Article anti-counterfeiting verification method, device and equipment based on radio frequency identification anti-counterfeiting system
By combining two-way identity verification, dynamic quantum random numbers, and multi-level verification of the radio frequency identification anti-counterfeiting system with software and hardware signatures and blockchain technology, the accuracy and security issues of product anti-counterfeiting verification are solved, and real-time updates and traceability throughout the entire lifecycle are realized.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SHENZHEN INTERESTED TECHNOLOGY CO LTD
- Filing Date
- 2025-05-30
- Publication Date
- 2026-05-19
AI Technical Summary
Existing anti-counterfeiting verification technologies suffer from low accuracy and security issues due to the replicability of static physical features, and cannot achieve full-cycle traceability.
A radio frequency identification (RFID) anti-counterfeiting system is used for two-way identity verification, generating dynamic quantum random numbers and anti-counterfeiting verification timestamps. Through multi-level anti-counterfeiting verification and blockchain tracking, combined with software and hardware signature processing and PUF technology, the security and traceability of the verification are ensured.
It improves the accuracy and security of anti-counterfeiting verification of goods, realizes real-time updates and evidence traceability throughout the entire life cycle, and enhances the ability to resist attacks and the accuracy of anti-counterfeiting alarms.
Smart Images

Figure CN120671694B_ABST
Abstract
Description
Technical Field
[0001] The embodiments disclosed herein relate to the field of computer technology, and specifically to a method, apparatus, and equipment for verifying the anti-counterfeiting of goods based on a radio frequency identification (RFID) anti-counterfeiting system. Background Technology
[0002] Anti-counterfeiting verification utilizes radio frequency identification (RFID) technology to verify the authenticity of product labels, preventing counterfeit goods and improving product authenticity and security. RFID is a wireless communication technology that uses radio signals to identify specific labels and verify their authenticity. For anti-counterfeiting verification, the common method is to digitize and store the product's static physical characteristics (e.g., anti-counterfeiting codes, dot matrix, texture, patterns) in a database. Upon detecting a product label, the label is compared with the static physical characteristics in the database to obtain verification information. The comparison result (authenticity result or archived images or patterns) is then sent to a verification terminal. The verification terminal analyzes the verification information to determine the product's authenticity and stores it in the database.
[0003] However, in practice, it has been found that when using the above methods to verify the authenticity of items, the following technical problems often exist: First, because the static physical characteristics of items are replicable, it is easy for multiple items to match a single static physical characteristic. Second, the verification is based solely on a one-way feature comparison between the item label and the static physical characteristic information in the database, which leads to passivity and illegal acquisition of item information, resulting in low accuracy of item anti-counterfeiting verification and low item security. Third, when counterfeit items are identified, it is impossible to trace the counterfeit items throughout their entire lifecycle.
[0004] The information disclosed in this background section is only intended to enhance the understanding of the background of the present disclosure concept, and therefore may contain information that does not constitute prior art known to those skilled in the art. Summary of the Invention
[0005] The summary portion of this disclosure is intended to provide a brief overview of the concepts, which will be described in detail in the detailed description portion. This summary portion is not intended to identify key or essential features of the claimed technical solutions, nor is it intended to limit the scope of the claimed technical solutions.
[0006] Some embodiments of this disclosure propose methods, apparatus, and equipment for verifying the authenticity of goods based on radio frequency identification (RFID) anti-counterfeiting systems, in order to solve one or more of the technical problems mentioned in the background section above.
[0007] In a first aspect, some embodiments of this disclosure provide a method for verifying the authenticity of goods based on a radio frequency identification (RFID) anti-counterfeiting system, comprising an RFID tag storage terminal, an application terminal, and an anti-counterfeiting verification platform: controlling the RFID tag storage terminal and the application terminal to perform two-way authentication to obtain a two-way authentication information set; in response to determining that the two-way authentication information set represents successful verification, controlling the application terminal to generate a dynamic quantum random number and an anti-counterfeiting verification timestamp; in response to detecting that the RFID tag storage terminal receives challenge request information sent by the application terminal, determining dynamic fingerprint generation method information; in response to determining that the dynamic fingerprint generation method information is signature fingerprint generation method information, based on the received dynamic quantum random number and anti-counterfeiting verification timestamp... The system generates tag dynamic fingerprint information based on the stored tag identification information. Using the tag private key physically stored in the RFID tag storage terminal, it performs a hardware-software combined signature process on the tag dynamic fingerprint information to obtain signed tag dynamic fingerprint information. Based on the verification platform public key of the anti-counterfeiting verification platform, it performs multi-level anti-counterfeiting verification on the received tag dynamic fingerprint information, signed tag dynamic fingerprint information, and tag-end issuance certificate information to obtain anti-counterfeiting verification result information. The multi-level anti-counterfeiting verification includes: issuance certificate verification, data integrity verification, and timeliness verification. In response to the determination that the anti-counterfeiting verification result information indicates verification failure, it triggers an alarm and performs blockchain-based counterfeiting tracking processing on the tag identification information.
[0008] Secondly, some embodiments of this disclosure provide an anti-counterfeiting verification device for items based on a radio frequency identification (RFID) anti-counterfeiting system, comprising: a two-way authentication unit configured to control the RFID tag storage terminal and the application terminal to perform two-way authentication to obtain a two-way authentication information set; a control unit configured to, in response to determining that the two-way authentication information set indicates successful authentication, control the application terminal to generate a dynamic quantum random number and an anti-counterfeiting verification timestamp; a first generation unit configured to, in response to detecting that the RFID tag storage terminal receives challenge request information sent by the application terminal, determine dynamic fingerprint generation method information; and a second generation unit configured to, in response to determining that the dynamic fingerprint generation method information is signature fingerprint generation method information, generate a signature fingerprint based on the received dynamic quantum random number, the anti-counterfeiting verification timestamp, and the stored tag. The system includes: an identification information unit that generates dynamic fingerprint information for tags; a hardware-software signature unit configured to perform hardware-software signature processing on the dynamic fingerprint information based on the tag's private key physically stored in the RFID tag storage terminal, resulting in signed dynamic fingerprint information; a multi-level anti-counterfeiting verification unit configured to perform multi-level anti-counterfeiting verification on the received dynamic fingerprint information, signed dynamic fingerprint information, and tag-end issuance certificate information based on the verification platform public key of the anti-counterfeiting verification platform, resulting in anti-counterfeiting verification result information, wherein the multi-level anti-counterfeiting verification includes: issuance certificate verification, data integrity verification, and timeliness verification; and an alarm unit configured to trigger an alarm in response to the determination that the anti-counterfeiting verification result information indicates verification failure, and to perform blockchain-based counterfeiting tracking processing on the tag identification information.
[0009] Thirdly, some embodiments of this disclosure provide an electronic device, including: one or more processors; and a storage device having one or more programs stored thereon, such that when the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in any implementation of the first aspect.
[0010] Fourthly, some embodiments of this disclosure provide a computer-readable medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the method as described in any implementation of the first aspect.
