtained by inputting the initial response information and the auxiliary response information into a Rep function in a reverse fuzzy extractor based on an error correction code offset mechanism, recovering the random number seed, and then inputting it into a key derivation function.

[0068] The eighth step is to determine the response conditional entropy range of the above-mentioned decoded response random number. In practice, the above-mentioned execution subject can use the conditional entropy function of the above-mentioned random number seed and the response auxiliary information to determine the response conditional entropy range of the above-mentioned decoded response random number. Among them, the above-mentioned conditional entropy function can be:

[0069] H ∞ (S|W)=H ∞ (S)-I(S,W)=H ∞ (S)-k+H ∞ (X)-H ∞ (XH T ).

[0070] Among them, H ∞ (S|W) represents the entropy of the random number seed under the infinite norm when the response auxiliary information is known. ∞ (S) represents the entropy of the random seed under the infinite norm, which can be a function of the length of the random seed in this scenario. I(S, W) represents the mutual information between the random seed and the response auxiliary information, which measures the degree of dependence between the random seed and the response auxiliary information. k represents the length of the random seed. H ∞(X) represents the entropy of the initial response information under the infinite norm, H ∞ (X) = nh(p b )=n×[-lb(max(p b , 1-p b ))], n represents the codeword length of the preset error correction code, h(p b ) indicates p bPUF The response bias is the minimum entropy density function of the probability of 1 appearing in the response value, and lb() represents the logarithmic function of 2 with base 2. ∞ (XH T ) represents the error correction checksum generated by the preset error correction code for the initial response information. Its upper limit is |XH|=nk and its lower limit is L·(n1n2-k2). n1 represents the codeword length of the BCH error correction code, n2 represents the codeword length of the repeated error correction code, k2 represents the information length of the BCH error correction code, and L represents the number of BCH error correction codes. H represents the check matrix of the preset error correction code. H T represents the transpose of the check matrix. X represents the initial response information. S represents the random number seed. W represents the response auxiliary information.

[0071] Because H ∞ (XH T ) has upper and lower limits, so H ∞ (S|W) also has upper and lower limits, that is, the response condition entropy range is L-(n1n2h(p b )-n1n2+k2)≤H ∞ (S|W)≤kn(1-(p b )).

[0072] In step nine, in response to determining that the hash string is identical within the response conditional entropy range, an XOR operation is performed on the tag-side private key and the response auxiliary information output by the PUF component to obtain a response tag private key, which serves as the tag-side private key. The response tag private key is immediately cleared after retrieval and use, completing the physical storage of the tag-side private key. It should be noted that because the PUF responds based on information about transistor threshold voltage variations within the hardware and interconnect delays, the response auxiliary information output by the PUF component is non-replicable and physically unique, thereby improving the security, uniqueness, and non-replicability of the tag-side private key.

[0073] The above-mentioned technical solution and its related contents, as an inventive point of an embodiment of the present disclosure, solve the second technical problem mentioned in the background technology: "Since the storage end of the RFID tag is a chip with limited resources and is easy to carry, and the stable output based on the fuzzy extractor has a large number of uniform speeds, it is not suitable for storage ends with limited computing power, area, and power, and ignores the distance between PUF chips, which increases the error correction burden, resulting in low stability, low storage security, and a large waste of storage resources at the RFID tag storage end." The factors that lead to low stability, low storage security, and a large waste of storage resources at the RFID tag storage end are often as follows: Since the storage end of the RFID tag is a chip with limited resources and is easy to carry, and the stable output based on the fuzzy extractor has a large number of uniform speeds, it is not suitable for storage ends with limited computing power, area, and power, and ignores the distance between PUF chips, which increases the error correction burden. If the above-mentioned factors are solved, the stability and storage security of the RFID tag storage end can be improved, and the waste of storage resources can be reduced. To achieve this effect, the present invention utilizes the characteristic that partially unstable PUF units are adjacent to partially unstable bits, proposes a conditional probability-based set of adjacent storage unit response stability values, and screens these values. This can reduce the capacitive crosstalk generated by coupling capacitance, reduce the influence of adjacent units, reduce the response error rate, and remove unstable bits that are prone to continuous errors. Then, by combining the advantages of a reverse fuzzy extractor and preselected bits, the response failure rate can be reduced with smaller PUF resources, improving the stability and storage security of the RFID tag storage end and reducing the waste of storage resources. Because the PUF responds based on the hardware's internal transistor threshold voltage variation differences and interconnect delays, the above-mentioned response auxiliary information output by the PUF component is non-replicable and physically unique, thereby improving the security, uniqueness, and non-replicability of the tag-end private key.

[0074] While employing technical solutions to address the aforementioned technical problem (1), the following technical problem often arises: Because the digital signature algorithm, which involves the national secret encryption algorithm, performs calculations on elliptic curves over different finite fields to generate and verify the digital signature, it involves a large number of elliptic curve point operations and large integer modular operations, resulting in a large amount of computation and requiring a large amount of computing resources, while the resources of the chip on the RFID tag storage side are limited. Regarding the aforementioned technical problem (2), conventional solutions generally implement the elliptic curve-based digital signature algorithm solely through software or hardware to obtain the tag's dynamic fingerprint information after signing. However, these conventional solutions still have the following problems: Software-only implementations cannot meet high throughput requirements, digital signature accuracy and efficiency are low, signing times are long, and they are often limited to elliptic curves over binary extended fields. Key lengths are short, resulting in low key security. Implementing digital signatures solely through hardware methods also suffers from poor versatility and scalability, and high costs for secondary development and upgrades. Considering the shortcomings of these conventional solutions and considering the advantages and current state of the physical storage technology for private keys owned by the inventor's company, we have decided to adopt the following solution:

[0075] In some optional implementations of some embodiments, performing a software and hardware combined signature process on the tag dynamic fingerprint information based on the tag end private key physically stored in the RFID tag storage end to obtain the signed tag dynamic fingerprint information may include the following steps:

[0076] The first step is to control the tag signing software to determine elliptic curve parameters and the elliptic curve cryptographic algorithm protocol. The tag signing software can be executed by a Cortex-M0 electronic component. The combined hardware and software signature processing includes the tag signing software and the tag signing hardware, which are used together to invoke the elliptic curve cryptographic algorithm protocol. The elliptic curve cryptographic algorithm protocol includes a key pair generation protocol, a digital signature generation protocol, and a digital signature verification protocol. The tag signing hardware is used to perform scalar multiplication operations in the elliptic curve cryptographic algorithm protocol, while the tag signing software is used to perform operations other than scalar multiplication in the elliptic curve cryptographic algorithm protocol. The elliptic curve key generation algorithm protocol can include SM2 and SM9. SM2 and SM9 can be switched freely by the tag signing software or customized by the user. If the user does not specify a switching instruction, the tag signing software will switch based on a customized switching condition. The customized switching condition can be to switch to the SM9 algorithm protocol in response to detecting bilinear pairing operations or anonymous authentication in the elliptic curve key generation algorithm protocol; otherwise, the SM2 algorithm protocol can be used.

[0077] The second step is to control the tag signature software end in response to determining that the tag signature software end executes the key generation algorithm based on the elliptic curve, call the software and hardware end calling interface to send the scalar multiplication operation request in the key generation algorithm based on the elliptic curve to the tag signature hardware end. The software and hardware end calling interface is connected to the master interface and the AHB (Advanced High Performance Bus) bus for communication. The master interface consists of four parts: the instruction area, the status area, the data area and the master state machine. The master interface is as follows Figure 3 The command area can be used to receive control commands sent by the tag signature software. The status area can be used to store status information of the tag signature hardware, which can be directly accessed by the tag signature software. The data area can be used for data exchange between the tag signature software and the tag signature hardware.

[0078] The above-mentioned master state machine can be composed of 8 states, which are responsible for controlling various operations of the tag signature hardware end. The state transition is controlled by instructions and feedback circuits. The above-mentioned 8 states may include: IDLE (idle state), INPUT_G (arbitrary point scalar multiplication parameter input state), INPUT_Q (fixed point or arbitrary point scalar multiplication parameter q input state), INPUT_U (unit function module parameter input state), PCAL (pre-calculation state), CAL (scalar multiplication calculation state), UCAL (unit function module calculation state), OUTPUT (output state). The switching between the 8 states can be controlled by Figure 4 shown. Figure 4The idle_tou, u_ready, ucal_done, cal_done, q_ready, pcal_done, g_ready, idle_tok, idle_tog, and output_done signals can all represent state transitions. When idle_tou = true, it indicates that one of the following operations, modular addition, modular subtraction, modular multiplication, and modular inverse, will be called in the domain operation layer of the tag signature hardware. When u_ready = true, it indicates that the input of each module in the tag signature hardware is complete. When ucal_done = true, it indicates that the calculation of each module in the tag signature hardware is complete and the control master state machine calculation is complete. When cal_done = true, it indicates that the scalar multiplication calculation of the multiplication point operation layer module is complete and the control master state machine scalar multiplication operation is complete. When q_ready = true, it indicates that the q value input of the scalar multiplication of the multiplication point operation layer module is complete. When pcal_done = true, the precalculation process for arbitrary-point scalar multiplication in the multiple-point operation layer module has been completed, indicating that the control master state machine has completed precalculation and can begin formal scalar multiplication calculations. When g_ready = true, the scalar parameter input for arbitrary-point scalar multiplication in the multiple-point operation layer module has been completed. When idle_tok = true, the function for fixed-point scalar multiplication in the multiple-point operation layer module will be called. When idle_tog = true, the function for arbitrary-point scalar multiplication in the multiple-point operation layer module will be called. When output_done = true, the output result of the tag signature hardware has been completed and the initial state has been restored. A null instruction with no operation.

[0079] The communication process between the tag signature hardware end and the tag signature software end is as follows: when the tag signature hardware end needs to be called, the tag signature software end will combine the information in the status area and input the corresponding control instructions into the instruction area; the tag signature software end will interact with the data area to complete the call and request information sending operations; after the tag signature hardware end completes the operation, it will notify the main control state machine through the feedback circuit that the operation is completed.

[0080] The third step is to control the tag signature software end to receive the elliptic curve key pair and elliptic curve parameter set generated by the tag signature hardware end through the software and hardware end calling interface.

[0081] In the fourth step, the tag signing software is controlled to perform string concatenation on the tag identification information, the bit length of the tag identification information, the elliptic curve coordinate pair of the tag public key corresponding to the tag private key, and the elliptic curve parameter set to obtain a concatenated string. The tag private key may also be obtained by calculation using a combination of software and hardware, including the tag signing software and the tag signing hardware.

[0082] Step 5: Perform a hash operation on the concatenated string to obtain an initial tag-side hash value. The initial tag-side hash value may represent summary information of the identity information stored on the RFID tag. The hash operation may be an SM3 hash operation.

[0083] In the sixth step, the initial tag-side hash value and the tag dynamic fingerprint information are concatenated and hashed to obtain a tag-side fingerprint summary. The tag-side fingerprint summary can be a string that introduces a nonlinear transformation into the initial tag-side hash value to reduce the risk of information tampering and leakage.

[0084] The seventh step is to randomly generate a random number combining the soft and hard ends, wherein the value range of the random number combining the soft and hard ends is [1, the order of the elliptic curve base point - 1].

[0085] The fifth step is to call the software and hardware calling interface to issue the scalar multiplication operation request information based on the above-mentioned digital signature generation protocol and the above-mentioned digital signature verification protocol and the random number of the software and hardware combined, and control the above-mentioned label signature hardware end to execute the scalar multiplication operation request information based on the above-mentioned digital signature generation protocol and the above-mentioned digital signature verification protocol to obtain the hardware scalar multiplication operation result, wherein the label processing hardware corresponding to the above-mentioned label processing hardware interface includes: domain operation controller, point operation controller, multiple point operation controller, coordinate conversion controller. The above-mentioned software and hardware combined label signature software end and label signature hardware end, as well as the various controllers included are composed of Figure 3 As shown in the left figure, the communication call relationship between the tag signature software end, the tag signature hardware end and the various parts included is displayed.