[0011] The above embodiments of this disclosure have the following beneficial effects: The anti-counterfeiting verification methods of some embodiments of this disclosure can actively perform anti-counterfeiting verification and real-time updates, and use blockchain for full-cycle evidence storage and traceability, thereby improving the accuracy of anti-counterfeiting verification. Specifically, the reasons for the low accuracy of related anti-counterfeiting verification, low security of items, and inability to trace counterfeit items throughout their entire lifecycle are: due to the replicability of static physical characteristics of items, multiple items can easily match a single static physical characteristic; and the method of only comparing and verifying the static physical characteristics of the item tag with the static physical characteristics information in the database in a single direction has passive and illegal acquisition problems, resulting in low accuracy and low security of anti-counterfeiting verification; in addition, it is impossible to trace counterfeit items throughout their entire lifecycle when they are identified. Based on this, the anti-counterfeiting verification methods of some embodiments of this disclosure can first control the above-mentioned RFID tag storage terminal and the above-mentioned application terminal to perform two-way authentication to obtain a two-way authentication information set. Here, two-way authentication can prevent third-party attackers from using fake tag information to attack while ensuring communication security, thereby improving anti-attack performance. Secondly, in response to the determination that the aforementioned two-way authentication information set all represent successful verification, the application terminal is controlled to generate dynamic quantum random numbers and anti-counterfeiting verification timestamps. Here, the dynamic quantum random numbers possess true randomness and unpredictability, generating unique random values for each verification, ensuring non-repeatability during the verification process. The anti-counterfeiting verification timestamps are real-time, used for time validity verification during the verification process to prevent duplicate submissions and replay attacks. Thirdly, in response to detecting that the RFID tag storage terminal receives challenge request information sent by the application terminal, the dynamic fingerprint generation method information is determined. Here, dynamically determining fingerprint generation through different methods avoids the leakage of fixed generation methods, improving anti-counterfeiting verification and anti-attack capabilities. Next, in response to determining that the aforementioned dynamic fingerprint generation method information is signature fingerprint generation method information, tag dynamic fingerprint information is generated based on the received dynamic quantum random numbers, anti-counterfeiting verification timestamps, and stored tag terminal identification information. Here, the tag dynamic fingerprint information, due to the real-time nature and unforgeability of the dynamic quantum random numbers and anti-counterfeiting verification timestamps, can effectively verify data integrity and immutability. Subsequently, based on the tag private key physically stored in the aforementioned RFID tag storage terminal, the aforementioned tag dynamic fingerprint information is subjected to a combination of hardware and software signature processing to obtain the signed tag dynamic fingerprint information.Here, the physically stored tag private key is protected by PUF (Physical Unclonable Functions) or SE (Secure Element). It automatically triggers self-destruction upon detecting a physical attack, improving the security and anti-leakage capability of the private key. This combination of software and hardware reduces the computational load of signature processing, improving signing efficiency and resource consumption. Then, based on the verification platform public key, the received tag dynamic fingerprint information, the signed tag dynamic fingerprint information, and the tag-end issued certificate information undergo multi-layered anti-counterfeiting verification to obtain the anti-counterfeiting verification result. This multi-layered anti-counterfeiting verification includes: certificate verification, data integrity verification, and timeliness verification. The certificate verification, through the embedding of tag-end issued certificate information and tag identification information, prevents certificate reuse. Furthermore, the multi-layered anti-counterfeiting verification improves the accuracy of anti-counterfeiting verification and ensures the security of the tag information stored in the RFID tag memory. Finally, in response to the determination that the above anti-counterfeiting verification result indicates verification failure, an alarm is triggered, and the above label identification information is processed for counterfeiting tracking based on blockchain. This improves the accuracy of anti-counterfeiting alarms and enables blockchain-based evidence storage and traceability of anti-counterfeiting measures. Therefore, this product anti-counterfeiting verification method based on the RFID anti-counterfeiting system, through two-way identity verification and dynamic quantum random numbers, can proactively perform product anti-counterfeiting verification and real-time updates, and achieve full-cycle evidence storage and traceability through blockchain, thereby improving the accuracy of product anti-counterfeiting verification. Attached Figure Description
[0012] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and elements are not necessarily drawn to scale.
[0013] Figure 1 This is a timing diagram of the communication transmission between the radio frequency identification (RFID) tag storage terminal, the application terminal, and the anti-counterfeiting verification platform terminal in some embodiments of the RFID-based anti-counterfeiting verification method for goods according to this disclosure.
[0014] Figure 2 This is a flowchart of some embodiments of the anti-counterfeiting verification method for articles based on the radio frequency identification anti-counterfeiting system according to the present disclosure;
[0015] Figure 3 This is a flowchart illustrating the communication between various controllers in the label signing software and label signing hardware in some embodiments of the article anti-counterfeiting verification method based on the radio frequency identification anti-counterfeiting system disclosed herein.
[0016] Figure 4 This is a flowchart showing the switching between various states of the master control state machine in some embodiments of the article anti-counterfeiting verification method based on the radio frequency identification anti-counterfeiting system according to the present disclosure;
[0017] Figure 5 This is a structural schematic diagram of some embodiments of the anti-counterfeiting verification device for articles based on the radio frequency identification anti-counterfeiting system disclosed herein;
[0018] Figure 6 This is a schematic diagram of the structure of an electronic device suitable for implementing some embodiments of the present disclosure. Detailed Implementation
[0019] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.
[0020] It should also be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings. Unless otherwise specified, the embodiments and features described in this disclosure can be combined with each other.
[0021] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.
[0022] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".
[0023] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.
[0024] This disclosure will now be described in detail with reference to the accompanying drawings and embodiments.
[0025] Figure 1 The diagram illustrates the communication flow between the RFID tag storage terminal 101, the application terminal 102, and the anti-counterfeiting verification platform terminal 103 included in the RFID anti-counterfeiting system. The RFID tag storage terminal 101 and the application terminal are connected for communication. The application terminal 102 and the anti-counterfeiting verification platform terminal 103 are connected for communication.
[0026] Figure 2 A flowchart 200 is shown, illustrating some embodiments of an article anti-counterfeiting verification method based on a radio frequency identification (RFID) anti-counterfeiting system according to this disclosure. This article anti-counterfeiting verification method based on an RFID anti-counterfeiting system includes the following steps:
[0027] Step 201: Control the RFID tag storage terminal and the application terminal to perform two-way authentication to obtain a two-way authentication information set.
[0028] In some embodiments, the executing entity (e.g., an electronic device) of the product anti-counterfeiting verification method based on the RFID anti-counterfeiting system can control the aforementioned RFID tag storage terminal and the aforementioned application terminal to perform two-way authentication, obtaining a two-way authentication information set. The two-way authentication information in the aforementioned two-way authentication information set can represent information from the RFID tag storage terminal verifying the identity of the application terminal, and information from the application terminal verifying the identity of the RFID tag storage terminal. It should be noted that in two-way authentication, the RFID tag storage terminal and the application terminal each verify the other's identity, ensuring the legitimacy of the other party's identity, preventing unauthorized devices from accessing the system, and effectively preventing malicious devices or unauthorized tags from accessing the system, thus protecting system security.