[0086] The domain operation controller can be a controller that uses an FPGA hardware-side scalar multiplication circuit module to support modular multiplication, modular addition, modular subtraction, and modular inverse operations. The modular multiplication operation can include: designing a low-power multiplier using the divide-and-conquer approach of the KOM (Karatsuba-Ofman) algorithm, reducing resource and energy consumption by combining serial and parallel computations. The KOM algorithm can convert an m-bit multiplication into two m / 2-bit and one m / 2+1-bit multiplications, as well as an addition operation. For special prime numbers in the SM2 and SM9 recommended parameters, namely extended Mersenne primes, a fast modular reduction algorithm is used to convert division into addition and subtraction operations, reducing computational complexity. Repeatedly calculated intermediate values ​​are pre-calculated and reused multiple times to reduce the number of repeated calculations. For modular operations on non-Mersenne prime numbers in the SM2 and SM9 protocol layers, a Barrett algorithm is implemented using a combination of software and hardware to reduce register consumption. The modular inverse operation can be a computational module that utilizes the binary extended Euclidean algorithm and the Euclidean algorithm, converting all divisions into addition and subtraction operations, and performing division by 2 operations with binary shifts, thereby reducing energy consumption. The modular addition and subtraction operations are combined into a modular addition and subtraction operation, selecting different initial values ​​for calculation based on different modular addition and subtraction modes. The result of addition may exceed the modulus P of the elliptic curve equation, so P must be subtracted from the result. The result of subtraction may be negative, so P must be added at the end. The final output result is determined by the overflow flags of both times.

[0087] The multiplication point arithmetic controller can be a controller using an FPGA hardware-side scalar multiplication circuit module to invoke arbitrary and fixed-point scalar multiplication operations. The multiplication point arithmetic controller can include a fixed-window NAF scalar representation and a fixed-window NAF scalar multiplication algorithm. The fixed-window NAF scalar representation can utilize the order of the elliptic curve base point parameter in an elliptic curve to convert even-numbered scalars q to odd-numbered numbers. If the scalar q is odd, the order of the elliptic curve base point is doubled to maintain conversion consistency. The converted scalar q is then converted to NAF form, where each bit (or window) is an arbitrary value within the odd range. The fixed-window NAF scalar multiplication algorithm can first precompute a number of points (e.g., P, 2P, 3P, ..., (2^fixed window length - 1)P), which are reused in subsequent operations. The algorithm then iterates over each bit in the NAF representation and performs a corresponding multiplication or point addition operation based on the value of the current bit. Due to the smaller number of non-zero bits in the NAF representation, the number of point addition operations is reduced.

[0088] The coordinate conversion controller may be a controller that utilizes Jacobian weighted projective coordinates or a standard projective coordinate system, and can eliminate modular inverse operations during the scalar multiplication iteration process, thereby improving computational efficiency.

[0089] The point operation controller can be a controller that uses an FPGA hardware-side scalar multiplication circuit module to call point addition and point multiplication operations to implement scalar multiplication. The point operation controller can implement conditional and unconditional point addition in the Jacobian weighted projection coordinate system, reducing the computational complexity of modular multiplication. This optimizes the fixed-window NAF scalar multiplication algorithm, significantly reducing the number of point additions compared to the Montgomery scalar multiplication algorithm. The conditional and unconditional point additions can, respectively, be conditional point additions with a coordinate component z_1 = 1 and unconditional point additions without the requirement for z_1 in the Jacobian weighted projection coordinate system. When calculating fixed-point scalar multiplications, i.e., scalar multiplications with the recommended parameter G for SM2 and SM_9, the calculation process is optimized by storing scalar points within the window with z_1 = 1 and using conditional point additions, thereby reducing the computational complexity of modular multiplications. When calculating the scalar multiplication of any point, the value of the scalar point within the window must be precalculated.

[0090] The sixth step is to control the above-mentioned tag signature software end to receive the hardware scalar multiplication operation result of the above-mentioned tag signature hardware end, and continue to execute the above-mentioned elliptic curve cryptography algorithm protocol. If there is still scalar multiplication operation to be executed in the above-mentioned elliptic curve cryptography algorithm protocol, call the software and hardware end calling interface to issue a scalar multiplication operation request.

[0091] In the seventh step, in response to determining that the operations of the tag signature hardware end and the tag signature software end are completed, the output result of the tag signature software is determined as the signed tag dynamic fingerprint information.

[0092] The above technical solution and its related contents, as an inventive point of the embodiments of the present disclosure, solve the second technical problem mentioned in the background technology: "If implemented only by software methods, there is an inability to meet high throughput requirements, the accuracy and efficiency of digital signatures are low, the signing time is long, and they are mostly limited to elliptic curves on binary extension fields, the key length is short, and the key security is low. If digital signatures are implemented only by hardware methods, they have poor versatility and scalability, and the cost of secondary development and upgrade is low." The factors that lead to low digital signature accuracy and efficiency, long signing time, poor versatility and scalability, and high cost of secondary development and upgrade are often as follows: If implemented only by software methods, there is an inability to meet high throughput requirements, the accuracy and efficiency of digital signatures are low, the signing time is long, and they are mostly limited to elliptic curves on binary extension fields, the key length is short, and the key security is low. If digital signatures are implemented only by hardware methods, they have poor versatility and scalability, and the cost of secondary development and upgrade is high. If the above factors are solved, the accuracy and efficiency of digital signatures can be improved, the signing time can be shortened, the versatility and scalability can be improved, and the cost of secondary development and upgrade can be reduced. To achieve this effect, the present disclosure first determines the elliptic curve parameters and elliptic curve cryptographic algorithm protocol, and performs two string concatenation and hash operations on each received string. The first string concatenation and hash operation embeds the identity of the RFID tag memory, which can prevent identity fraud and signature forgery. The second string concatenation and hash operation introduces the superposition effect of nonlinear transformations, increasing the difficulty for attackers to construct and reducing the risk of tampering with the tag's dynamic fingerprint information. Then, the software and hardware call interface is called to interactively call the tag signature software and the tag signature hardware, and to issue scalar multiplication operation requests. Since the tag signature software can adapt to protocol changes, the tag signature hardware does not need to be reconfigured. It has high computing performance, versatility, and strong scalability, and can be used in encryption servers and other occasions. Afterwards, since the tag hardware side implements the implementation of each controller, including the relationship between the number of bits of the minimum multiplier in the parallel calculation of the KOM algorithm and its energy consumption and resource consumption, the serial calculation of the low-power 64-bit multiplier is realized to realize the low-power 256-bit multiplier; by extending the modular reduction algorithm of Mersenne primes, the division is converted into addition and subtraction operations, thereby greatly reducing the complexity and energy consumption of modular reduction. The modular reduction algorithm of non-extended Mersenne primes based on the Barrett algorithm uses multiplication and modular reduction operations instead of high-cost division operations to implement modular operations, thereby efficiently calculating the modular multiplication of any parameter to reduce register consumption; modular addition and subtraction operations are merged to achieve the goal of reducing power consumption and resource consumption; the fixed window NAF scalar multiplication algorithm now provides a solution for efficient calculation of scalar multiplication for low-power environments that need to resist SPA attacks, and optimizes the last point addition calculation, thereby further reducing resource consumption and energy consumption.Finally, in response to determining that the tag signature hardware and tag signature software operations are completed, the dynamic fingerprint information of the signed tag is obtained. Through multiple interactions of the tag signature hardware and tag signature software operations, the respective advantages of software and hardware can be fully utilized, performance can be improved, energy consumption of hardware resources can be reduced, the accuracy and efficiency of digital signatures can be improved, the signing time can be shortened, the versatility and scalability can be improved, and the cost of secondary development and upgrading can be reduced.