[0029] In some optional implementations of certain embodiments, controlling the RFID tag storage terminal and the application terminal to perform two-way authentication to obtain a two-way authentication information set may include the following steps:
[0030] The first step is to control the aforementioned RFID tag storage terminal to generate the tag's elliptic curve private key and tag's elliptic curve public key. The tag's elliptic curve private key can be a randomly generated prime number whose order is less than that of the circular curve group. The tag's elliptic curve public key can be a string obtained by adding and multiplying the tag's elliptic curve private key and the base points of the elliptic curve.
[0031] The second step is to determine the dot product of the aforementioned tag elliptic curve private key and the aforementioned application elliptic curve public key sent by the application terminal, which will serve as the tag shared key.
[0032] The third step involves performing an XOR operation on the aforementioned tag shared key and storage terminal identification information to obtain the first tag verification information. The aforementioned storage terminal identification information can be an EPC that uniquely identifies the storage terminal of the aforementioned RFID tag.
[0033] The fourth step involves performing a hash operation on the aforementioned shared tag key, the aforementioned storage terminal identification information, and the aforementioned application elliptic curve public key to obtain the second tag verification information. This second tag verification information can be obtained by first concatenating the aforementioned shared key, the aforementioned storage terminal identification information, and the aforementioned application elliptic curve public key, and then inputting the concatenation into a hash function.
[0034] The fifth step involves controlling the aforementioned anti-counterfeiting verification platform to determine the dot product of the tag elliptic curve public key and the application elliptic curve private key sent by the aforementioned RFID tag storage terminal, which serves as the anti-counterfeiting shared key.
[0035] Step 6: Perform an XOR operation on the first tag verification information and the anti-counterfeiting shared key to obtain the anti-counterfeiting tag verification information.
[0036] Step 7: Determine whether there is storage terminal identification information in the above-mentioned anti-counterfeiting verification platform that corresponds to the above-mentioned anti-counterfeiting label verification information.
[0037] Step 8: In response to the determination that there is storage terminal identification information corresponding to the above anti-counterfeiting label verification information, perform a hash operation on the above anti-counterfeiting shared key, the above storage terminal identification information and the above application elliptic curve public key to obtain the third label verification information.
[0038] Step 9: In response to determining that the third tag verification information and the second tag verification information received by the application terminal are the same, the information of the RFID tag storage terminal confirming the identity verification of the application terminal is determined as the first two-way identity verification information.
[0039] Optionally, the above method may further include the following steps:
[0040] The first step is to control the application terminal to determine the tag activation information corresponding to the storage terminal identification information. This tag activation information can be generated by using a PUF module to input the storage terminal identification information into a PUF function for activation.
[0041] The second step is to determine the XOR operation between the above-mentioned storage terminal identification information and the above-mentioned tag incentive information to obtain the first application verification information.
[0042] The third step is to determine the XOR operation between the application shared key and the tag incentive response information corresponding to the tag incentive information to obtain the second application verification information.
[0043] The fourth step is to control the application terminal to determine the XOR operation between the received first application verification information and the storage terminal identification information to obtain the first application information to be verified.
[0044] Fifth, input the first application information to be verified into the non-cloning function to obtain the second application information to be verified. The non-cloning function can be a PUF function.
[0045] The sixth step is to determine the XOR operation between the received second application verification information and the aforementioned tag shared key to obtain the third application verification information.
[0046] Step 7: In response to determining that the third application verification information and the second application information to be verified are the same, the information of the application terminal confirming the identity verification of the RFID tag storage terminal is determined as the second two-way identity verification information.
[0047] Step 8: The first two-way authentication information and the second two-way authentication information are determined as the two-way authentication information set.
[0048] Step 202: In response to determining that the two-way authentication information set represents successful authentication, control the application terminal to generate dynamic quantum random numbers and anti-counterfeiting verification timestamps.
[0049] In some embodiments, the executing entity may, in response to determining that the two-way authentication information set represents successful verification, control the application terminal to generate dynamic quantum random numbers and anti-counterfeiting verification timestamps. The aforementioned RFID anti-counterfeiting system may be an active anti-counterfeiting verification system suitable for luxury goods, digital assets, industrial parts, medical fields, financial fields, and physical goods, verifying tag information obtained by RFID methods. The aforementioned RFID anti-counterfeiting system may include: an RFID tag storage terminal, an application terminal, and an anti-counterfeiting verification platform. The aforementioned RFID tag storage terminal may be an RFID (Radio Frequency Identification) chip that stores the tag information of the item. The aforementioned application terminal may be a server that communicates with the aforementioned RFID tag storage terminal and sends random numbers and timestamps. For example, the aforementioned application terminal may be a mobile phone. The aforementioned anti-counterfeiting verification platform may be a server used to verify the authenticity of the tag information of the aforementioned RFID tag storage terminal and to perform full-cycle tracking and traceability, and to store the tag terminal identification information, tag terminal public key, and tag terminal issuance certificate information of each RFID tag storage terminal in a database format. The aforementioned dynamic quantum random number can be a 128-bit, unpredictable random number generated based on quantum superposition and quantum entanglement states in quantum mechanics, conforming to the randomness detection specifications issued by the State Cryptography Administration. This dynamic quantum random number can be generated using a QRNG (Quantum Random Number Generator). The aforementioned location verification timestamp can record the time when the anti-counterfeiting verification was initiated.
[0050] Step 203: In response to detecting that the RFID tag storage terminal has received a challenge request information sent by the application terminal, determine the dynamic fingerprint generation method information.
[0051] In some embodiments, the executing entity may determine dynamic fingerprint generation method information in response to detecting that the RFID tag storage terminal has received challenge request information sent by the application terminal. The challenge request information may be request information in a signature request data packet sent by the application terminal to the RFID tag storage terminal. The dynamic fingerprint generation method information may be information about the method of generating the tag information stored in the RFID tag storage terminal. The dynamic fingerprint generation method information may include, but is not limited to, at least one of the following: signature anti-counterfeiting method information, identity authentication method information, data encryption method information, blockchain anti-counterfeiting method information, and hardware anti-counterfeiting method information.
[0052] Step 204: In response to determining that the dynamic fingerprint generation method information is the signature fingerprint generation method information, the tag dynamic fingerprint information is generated based on the received dynamic quantum random number, the anti-counterfeiting verification timestamp, and the stored tag end identification information.
[0053] In some embodiments, the executing entity may, in response to determining that the dynamic fingerprint generation method information is signature fingerprint generation method information, generate tag dynamic fingerprint information based on the received dynamic quantum random number, anti-counterfeiting verification timestamp, and stored tag terminal identification information. The signature fingerprint generation method information may be generation method information for generating fingerprint information through a signature algorithm. The tag dynamic fingerprint information may be information characterizing the uniqueness of the tag information, verifying the authenticity, integrity, and non-repudiation of the data. The tag terminal identification information may be identification information uniquely identifying the storage terminal of the RFID tag. The tag terminal identification information may be an EPC (Electronic Product Code).
[0054] As an example, the aforementioned executing entity can first concatenate the aforementioned dynamic quantum random number, the aforementioned location verification timestamp, and the aforementioned tag identification information to obtain a concatenated string. Then, the concatenated string is input into a national cryptographic algorithm to obtain the tag's dynamic fingerprint information. The aforementioned national cryptographic algorithm can be the SM3 (cryptographic hash function) algorithm.
[0055] Step 205: Based on the private key of the tag stored physically at the RFID tag storage terminal, perform a combination of hardware and software signature processing on the tag dynamic fingerprint information to obtain the signed tag dynamic fingerprint information.
[0056] In some embodiments, the executing entity can perform a combination of hardware and software signature processing on the tag dynamic fingerprint information based on the tag-end private key physically stored in the RFID tag storage terminal, to obtain the signed tag dynamic fingerprint information. The tag-end private key can be the private key in the key pair generated by the RFID tag storage terminal using a secp256k1 elliptic curve. secp256k1 can be any type of elliptic curve. The signed tag dynamic fingerprint information can be the fingerprint information generated by the tag-end private key and the signature algorithm. The signed tag dynamic fingerprint information can be sent from the RFID tag storage terminal to the application terminal, and then the application terminal sends the signed tag dynamic fingerprint information to the anti-counterfeiting verification platform.
[0057] As an example, the aforementioned executing entity can input the private key of the tag and the dynamic fingerprint information of the tag into the SM9 (Identification Cryptography Algorithm) national cryptographic algorithm, which combines software and hardware, to obtain the dynamic fingerprint information of the tag after signing. The aforementioned SM9 national cryptographic algorithm, combining software and hardware, can be based on a SoPC (System On a Programmable Chip) architecture and implemented on an FPGA (Field Programmable Gate Array) to complete the generation and verification of digital signatures. The software part of the SM9 algorithm optimizes the SM9 algorithm by introducing Jacobian coordinates to avoid modular inversion operations and introducing modular exponentiation calculations based on NAF (Non-Adjacent Form) to reduce software computation time. The hardware can implement partial prime field multi-point calculation units, quadratic extended field multi-point calculation units, and hardware parts that reference bilinear pairing calculations to reuse and shorten the design cycle. The prime field multi-point calculation unit uses the Montgomery ladder algorithm to improve resistance to side-channel attacks and improves computation speed by performing calculations in parallel with two prime field calculation units. The quadratic extended domain multi-point calculation unit performs calculations through the quadratic extended domain calculation unit.
[0058] In addressing the first technical problem mentioned above, a second technical problem often arises: the stability of the physically unclonable function response is affected by the resources and computing power of the RFID tag's storage, leading to instability and low security for private key storage. A conventional solution to this second technical problem is to use a fuzzy extractor to obtain and store the stable output of the physically unclonable function. However, this conventional solution still suffers from the following issues: the RFID tag's storage is a resource-constrained, portable chip, and the stable output based on the fuzzy extractor involves a large number of uniform parameters, making it unsuitable for storage devices with limited computing power, area, and power. Furthermore, it ignores the PUF inter-chip distance, increasing the error correction burden and resulting in low stability, low storage security, and significant waste of storage resources. Considering the shortcomings of the conventional solution and leveraging the advantages and current state of the inventor's company's physical key storage technology, we have decided to adopt the following solution:
[0059] In some optional implementations of certain embodiments, the physically stored tag-end private key described above may be stored through the following steps:
[0060] The first step involves inputting the power-on initial state information and storage terminal identification information of the aforementioned RFID tag memory in the active state to the physically unclonable functional component (PUF) to obtain initial response information. The power-on initial state information in the active state can be a random power-on value of the RFID tag memory when powered on, representing the power-on state. The physically unclonable functional component can be a hardware PUF component. The initial response information can be the response information of the hardware PUF component after receiving the power-on initial state information and storage terminal identification information, reflecting the differences in transistor threshold voltage changes and interconnect delays within the PUF hardware. Because the PUF can utilize the uncopyability of its hardware physical structure, the initial response information possesses physical uniqueness.
[0061] The second step is to determine the set of adjacent response stability values for the memory cells included in the aforementioned physically unclonable functional components. Here, a memory cell in the aforementioned set can be a basic unit of a memory circuit, a memory cell used to store 1 bit of data, or a memory cell composed of multiple transistors. The adjacent response stability values in the aforementioned set of adjacent response stability values characterize the degree to which a memory cell is affected by capacitive crosstalk from adjacent memory cells. The larger the adjacent response stability value, the greater the influence from adjacent memory cells. In practice, the executing entity can perform the following determination steps for each memory cell in the aforementioned set of memory cells: First, determine the joint response error probability where a memory cell experiences a response error, and at least two adjacent cells within a fixed window centered on the memory cell also experience response errors. Here, the fixed window can be a 5-bit window. Then, determine the response error probability where at least two adjacent cells within the fixed window centered on the memory cell also experience response errors. Finally, determine the ratio of the joint response error probability to the response error probability as the adjacent response stability value of the memory cell.
[0062] The third step involves performing stability screening on the aforementioned set of adjacent response stability values for storage cells to obtain a stable set of storage cells. The stable storage cells in this set can be those whose adjacent response stability values are less than or equal to a preset response stability threshold. This preset response stability threshold can be 0.3.
[0063] As an example, the aforementioned execution entity can select at least one adjacent response stability value of a storage cell that is less than or equal to a preset response stability threshold from the aforementioned set of adjacent response stability values of storage cells, and use it as a stable storage cell set.
[0064] The fourth step involves inputting the random number seed corresponding to the initial response information into the hash function to obtain the hash string. The random number seed can be a 64-bit strongly random binary sequence randomly selected from the initial response information. The hash function can be a key derivation function.
[0065] The fifth step involves encoding the hash string and the preset error correction code to obtain the error correction code encoding information. The preset error correction code can be a BCH (Bose Chaudhuri Hocquenghem, error correction code) and a repeated error correction code obtained by repeating each storage unit in the storage unit set a preset number of times. The BCH can be (127, 85, 13). 127 represents the total codeword length, 85 represents the information length, and 13 represents the error correction capability. The repeated error correction code can be (5, 1, 5). The first 5 represents the output codeword length, the 1 represents the input information length, and the second 5 represents the Hamming distance, i.e., the full codeword difference, with no redundancy in error correction capability. The error correction code encoding information can be obtained by inputting the hash string and the preset error correction code into the Gen function of the reverse fuzzy extractor based on the error correction code offset mechanism.
[0066] The sixth step is to determine the XOR operation between the above error correction code encoding information and the initial response information corresponding to the above stable storage unit set to obtain the response auxiliary information.
[0067] Step 7: Decode the initial response information and the auxiliary response information to obtain a decoded response random number. This decoded response random number can be obtained by inputting the initial response information and the auxiliary response information into the Rep function of the reverse blur extractor based on the error correction code offset mechanism, recovering the random number seed, and then inputting it into the key derivation function.