[0093] Step 206 , based on the verification platform public key of the anti-counterfeiting verification platform, perform multi-level anti-counterfeiting verification on the received tag dynamic fingerprint information, the signed tag dynamic fingerprint information and the tag end issuance certificate information to obtain anti-counterfeiting verification result information.

[0094] In some embodiments, the execution entity may perform multi-level anti-counterfeiting verification on the received tag dynamic fingerprint information, the signed tag dynamic fingerprint information, and the tag-side issuance certificate information based on the verification platform public key of the anti-counterfeiting verification platform, obtaining anti-counterfeiting verification result information. The multi-level anti-counterfeiting verification includes: issuance certificate verification, data integrity verification, and timeliness verification. The tag-side issuance certificate information may be identity verification information issued by the anti-counterfeiting verification platform to verify the identity of the RFID tag storage terminal and ensure its legitimacy and credibility. The tag-side issuance certificate information may be obtained by the following steps: first, concatenating the string corresponding to the tag-side public key of the RFID tag storage terminal and the tag-side identification information to obtain a concatenated tag-side string. Then, the concatenated tag-side string and the verification platform private key of the anti-counterfeiting verification platform are input into the digital signature function of the SM2 algorithm to obtain the tag-side issuance certificate information. By binding the tag-side identification information and the tag-side public key, the tag-side issuance certificate information can prevent the reuse of issuance certificates and enhance anti-counterfeiting capabilities. The anti-counterfeiting verification result information may indicate whether the anti-counterfeiting verification platform has passed the multi-level verification of the tag dynamic fingerprint information stored in the RFID tag storage. The tag dynamic fingerprint information, the signed tag dynamic fingerprint information, and the tag issuance certificate information may be data sent from the application terminal to the anti-counterfeiting verification platform. The anti-counterfeiting verification result information may be information sent from the anti-counterfeiting verification platform to the application terminal.

[0095] In some optional implementations of some embodiments, the above-mentioned multi-level anti-counterfeiting verification is performed on the received tag dynamic fingerprint information, the signed tag dynamic fingerprint information, and the tag end issuance certificate information based on the verification platform public key of the above-mentioned anti-counterfeiting verification platform end to obtain the anti-counterfeiting verification result information, which may include the following steps:

[0096] The first step is to control the anti-counterfeiting verification platform to perform digital certificate verification on the certificate information issued by the tag according to the public key of the verification platform to obtain certificate verification result information. The certificate verification result information can indicate whether the issued certificate is forged.

[0097] As an example, the execution entity may input the tag-side certificate information and the verification platform public key into the signature verification function SM2_Verify() in the SM2 algorithm to obtain certificate verification result information.

[0098] In the second step, the tag dynamic fingerprint information is input into a tag fingerprint hash value generation function to obtain a dynamic fingerprint hash value. The dynamic fingerprint hash value can represent the digital fingerprint of the tag dynamic fingerprint information, that is, it maps the tag dynamic fingerprint information to a fixed-length string. The tag fingerprint hash value generation function can be a function for mapping the tag dynamic fingerprint information to a fixed-length string of random letters and numbers. For example, the tag fingerprint hash value generation function can be an SM3 algorithm.

[0099] The third step is to perform hash value verification on the dynamic fingerprint hash value based on the tag end public key and the signed tag dynamic fingerprint information to obtain hash value verification result information. The hash value verification result can indicate whether the received tag dynamic fingerprint information is complete, that is, the integrity verification information of the tag dynamic fingerprint information.

[0100] As an example, the above-mentioned execution entity can input the received tag dynamic fingerprint information, tag end public key and signed tag dynamic fingerprint information into the signature verification function SM2_Verify() in the SM2 algorithm to obtain hash value verification result information.

[0101] The fourth step is to determine whether the verification timestamp in the tag dynamic fingerprint information is within a preset timestamp window, thereby obtaining timestamp verification result information. The timestamp verification result information may indicate whether the verification timestamp is within the preset timestamp window. The preset timestamp window may be a pre-set verification time range. For example, the preset timestamp window may be within five minutes before and after the current time.

[0102] Step 5: Determine the certificate verification result information, the hash value verification result information, and the timestamp verification result information as anti-counterfeiting verification result information, and in response to determining that the certificate verification result information, the hash value verification result information, and the timestamp verification result information all indicate successful verification, determine a random hash value of the random number in the tag dynamic fingerprint information, and send the random hash value and the verification information indicating successful verification to the application terminal. The random hash value may be a hash value obtained by inputting the random number in the signature dynamic fingerprint information into a SHA256 (Secure Hash Algorithm 256-bit) hash function.

[0103] Step 207 , in response to determining that the anti-counterfeiting verification result information indicates a verification failure, triggering an alarm, and performing blockchain-based counterfeit tracking processing on the tag-end identification information.

[0104] In some embodiments, the execution entity may, in response to determining that the anti-counterfeiting verification result information indicates a verification failure, trigger an alarm and perform blockchain-based counterfeit tracking on the tag-end identification information. The alarm may be an alarm that displays different colors and sounds on the display screen of the application terminal. The counterfeit tracking process may utilize blockchain technology to record and track the entire process of an item, from production to distribution.

[0105] In some optional implementations of some embodiments, before responding to determining that the anti-counterfeiting verification result information indicates a verification failure, triggering an alarm, and performing blockchain-based counterfeit tracking processing on the tag-end identification information, the method may further include the following steps:

[0106] The first step is to control the radio frequency identification tag storage end in response to determining that the above-mentioned dynamic fingerprint generation method information is the encryption and decryption fingerprint generation method information, and determine the label hash value of the above-mentioned tag end identification information and the verification platform public key of the above-mentioned anti-counterfeiting verification platform end. Among them, the above-mentioned encryption and decryption fingerprint generation method information can be the information of fingerprint generation achieved by the encryption and decryption algorithm. The above-mentioned label hash value can be a string obtained by mapping the above-mentioned tag end identification information and the above-mentioned anti-counterfeiting verification platform end to a fixed-length string. In practice, the above-mentioned execution entity can first concatenate the string corresponding to the above-mentioned tag end identification information and the verification platform public key to obtain the concatenated label anti-counterfeiting string. Then, the above-mentioned spliced ​​label anti-counterfeiting string is input into the SM3 algorithm to obtain the label hash value.

[0107] The second step is to generate a temporary tag key pair for the RFID tag storage end, wherein the temporary tag key pair includes: a temporary tag private key and a temporary tag public key. The temporary tag key pair can be a temporary elliptic curve key pair generated for a single encryption to characterize the randomness and uniqueness of the single encryption. In practice, the execution entity can first randomly generate a temporary random number as the temporary tag private key, wherein the temporary random number can be a prime number less than the order of the elliptic curve group. Then, the temporary tag private key and the base point of the elliptic curve are added and multiplied to obtain the temporary tag public key.

[0108] The third step is to generate an elliptic derivative key based on the tag dynamic fingerprint information, the tag hash value and the temporary tag key pair. The elliptic derivative key can be a session key or a re-encrypted key that generates the tag hash value and the temporary tag key pair.

[0109] As an example, the execution entity may first determine the binary representation of the bit length of the dynamic fingerprint information of the tag as a fingerprint bit binary string. Then, the horizontal coordinate and vertical coordinate of the temporary tag public key in the temporary tag key pair and the tag hash value are string-concatenated to obtain a concatenated tag string. Finally, the concatenated tag string and the fingerprint bit binary string are input into a key derivation function to obtain an elliptic derived key. The key derivation function may be, but is not limited to, one of the following: PBKDF2 (Password-Based KeyDerivation Function2), Scrypt key derivation function, and Argon2 key derivation function.

[0110] Step 4: Coordinate encoding is performed on the coordinates of the temporary tag public key to obtain a public key encoding byte stream. The public key encoding byte stream may be a string of the temporary tag public key converted into a standardized byte stream. The coordinate encoding may be a byte stream encoding of the concatenated ordinate and abscissa of the temporary tag public key.

[0111] In the fifth step, the tag dynamic fingerprint information is encrypted according to the elliptical derived key to obtain the encrypted tag dynamic fingerprint information.

[0112] As an example, the execution entity may perform a bitwise exclusive OR operation on the tag dynamic fingerprint information and the elliptic derived key to obtain the encrypted tag dynamic fingerprint information.

[0113] The sixth step is to verify the data integrity of the dynamic fingerprint information of the tag according to the coordinates of the temporary tag public key to obtain a tag verification byte stream. The tag verification byte stream can indicate whether the dynamic fingerprint information of the tag is complete and whether it has been tampered with.

[0114] As an example, the execution entity may first concatenate the horizontal and vertical coordinates of the temporary tag public key and the string corresponding to the tag dynamic fingerprint information to obtain a concatenated key string. The concatenated key string is then input into the SM3 algorithm to obtain a tag verification byte stream.

[0115] In the seventh step, the public key encoding byte stream, the tag verification byte stream and the encrypted tag dynamic fingerprint information are byte stream spliced ​​to obtain a spliced ​​encoding byte stream.

[0116] In the eighth step, the tag dynamic fingerprint information and the concatenated encoded byte stream are sent to the application terminal.

[0117] Optionally, after sending the tag dynamic fingerprint information and the concatenated encoded byte stream to the application terminal, the method may further include the following steps:

[0118] The first step is to control the application terminal to send the tag dynamic fingerprint information and the spliced ​​encoded byte stream to the anti-counterfeiting verification platform;

[0119] The second step is to control the anti-counterfeiting verification platform to decode the received concatenated encoded byte stream to obtain a first decoded string, a second decoded string, and a third decoded string. The first decoded string may be the byte stream obtained by decoding the public key encoded byte stream. The second decoded string may be the byte stream obtained by decoding the tag verification byte stream. The third decoded byte stream may be the string obtained by decoding the byte stream corresponding to the encrypted tag dynamic fingerprint information. In practice, the execution entity may first extract the byte stream from the concatenated encoded byte stream according to the coordinate encoding format of the temporary tag public key, and then decode it to obtain the first decoded string. Then, since the tag verification byte stream is of fixed length, the byte stream corresponding to the length of the tag verification byte stream is extracted from the concatenated encoded byte stream after removing the byte stream corresponding to the first decoded string, and then decode it to obtain the second decoded string. Finally, the concatenated encoded byte stream after removing the byte streams corresponding to the first and second decoded strings is decoded to obtain the third decoded string.

[0120] The third step is to determine the product of the verification platform private key of the anti-counterfeiting verification platform and the first decoded string as the verification terminal coordinates. The verification platform private key is stored in a platform encryption hardware component. The platform encryption hardware component may be an HSM (Hardware Security Module). Storing the verification platform private key in the platform encryption hardware component prevents clear text export, improves the security of the verification platform private key, and prevents attackers from intercepting it.