[0068] Step 8: Determine the range of the conditional entropy of the decoded response random number. In practice, the executing entity can use the conditional entropy function of the random number seed and response auxiliary information to determine the range of the conditional entropy of the decoded response random number. The conditional entropy function can be:
[0069] H ∞ (S|W)=H ∞ (S)-I(S,W)=H ∞ (S)-k+H ∞ (X)-H ∞ (XH T ).
[0070] Among them, H ∞ (S|W) represents the entropy of the random number seed in the infinite norm when the auxiliary information of the response is known. ∞ (S) represents the entropy of the random number seed under the infinity norm, which in this scenario can be a function of the length of the random number seed. I(S, W) represents the mutual information between the random number seed and the response auxiliary information, characterizing the degree of dependence between the random number seed and the response auxiliary information. k represents the length of the random number seed. H ∞(X) represents the entropy of the initial response information in the infinite norm, H ∞ (X)=nh(p b )=n×[-lb(max(p b ,1-p b ))], where n represents the codeword length of the preset error correction code, h(p b ) represents p bPUF The bias of the response is the minimum entropy density function of the probability of 1 appearing in the response value, where lb() represents the base-2 logarithmic function of 2. H ∞ (XH T The expression represents the error correction checksum generated from the initial response information using preset error correction codes. Its upper limit is |XH| = nk, and its lower limit is L·(n1n2-k2), where n1 represents the codeword length of the BCH error correction code, n2 represents the codeword length of the repeated error correction code, k2 represents the information length of the BCH error correction code, and L represents the number of BCH error correction codes. H represents the checksum matrix of the preset error correction codes. T This represents the transpose of the parity-check matrix. X represents the initial response information. S represents the random number seed. W represents the response auxiliary information.
[0071] Due to H ∞ (XH T H has upper and lower limits, therefore H ∞ (S|W) also has upper and lower limits, that is, the range of the response conditional entropy is L-(n1n2h(p)). b H )-n1n2+k2)≤H ∞ (S|W)≤kn(1-(p b )).
[0072] Step nine: In response to the determination that the hash string exists within the same range of the response condition entropy, an XOR operation is performed on the tag-side private key and the response auxiliary information output by the PUF component to obtain the response tag private key, which serves as the tag-side private key. This key is then immediately cleared after retrieval and use, thus completing the physical storage of the tag-side private key. It should be noted that because the PUF responds based on the differences in threshold voltage changes of the internal transistors and interconnect delays, the response auxiliary information output by the PUF component is non-replicable and physically unique, thereby improving the security, uniqueness, and non-replicability of the tag-side private key.
[0073] The above-described technical solution and its related content, as an inventive point of this disclosure, solve the second technical problem mentioned in the background: "Because the RFID tag storage terminal is a resource-constrained, portable chip, and the stable output based on the fuzzy extractor has a large number of uniform speeds, it is not suitable for storage terminals with limited computing power, area, and power. Furthermore, ignoring the PUF inter-chip distance increases the error correction burden, resulting in low stability, low storage security, and a significant waste of storage resources for the RFID tag storage terminal." The factors leading to low stability, low storage security, and significant waste of storage resources in the RFID tag storage terminal are often as follows: Since the RFID tag storage terminal is a resource-constrained, portable chip, and the stable output based on the fuzzy extractor has a large number of uniform speeds, it is not suitable for storage terminals with limited computing power, area, and power. Furthermore, ignoring the PUF inter-chip distance increases the error correction burden. Solving these factors can improve the stability and storage security of the RFID tag storage terminal and reduce the waste of storage resources. To achieve this effect, this disclosure utilizes the characteristic of adjacent unstable bits in some unstable PUF cells to propose a set of storage cell adjacent response stability values based on conditional probability. This set is then filtered to reduce capacitive crosstalk caused by coupling capacitors, decrease the influence of adjacent cells, lower the response error rate, and remove unstable bits prone to consecutive errors. Furthermore, by combining the advantages of a reverse fuzzy extractor and pre-selected bits, the response failure rate can be reduced with smaller PUF resources, improving the stability and security of the RFID tag's storage end and reducing storage resource waste. Since the PUF responds based on the differences in threshold voltage changes of internal transistors and interconnect delays, the aforementioned response auxiliary information output by the PUF component is non-replicable and physically unique, thus improving the security, uniqueness, and non-replicability of the tag's private key.
[0074] In addressing the first technical problem mentioned above, a third technical problem often arises: Since digital signature algorithms involving national cryptographic algorithms perform calculations on elliptic curves under different finite fields to generate and verify digital signatures, this involves numerous elliptic curve point operations and large integer modulo operations, resulting in high computational load and requiring substantial computing resources. However, the resources of the chips at the storage end of RFID tags are limited. For the second technical problem, conventional solutions typically involve implementing elliptic curve-based digital signature algorithms solely through software or hardware methods to obtain the dynamic fingerprint information of the signed tag. However, these conventional solutions still suffer from the following issues: software implementations cannot meet high throughput requirements, resulting in lower accuracy and efficiency of digital signatures, longer signing times, and limitations on elliptic curves over binary extended fields, leading to shorter key lengths and lower key security. Hardware implementations suffer from poor versatility and scalability, and high costs for secondary development and upgrades. Considering the shortcomings of these conventional solutions and leveraging the advantages and current state of our company's physical key storage technology, we have decided to adopt the following solution:
[0075] In some optional implementations of certain embodiments, the process of performing a hardware-software combined signature on the tag dynamic fingerprint information based on the tag private key physically stored at the RFID tag storage terminal to obtain the signed tag dynamic fingerprint information may include the following steps:
[0076] The first step involves controlling the tag signing software to determine the elliptic curve parameters and the elliptic curve cryptography (ECC) protocol. This tag signing software can be executed by a Cortex-M0 electronic component. The combined hardware and software signature processing involves the tag signing software and hardware working together to invoke the ECC protocol. This ECC protocol includes a key pair generation protocol, a digital signature generation protocol, and a digital signature verification protocol. The tag signing hardware performs scalar multiplication operations within the ECC protocol, while the tag signing software performs all other operations within the ECC protocol. The ECC key generation protocol can include SM2 and SM9. The tag signing software can freely switch between SM2 and SM9, or the user can customize the switch. If the user does not specify a switching command, the tag signing software will use internal custom switching conditions. These custom switching conditions could be triggered by detecting bilinear pairing operations or anonymous authentication scenarios within the ECC key generation protocol, switching to the SM9 protocol; otherwise, the SM2 protocol can be used.
[0077] The second step involves, in response to the determination that the tag signing software is executing an elliptic curve-based key generation algorithm, controlling the tag signing software to invoke the software-hardware interface to send the scalar multiplication operation request from the elliptic curve-based key generation algorithm to the tag signing hardware. The software-hardware interface communicates with the AHB (Advanced High Performance Bus) bus via a main control interface. The main control interface consists of four parts: an instruction area, a state area, a data area, and a main control state machine. The main control interface is described below. Figure 3 As shown in the right half of the diagram. The instruction area described above can be used to receive control commands sent by the tag signing software. The status area described above can be used to store the status information of the tag signing hardware, which can be directly accessed by the tag signing software. The data area described above can be used for data interaction between the tag signing software and the tag signing hardware.
[0078] The aforementioned master control state machine can consist of eight states, responsible for controlling various operations of the tag signature hardware. State transitions are controlled by instructions and feedback circuits. These eight states can include: IDLE (idle state), INPUT_G (arbitrary point scalar multiplication parameter input state), INPUT_Q (fixed point or arbitrary point scalar multiplication parameter q input state), INPUT_U (unit function module parameter input state), PCAL (pre-computation state), CAL (scalar multiplication calculation state), UCAL (unit function module calculation state), and OUTPUT (output state). Switching between these eight states can be controlled by... Figure 4 As shown. Figure 4The parameters `idle_tou`, `u_ready`, `ucal_done`, `cal_done`, `q_ready`, `pcal_done`, `g_ready`, `idle_tok`, `idle_tog`, and `output_done` can all represent state transition signals. When `idle_tou` = true, it indicates that one of the modular addition, modular subtraction, modular multiplication, or modular inverse operations in the domain operation layer of the tag signature hardware will be invoked. When `u_ready` = true, it indicates that the input of each module in the tag signature hardware is complete. When `ucal_done` = true, it indicates that the calculation of each module in the tag signature hardware is complete, and the calculation of the master control state machine is complete. When `cal_done` = true, it indicates that the scalar multiplication calculation of the multi-point operation layer module is complete, and the scalar multiplication operation of the master control state machine is complete. When `q_ready` = true, it indicates that the input of the q-value for the scalar multiplication of the multi-point operation layer module is complete. When `pcal_done = true`, it indicates that the pre-calculation process of arbitrary-point scalar multiplication in the multi-point arithmetic layer module is complete, and the main control state machine pre-calculation is finished, ready to begin the formal scalar multiplication calculation. When `g_ready = true`, it indicates that the scalar parameter input for arbitrary-point scalar multiplication in the multi-point arithmetic layer module is complete. When `idle_tok = true`, it indicates that the fixed-point scalar multiplication function in the multi-point arithmetic layer module will be called. When `idle_tog = true`, it indicates that the arbitrary-point scalar multiplication function in the multi-point arithmetic layer module will be called. When `output_done = true`, it indicates that the output result from the tag signature hardware has ended, restoring the initial state to an empty instruction; no operation is performed.
[0079] The communication process between the tag signing hardware and software can be as follows: when the tag signing hardware needs to be called, the tag signing software will combine the information in the state area and input the corresponding control command into the command area; the tag signing software will interact with the data area to complete the call and request information sending operation; after the tag signing hardware completes the operation, it will notify the master control state machine to complete the operation through the feedback circuit.
[0080] The third step is to control the aforementioned tag signing software to receive the elliptic curve key pair and elliptic curve parameter set generated by the aforementioned tag signing hardware through the aforementioned software and hardware call interface.
[0081] The fourth step involves controlling the aforementioned tag signing software to concatenate the tag identifier information, the bit length of the tag identifier information, the elliptic curve coordinates of the tag public key corresponding to the tag private key, and the elliptic curve parameter set to obtain the concatenated string. The tag private key can also be obtained through a combination of software and hardware operations, including the tag signing software and hardware.
[0082] The fifth step involves performing a hash operation on the concatenated string to obtain the initial tag hash value. This initial tag hash value represents a summary of the identity information stored in the RFID tag's storage. The hash operation can be an SM3 hash operation.
[0083] Step 6: After concatenating the initial tag hash value and the tag dynamic fingerprint information, perform a hash operation to obtain the tag fingerprint digest. The tag fingerprint digest can be a string that incorporates a non-linear transformation into the initial tag hash value to reduce the risk of information tampering and leakage.
[0084] Step 7: Randomly generate a combination of hardware and software endpoints, wherein the value range of the above-mentioned combination of hardware and software endpoints is [1, the order of the base point of the elliptic curve - 1].
[0085] The fifth step involves calling the software and hardware APIs. This includes sending a scalar multiplication request based on the aforementioned digital signature generation and verification protocols, along with a combined software and hardware random number. The system also controls the tag signing hardware to execute the scalar multiplication request, obtaining the hardware scalar multiplication result. The tag processing hardware corresponding to the aforementioned tag processing hardware interface includes: a domain operation controller, a point operation controller, a multi-point operation controller, and a coordinate transformation controller. The combined software and hardware tag signing software, along with the various controllers, are... Figure 3 The left figure shows the communication call relationship between the tag signing software, the tag signing hardware, and the various components.
[0086] The aforementioned domain operation controller can be a controller that supports modular multiplication, modular addition, modular subtraction, and modular inverse operations via an FPGA hardware-side scalar multiplication circuit module. The modular multiplication operation can include: designing a low-power multiplier using the divide-and-conquer method of the KOM (Karatsuba-Ofman) algorithm, reducing resource and energy consumption through a combination of serial and parallel computation. The KOM algorithm can be used to transform an m-bit multiplication calculation into two m / 2-bit and one m / 2+1-bit multiplication calculations, as well as write addition calculations; for special prime numbers in the recommended parameters of SM2 and SM9, namely extended Mersenne primes, a fast modular reduction algorithm is used to convert division into addition and subtraction operations, reducing computational complexity; intermediate values for repeated calculations are pre-calculated and reused multiple times to reduce the number of repetitive calculations; for modular operations on non-Mersenne primes in the SM2 and SM9 protocol layers, a hardware-software hybrid approach is used to implement the Barrett algorithm to reduce register consumption. The aforementioned modular inverse operation can utilize the binary extended Euclidean algorithm with a recursive division method, transforming all division into addition and subtraction operations, and performing the division by 2 operation using binary shifting, which helps reduce energy consumption. The aforementioned modular addition and subtraction operations are combined into a single modular addition-subtraction operation. Different initial values are selected for calculation based on different modular addition / subtraction modes. The result of addition may exceed the modulus P of the elliptic curve equation, so the result needs to be subtracted from P. The result of subtraction may be negative, so P needs to be added back. The final output result is determined based on the overflow flags from both operations.
[0087] The aforementioned multi-point operation controller can be a controller that uses an FPGA hardware-side scalar multiplication circuit module to call arbitrary-point and fixed-point scalar multiplication operations. The aforementioned multi-point operation controller can include: a fixed-window NAF scalar representation and a fixed-window NAF scalar multiplication algorithm. The aforementioned fixed-window NAF scalar representation can be an algorithm that uses the order of the base point of the elliptic curve parameter to convert the scalar q from an even number to an odd number, and adds twice the order of the elliptic curve base point to maintain conversion consistency when the q is odd. Then, the converted scalar q is converted back to NAF form, where each bit (or window) is any value among odd numbers. The aforementioned fixed-window NAF scalar multiplication algorithm can be an algorithm that first pre-calculates some points (such as P, 2P, 3P, ..., (2^fixed window length - 1)P), which will be reused in subsequent operations. Then, iterates through each bit of the NAF representation, performing the corresponding doubling or addition operation based on the value of the current bit. Since the number of non-zero bits in the NAF representation is small, the number of addition operations is also reduced accordingly.