[0121] The fourth step is to generate a verification terminal derived key based on the verification terminal coordinates and the tag hash value. The verification terminal derived key can be a session key or a re-encrypted key that generates the verification terminal coordinates and the tag hash value.

[0122] As an example, the execution entity may first concatenate the horizontal and vertical coordinates corresponding to the verification end coordinates and the tag hash value to obtain a concatenated coordinate string. The concatenated coordinate string and the fingerprint bit binary string corresponding to the received second decoded string are then input into a key derivation function to obtain a verification end derived key.

[0123] The fifth step is to determine the XOR operation of the verification end derived key and the second decoded character string to obtain the verification end decrypted information.

[0124] In step 6, the decrypted information from the verification end and the verification end coordinates are concatenated and input into a data integrity verification function to generate a verification end verification string. The verification end verification string can verify whether the received verification end decoded information and the sent tag dynamic fingerprint information are identical. The data integrity verification function can be used to verify the integrity of the received tag dynamic fingerprint information and whether it has been tampered with. For example, the data integrity verification function can be the SM3 algorithm.

[0125] In step 7, in response to determining that the verification end verification string is the same as the third decoded string, data is extracted from the verification end decrypted information to obtain decrypted tag identification information, decrypted timestamp, and decrypted random number.

[0126] In step 8, multi-level verification is performed on the decrypted tag identification information, the decrypted timestamp, and the decrypted random number to obtain a multi-level verification result information set. The multi-level verification result information set may include verification information indicating whether the decrypted tag identification information is identical to the tag identification information stored in the RFID tag storage terminal, whether the decrypted timestamp is within a preset timestamp window, and whether the decrypted random number is reused.

[0127] In the ninth step, in response to determining that the verification result information of each level in the multi-level verification result information set indicates successful verification, the verification success information and the decrypted tag identification information are sent to the application terminal.

[0128] Further references Figure 5 As an implementation of the methods shown in the above figures, the present disclosure provides some embodiments of an article anti-counterfeiting verification device based on a radio frequency identification anti-counterfeiting system. These device embodiments are similar to Figure 2 Corresponding to the method embodiments shown, the article anti-counterfeiting verification device based on the radio frequency identification anti-counterfeiting system can be specifically applied to various electronic devices.

[0129] like Figure 5 As shown, an article anti-counterfeiting verification device 500 based on an RFID anti-counterfeiting system includes: a bidirectional identity authentication unit 501, a control unit 502, a first generation unit 503, a second generation unit 504, a combined hardware and software signature unit 505, a multi-level anti-counterfeiting verification unit 506, and an alarm unit 507. The bidirectional identity authentication unit 501 is configured to control the RFID tag storage terminal and the application terminal to perform bidirectional identity authentication to obtain a bidirectional identity authentication information set. The control unit 502 is configured to, in response to determining that both bidirectional identity authentication information sets indicate successful authentication, control the application terminal to generate a dynamic quantum random number and an anti-counterfeiting verification timestamp. The first generation unit 503 is configured to, in response to detecting that the RFID tag storage terminal receives a challenge request message sent by the application terminal, determine dynamic fingerprint generation method information. The second generation unit 504 is configured to, in response to determining that the dynamic fingerprint generation method information is signature fingerprint generation method information, generate tag dynamic fingerprint information based on the received dynamic quantum random number, anti-counterfeiting verification timestamp, and stored tag terminal identification information. The hardware-software signature unit 505 is configured to: perform hardware-software signature processing on the above-mentioned tag dynamic fingerprint information according to the tag end private key physically stored at the above-mentioned RFID tag storage end, and obtain the signed tag dynamic fingerprint information. The multi-level anti-counterfeiting verification unit 506 is configured to: perform multi-level anti-counterfeiting verification on the received tag dynamic fingerprint information, the signed tag dynamic fingerprint information and the tag end issuance certificate information according to the verification platform public key of the above-mentioned anti-counterfeiting verification platform end, and obtain anti-counterfeiting verification result information, wherein the multi-level anti-counterfeiting verification includes: issuance certificate verification, data integrity verification and timeliness verification. The alarm unit 507 is configured to: trigger an alarm in response to determining that the above-mentioned anti-counterfeiting verification result information indicates a verification failure, and perform blockchain-based counterfeit tracking processing on the above-mentioned tag end identification information.

[0130] It is understandable that the units described in the article anti-counterfeiting verification device 500 based on the radio frequency identification anti-counterfeiting system are similar to those in the reference Figure 1 Therefore, the operations, features and beneficial effects described above for the method are also applicable to the article anti-counterfeiting verification device 500 based on the radio frequency identification anti-counterfeiting system and the units included therein, and will not be repeated here.

[0131] Reference below Figure 6 , which shows a structural schematic diagram of an electronic device (eg, an electronic device) 600 suitable for implementing some embodiments of the present disclosure. Figure 6 The electronic device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.

[0132] like Figure 6 As shown, the electronic device 600 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 601, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 602 or a program loaded from a storage device 608 into a random access memory (RAM) 603. Various programs and data required for the operation of the electronic device 600 are also stored in the RAM 603. The processing device 601, the ROM 602, and the RAM 603 are connected to each other via a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.

[0133] Typically, the following devices may be connected to the I / O interface 605: an input device 606 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 607 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 608 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 609. The communication device 609 may allow the electronic device 600 to communicate with other devices wirelessly or by wire to exchange data. Although Figure 5 The electronic device 600 is shown with various devices, but it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed instead. Figure 6 Each block shown in the figure may represent one device, or may represent multiple devices as needed.

[0134] In particular, according to some embodiments of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, some embodiments of the present disclosure include a computer program product comprising a computer program carried on a computer-readable medium, the computer program comprising program code for executing the method shown in the flowchart. In some such embodiments, the computer program can be downloaded and installed from a network via the communication device 609, or installed from the storage device 608, or installed from the ROM 602. When the computer program is executed by the processing device 601, the above-mentioned functions defined in the method of some embodiments of the present disclosure are performed.