[0088] The aforementioned coordinate transformation controller can utilize Jacobian weighted projective coordinates or standard projective coordinates to eliminate modular inverse operations during scalar multiplication iterations, thereby improving computational efficiency.
[0089] The aforementioned point operation controller can be an FPGA hardware-based scalar multiplication circuit module used to call point addition and point multiplication operations to implement scalar multiplication. This controller can implement conditional and unconditional point addition in the Jacobian weighted projective coordinate system, reducing the computational cost of modular multiplication. It also significantly reduces the number of point addition calculations compared to the Montgomery scalar multiplication algorithm in the fixed-window NAF scalar multiplication algorithm. The conditional and unconditional point additions can be, respectively, conditional point addition where a coordinate component z_1 = 1 and unconditional point addition where z_1 is not required, in the Jacobian weighted projective coordinate system. When calculating fixed-point scalar multiplication, i.e., the scalar multiplication of SM2 and SM_9 recommended parameters G, the computation process is optimized by storing scalar points with z_1 = 1 within the window and using conditional point addition, thereby reducing the computational cost of modular multiplication. When calculating the scalar multiplication of arbitrary points, the values of the scalar points within the window need to be pre-calculated.
[0090] Step 6: Control the aforementioned tag signing software to receive the hardware scalar multiplication result from the aforementioned tag signing hardware, and continue to execute the aforementioned elliptic curve cryptography algorithm protocol. If there are still scalar multiplication operations to be executed in the aforementioned elliptic curve cryptography algorithm protocol, call the software and hardware calling interfaces to send scalar multiplication operation requests.
[0091] Step 7: In response to the completion of the above-mentioned tag signing hardware and tag signing software operations, the output result of the tag signing software is determined as the dynamic fingerprint information of the signed tag.
[0092] The above-described technical solution and its related content, as an inventive point of this disclosure, solve the second technical problem mentioned in the background: "Implementing digital signatures solely through software methods cannot meet high throughput requirements, resulting in low accuracy and efficiency, long signing times, and limitations on elliptic curves over binary extended fields. Furthermore, the short key length leads to low key security, and hardware-based digital signature implementation suffers from poor versatility, scalability, and low costs for secondary development and upgrades." The factors contributing to low accuracy and efficiency, long signing times, poor versatility, scalability, and high costs for secondary development and upgrades in digital signatures are often as follows: Implementing digital signatures solely through software methods cannot meet high throughput requirements; the accuracy and efficiency of digital signatures are low, the signing time is long, and the short key length leads to low key security; hardware-based digital signature implementation suffers from poor versatility, scalability, and high costs for secondary development and upgrades. Solving these factors can improve the accuracy and efficiency of digital signatures, shorten signing times, improve versatility and scalability, and reduce the costs of secondary development and upgrades. To achieve this effect, this disclosure first determines the elliptic curve parameters and elliptic curve cryptography algorithm protocol, and performs two string concatenation and hash operations on each received string. The first string concatenation and hash operation embeds the identity of the RFID tag's memory, preventing identity impersonation and signature forgery. The second string concatenation and hash operation introduces the superposition effect of nonlinear transformations, increasing the difficulty for attackers to construct the fingerprint and reducing the risk of tampering with the tag's dynamic fingerprint information. Then, it calls the software and hardware interfaces to perform interactive calls between the tag signing software and hardware, and to send scalar multiplication operation requests. Because the tag signing software can adapt to protocol changes, the tag signing hardware does not need to be reconfigured. This method features high computational performance, versatility, and strong scalability, and can be used in applications such as encryption servers. Subsequently, due to the implementation of various controllers on the tag hardware side, including the relationship between the number of bits of the minimum multiplier and its energy and resource consumption in the parallel computation of the KOM algorithm, serial computation of a low-power 64-bit multiplier was achieved to realize a low-power 256-bit multiplier. By extending the modular reduction algorithm of Mersenne primes, division was transformed into addition and subtraction operations, thereby greatly reducing the complexity and energy consumption of modular reduction. The modular reduction algorithm of non-extended Mersenne primes based on the Barrett algorithm used multiplication and modular reduction operations to replace the high-cost division operation to realize the modulo operation, thereby efficiently calculating the modular multiplication of any parameter and reducing register consumption. Modulo addition and subtraction operations were merged to achieve the goal of reducing power consumption and resource consumption. The fixed-window NAF scalar multiplication algorithm provides an efficient solution for calculating scalar multiplication in low-power environments that require resistance to SPA attacks, and optimizes the last point addition calculation, thereby further reducing resource and energy consumption.Finally, in response to the completion of the tag signing hardware and software operations, the dynamic fingerprint information of the signed tag is obtained. Through multiple interactions between the tag signing hardware and software operations, the respective advantages of the software and hardware can be fully utilized to improve performance, reduce the energy consumption of hardware resources, improve the accuracy and efficiency of digital signatures, shorten signing time, improve versatility and scalability, and reduce the cost of secondary development and upgrades.
[0093] Step 206: Based on the verification platform public key of the anti-counterfeiting verification platform, perform multi-level anti-counterfeiting verification on the received tag dynamic fingerprint information, the signed tag dynamic fingerprint information, and the tag-end issued certificate information to obtain the anti-counterfeiting verification result information.
[0094] In some embodiments, the aforementioned executing entity can perform multi-level anti-counterfeiting verification on the received tag dynamic fingerprint information, signed tag dynamic fingerprint information, and tag-end issuance certificate information based on the verification platform public key of the aforementioned anti-counterfeiting verification platform, to obtain anti-counterfeiting verification result information. The aforementioned multi-level anti-counterfeiting verification includes: issuance certificate verification, data integrity verification, and timeliness verification. The aforementioned tag-end issuance certificate information can be identity verification information issued by the anti-counterfeiting verification platform to verify the identity of the RFID tag storage terminal and ensure its legality and credibility. The aforementioned tag-end issuance certificate information can be obtained through the following steps: First, concatenate the tag-end public key of the RFID tag storage terminal and the string corresponding to the tag-end identification information to obtain the concatenated tag-end string. Then, input the concatenated tag-end string and the verification platform private key of the aforementioned anti-counterfeiting verification platform into the digital signature function in the SM2 algorithm to obtain the tag-end issuance certificate information. By binding the tag-end identification information and the tag-end public key, the aforementioned tag-end issuance certificate information can prevent certificate reuse and enhance anti-counterfeiting capabilities. The aforementioned anti-counterfeiting verification result information indicates whether the anti-counterfeiting verification platform has successfully verified the multi-level verification of the tag's dynamic fingerprint information stored in the RFID tag's memory. The aforementioned tag dynamic fingerprint information, the aforementioned signed tag dynamic fingerprint information, and the aforementioned tag-issued certificate information can be data sent from the aforementioned application terminal to the aforementioned anti-counterfeiting verification platform. The aforementioned anti-counterfeiting verification result information can also be information sent from the aforementioned anti-counterfeiting verification platform to the aforementioned application terminal.