[0135] It should be noted that in some embodiments of the present disclosure, the computer-readable medium mentioned above may be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In some embodiments of the present disclosure, the computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device, or device. In some embodiments of the present disclosure, the computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium that can transmit, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any suitable medium, including but not limited to wires, optical cables, RF (radio frequency), etc., or any suitable combination thereof.

[0136] In some embodiments, the client and server can communicate using any currently known or future developed network protocol, such as HTTP (Hypertext Transfer Protocol), and can be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or future developed network.

[0137] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device. The computer-readable medium carries one or more programs. When the one or more programs are executed by the electronic device, the electronic device performs steps 201 to 207.

[0138] Computer program code for performing the operations of some embodiments of the present disclosure may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, C++, and conventional procedural programming languages ​​such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).

[0139] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the module, program segment, or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of the boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0140] The units described in some embodiments of the present disclosure may be implemented in software or in hardware. The units described may also be provided in a processor. For example, they may be described as follows: a processor including a control unit, a two-way authentication unit, a first generation unit, a second generation unit, a hardware-software signature unit, a multi-level anti-counterfeiting verification unit, and an alarm unit. The names of these units do not, in some cases, constitute limitations on the units themselves. For example, two-way authentication may also be described as "a unit that controls the above-mentioned radio frequency identification tag storage terminal and the above-mentioned application terminal to perform two-way authentication and obtain a two-way authentication information set."

[0141] The functions described above herein may be performed, at least in part, by one or more hardware logic components. For example, and without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chip (SOCs), complex programmable logic devices (CPLDs), and the like.

[0142] The above description is only an illustration of some preferred embodiments of the present disclosure and the technical principles used. Those skilled in the art should understand that the scope of the invention involved in the embodiments of the present disclosure is not limited to the technical solutions formed by the specific combination of the above-mentioned technical features, but should also cover other technical solutions formed by any combination of the above-mentioned technical features or their equivalent features without departing from the above-mentioned inventive concept. For example, the above-mentioned features are replaced with (but not limited to) technical features with similar functions disclosed in the embodiments of the present disclosure.

Claims

1. A method for verifying the anti-counterfeiting of articles based on a radio frequency identification anti-counterfeiting system, comprising: an radio frequency identification tag storage terminal, an application terminal, and an anti-counterfeiting verification platform terminal; Controlling the radio frequency identification tag storage end and the application terminal to perform two-way identity authentication to obtain a two-way identity authentication information set; In response to determining that both the two-way identity authentication information sets indicate successful authentication, controlling the application terminal to generate a dynamic quantum random number and an anti-counterfeiting verification timestamp; In response to detecting that the RFID tag storage terminal receives the challenge request information sent by the application terminal, determining dynamic fingerprint generation method information; In response to determining that the dynamic fingerprint generation mode information is signature fingerprint generation mode information, generating tag dynamic fingerprint information according to the received dynamic quantum random number, the anti-counterfeiting verification timestamp and the stored tag end identification information; Performing a software and hardware signature process on the tag dynamic fingerprint information according to the tag end private key physically stored in the RFID tag storage end to obtain the signed tag dynamic fingerprint information; Performing multi-level anti-counterfeiting verification on the received tag dynamic fingerprint information, the signed tag dynamic fingerprint information, and the tag issuance certificate information according to the verification platform public key of the anti-counterfeiting verification platform to obtain anti-counterfeiting verification result information, wherein the multi-level anti-counterfeiting verification includes: issuance certificate verification, data integrity verification, and timeliness verification; In response to determining that the anti-counterfeiting verification result information indicates a verification failure, an alarm is triggered, and a blockchain-based counterfeit tracking process is performed on the tag-end identification information.

2. The method according to claim 1, wherein Before triggering an alarm in response to determining that the anti-counterfeiting verification result information indicates a verification failure and performing blockchain-based counterfeit tracking processing on the tag-end identification information, the method further includes: In response to determining that the dynamic fingerprint generation mode information is encryption and decryption fingerprint generation mode information, controlling the radio frequency identification tag storage end to determine the tag end identification information and the tag hash value of the verification platform public key of the anti-counterfeiting verification platform end; Generate a temporary tag key pair for the radio frequency identification tag storage end, wherein the temporary tag key pair includes: a temporary tag private key and a temporary tag public key; Generate an elliptic derived key according to the tag dynamic fingerprint information, the tag hash value and the temporary tag key pair; Coordinate encoding is performed on the coordinates of the temporary tag public key to obtain a public key encoding byte stream; Performing tag encryption on the tag dynamic fingerprint information according to the elliptical derived key to obtain encrypted tag dynamic fingerprint information; Performing data integrity verification on the tag dynamic fingerprint information according to the coordinates of the temporary tag public key to obtain a tag verification byte stream; Performing byte stream splicing on the public key encoded byte stream, the tag verification byte stream and the encrypted tag dynamic fingerprint information to obtain a spliced ​​encoded byte stream; The tag dynamic fingerprint information and the spliced ​​encoded byte stream are sent to the application terminal.

3. The method according to claim 2, wherein: After sending the tag dynamic fingerprint information and the spliced ​​encoded byte stream to the application terminal, the method further includes: Controlling the application terminal to send the tag dynamic fingerprint information and the spliced ​​encoded byte stream to the anti-counterfeiting verification platform end; Controlling the anti-counterfeiting verification platform to decode the received concatenated encoded byte stream to obtain a first decoded string, a second decoded string, and a third decoded string; Determine the product of the verification platform private key of the anti-counterfeiting verification platform and the first decoded string as the verification terminal coordinates, wherein the verification platform private key is stored in the platform encryption hardware component; Generate a verification terminal derived key according to the verification terminal coordinates and the tag hash value; Determining an exclusive OR operation of the verification end derived key and the second decoded character string to obtain verification end decrypted information; The verification end decryption information and the verification end coordinates are spliced ​​and input into the data integrity verification function to obtain the verification end verification string; In response to determining that the verification end verification string and the third decoded string are identical, extracting data from the verification end decrypted information to obtain decrypted tag identification information, a decrypted timestamp, and a decrypted random number; Performing multi-level verification on the decrypted tag identification information, the decrypted timestamp, and the decrypted random number to obtain a multi-level verification result information set; In response to determining that each level of verification result information in the multi-level verification result information set indicates successful verification, the verification success information and the decrypted tag identification information are sent to the application terminal.

4. The method according to claim 1, wherein The anti-counterfeiting verification platform performs multi-level anti-counterfeiting verification on the received tag dynamic fingerprint information, the signed tag dynamic fingerprint information, and the tag end issuance certificate information according to the verification platform public key of the anti-counterfeiting verification platform end, and obtains anti-counterfeiting verification result information, including: Controlling the anti-counterfeiting verification platform to perform digital certificate verification on the certificate information issued by the tag end according to the verification platform public key, and obtaining certificate verification result information; Input the tag dynamic fingerprint information into the tag fingerprint hash value generation function to obtain a dynamic fingerprint hash value; Perform hash value verification on the dynamic fingerprint hash value according to the tag end public key and the signed tag dynamic fingerprint information to obtain hash value verification result information; Determine whether the verification timestamp in the tag dynamic fingerprint information is within a preset timestamp window, and obtain timestamp verification result information; The certificate verification result information, the hash value verification result information and the timestamp verification result information are determined as anti-counterfeiting verification result information, and in response to determining that the certificate verification result information, the hash value verification result information and the timestamp verification result information all represent successful verification, a random hash value of the random number in the tag dynamic fingerprint information is determined, and the random hash value and the verification information representing successful verification are sent to the application terminal.

5. The method according to claim 1, wherein The controlling the radio frequency identification tag storage end and the application terminal to perform bidirectional identity authentication to obtain a bidirectional identity authentication information set includes: Controlling the radio frequency identification tag storage end to generate a tag elliptic curve private key and a tag elliptic curve public key; Determine the point product of the label elliptic curve private key and the application elliptic curve public key sent by the application terminal as the label shared key; Determine an exclusive OR operation of the tag shared key and the storage end identification information to obtain first tag verification information; Performing a hash operation on the tag shared key, the storage end identification information, and the applied elliptic curve public key to obtain second tag verification information; Controlling the anti-counterfeiting verification platform to determine the point product of the tag elliptic curve public key and the application elliptic curve private key received from the radio frequency identification tag storage end as the anti-counterfeiting shared key; Determine an exclusive OR operation of the first label verification information and the anti-counterfeiting shared key to obtain anti-counterfeiting label verification information; Determining whether storage end identification information corresponding to the anti-counterfeiting label verification information exists in the anti-counterfeiting verification platform end; In response to determining that storage end identification information corresponding to the anti-counterfeiting label verification information exists, performing a hash operation on the anti-counterfeiting shared key, the storage end identification information, and the applied elliptic curve public key to obtain third label verification information; In response to determining that the third tag verification information is identical to the second tag verification information received by the application terminal, the information of the RFID tag storage end confirming the identity authentication of the application terminal is determined as the first two-way identity authentication information.

6. The method according to claim 5, wherein: The method further comprises: Controlling the application terminal to determine the tag incentive information corresponding to the storage terminal identification information; Determine an exclusive OR operation of the storage end identification information and the tag excitation information to obtain first application verification information; Determine an exclusive OR operation between the anti-counterfeiting shared key and the tag excitation response information corresponding to the tag excitation information to obtain second application verification information; Controlling the application terminal to determine an exclusive OR operation of the received first application verification information and the storage terminal identification information to obtain first application information to be verified; Inputting the first application information to be verified into an unclonable function to obtain second application information to be verified; Determine an exclusive OR operation of the received second application verification information and the label shared key to obtain third application verification information; In response to determining that the third application verification information is the same as the second application information to be verified, determining the information of the identity verification of the radio frequency identification tag storage terminal confirmed by the application terminal as second two-way identity verification information; The first two-way identity authentication information and the second two-way identity authentication information are determined as the two-way identity authentication information set.

7. An article anti-counterfeiting verification device based on a radio frequency identification anti-counterfeiting system, comprising: a two-way authentication unit configured to control the radio frequency identification tag storage end and the application terminal to perform two-way authentication to obtain a two-way authentication information set; a control unit configured to, in response to determining that both the two-way identity authentication information sets indicate successful authentication, control the application terminal to generate a dynamic quantum random number and an anti-counterfeiting verification timestamp; a first generating unit configured to determine dynamic fingerprint generation mode information in response to detecting that the RFID tag storage terminal receives the challenge request information sent by the application terminal; a second generating unit configured to, in response to determining that the dynamic fingerprint generation mode information is signature fingerprint generation mode information, generate tag dynamic fingerprint information according to the received dynamic quantum random number, the anti-counterfeiting verification timestamp and the stored tag end identification information; a software and hardware combined signature unit configured to perform software and hardware combined signature processing on the tag dynamic fingerprint information according to the tag end private key physically stored in the RFID tag storage end, and obtain the signed tag dynamic fingerprint information; A multi-level anti-counterfeiting verification unit is configured to perform multi-level anti-counterfeiting verification on the received tag dynamic fingerprint information, the signed tag dynamic fingerprint information, and the tag issuance certificate information according to the verification platform public key of the anti-counterfeiting verification platform to obtain anti-counterfeiting verification result information, wherein the multi-level anti-counterfeiting verification includes: issuance certificate verification, data integrity verification, and timeliness verification; The alarm unit is configured to trigger an alarm in response to determining that the anti-counterfeiting verification result information indicates a verification failure, and to perform blockchain-based counterfeit tracking processing on the tag-end identification information.

8. An electronic device comprising: one or more processors; a storage device having one or more programs stored thereon, When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 6.

9. A computer-readable medium having a computer program stored thereon, wherein: When the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Anti-counterfeiting method and system based on radio frequency identification technology

    CN102955958A

  • Block chain logistic source tracking anti-fake method based on NFC (Near Field Communication)

    CN107133532A

  • Cloud storage method and system based on identity verification technology with optimal algorithm

    CN107707660A

  • Information authentication method and device, equipment and storage medium

    CN117544321A

  • Device, consumables and authentication method for anti-counterfeiting authentication of consumables based on NFC tags using PUF

    CN119761396A