[0095] In some optional implementations of certain embodiments, the above-mentioned multi-level anti-counterfeiting verification of the received tag dynamic fingerprint information, the signed tag dynamic fingerprint information, and the tag-end issued certificate information based on the verification platform public key of the anti-counterfeiting verification platform to obtain anti-counterfeiting verification result information may include the following steps:
[0096] The first step involves controlling the aforementioned anti-counterfeiting verification platform. Based on the platform's public key, the platform verifies the digital certificate information issued by the label terminal, obtaining the certificate verification result. This result indicates whether the issued certificate contains counterfeit information.
[0097] As an example, the aforementioned executing entity can input the aforementioned label-end issued certificate information and the aforementioned verification platform public key into the signature verification function SM2_Verify() in the SM2 algorithm to obtain the certificate verification result information.
[0098] The second step involves inputting the aforementioned dynamic fingerprint information of the tag into the tag fingerprint hash value generation function to obtain the dynamic fingerprint hash value. This dynamic fingerprint hash value represents the digital fingerprint of the tag's dynamic fingerprint information, mapping it to a fixed-length string. The tag fingerprint hash value generation function can be a function used to map the tag's dynamic fingerprint information to a fixed-length string of random letters and numbers. For example, the tag fingerprint hash value generation function could be the SM3 algorithm.
[0099] The third step involves verifying the hash value of the dynamic fingerprint based on the aforementioned tag public key and the signed tag dynamic fingerprint information, thus obtaining the hash value verification result. This hash value verification result indicates whether the received tag dynamic fingerprint information is complete, serving as the integrity verification information for the tag dynamic fingerprint information.
[0100] As an example, the aforementioned executing entity can input the received tag dynamic fingerprint information, tag-end public key, and signed tag dynamic fingerprint information into the signature verification function SM2_Verify() in the SM2 algorithm to obtain the hash value verification result information.
[0101] The fourth step is to determine whether the verification timestamp in the aforementioned tag dynamic fingerprint information falls within a preset timestamp window, thus obtaining timestamp verification result information. This timestamp verification result information indicates whether the verification timestamp is within the preset timestamp window. The preset timestamp window can be a pre-defined verification time range. For example, the preset timestamp window can be a window within five minutes before or after the current time.
[0102] The fifth step involves determining the certificate verification result, hash value verification result, and timestamp verification result as anti-counterfeiting verification result information. In response to the determination that all three result information indicates successful verification, a random hash value is determined from the random number in the tag's dynamic fingerprint information. This random hash value and the verification information indicating successful verification are then sent to the application terminal. The random hash value can be obtained by inputting the random number from the signature's dynamic fingerprint information into the SHA256 (Secure Hash Algorithm 256-bit) hash function.
[0103] Step 207: In response to the determination that the anti-counterfeiting verification result information indicates verification failure, trigger the alarm and perform blockchain-based counterfeiting tracking processing on the label identification information.
[0104] In some embodiments, the aforementioned executing entity may, in response to determining that the anti-counterfeiting verification result information indicates verification failure, trigger an alarm and perform blockchain-based counterfeit tracking processing on the aforementioned label identification information. The alarm may be one that provides alerts via different colors and sounds on the display screen of the application terminal. The counterfeit tracking processing may utilize blockchain technology to record and track the entire process of an item from production to distribution.
[0105] In some optional implementations of certain embodiments, before the above-mentioned response to determining that the anti-counterfeiting verification result information indicates verification failure, triggering an alarm, and performing blockchain-based counterfeiting tracking processing on the label identification information, the above-mentioned method may further include the following steps:
[0106] The first step involves, in response to the determination that the aforementioned dynamic fingerprint generation method information is encrypted fingerprint generation method information, controlling the aforementioned RFID tag storage terminal to determine the tag hash value of the aforementioned tag identification information and the verification platform public key of the aforementioned anti-counterfeiting verification platform. The aforementioned encrypted fingerprint generation method information can be fingerprint generation information implemented through an encryption / decryption algorithm. The aforementioned tag hash value can be a string obtained by mapping the aforementioned tag identification information and the aforementioned anti-counterfeiting verification platform's public key to a fixed length. In practice, the executing entity can first concatenate the string corresponding to the aforementioned tag identification information and the verification platform public key to obtain a concatenated tag anti-counterfeiting string. Then, the concatenated tag anti-counterfeiting string is input into the SM3 algorithm to obtain the tag hash value.
[0107] The second step involves generating a temporary tag key pair for the aforementioned RFID tag storage terminal. This temporary tag key pair includes a temporary tag private key and a temporary tag public key. The temporary tag key pair can be a temporary elliptic curve key pair generated for a single encryption, characterizing the randomness and uniqueness of the single encryption. In practice, the executing entity can first randomly generate a temporary random number as the temporary tag private key, where the temporary random number can be a prime number less than the order of the elliptic curve group. Then, addition and multiplication operations are performed on the temporary tag private key and the base points of the elliptic curve to obtain the temporary tag public key.
[0108] The third step involves generating an elliptic derivation key based on the aforementioned tag dynamic fingerprint information, tag hash value, and temporary tag key pair. This elliptic derivation key can be either the session key that generated the tag hash value and temporary tag key pair, or a re-encrypted key.
[0109] As an example, the aforementioned execution entity can first determine the binary representation of the bit length of the aforementioned tag dynamic fingerprint information, as the fingerprint bit binary string. Then, it concatenates the x and y coordinates of the temporary tag public key in the aforementioned temporary tag key pair with the aforementioned tag hash value to obtain the concatenated tag string. Finally, it inputs the concatenated tag string and the aforementioned fingerprint bit binary string into the key derivation function to obtain the elliptic derivation key. The aforementioned key derivation function can be, but is not limited to, one of the following: PBKDF2 (Password-Based Key Derivation Function 2), Scrypt key derivation function, and Argon2 key derivation function.
[0110] The fourth step is to perform coordinate encoding on the coordinates of the aforementioned temporary tag public key to obtain a public key encoded byte stream. This public key encoded byte stream can be obtained by converting the string of the temporary tag public key into a standardized byte stream. The coordinate encoding can be performed by concatenating the vertical and horizontal coordinates of the temporary tag public key and then encoding the resulting byte stream.
[0111] Fifth step: Based on the above elliptic derived key, encrypt the above tag dynamic fingerprint information to obtain the encrypted tag dynamic fingerprint information.
[0112] As an example, the aforementioned executing entity can perform a bitwise XOR operation on the aforementioned tag dynamic fingerprint information and the aforementioned elliptic derived key to obtain the encrypted tag dynamic fingerprint information.
[0113] Step 6: Based on the coordinates of the temporary tag public key, perform data integrity verification on the tag dynamic fingerprint information to obtain the tag verification byte stream. This tag verification byte stream characterizes whether the tag dynamic fingerprint information is complete and has not been tampered with.
[0114] As an example, the aforementioned execution entity can first concatenate the horizontal and vertical coordinates of the temporary tag public key with the string corresponding to the tag dynamic fingerprint information to obtain a concatenated key string. Then, the concatenated key string is input into the SM3 algorithm to obtain the tag verification byte stream.
[0115] Step 7: Concatenate the above public key encoded byte stream, the above tag verification byte stream, and the above encrypted tag dynamic fingerprint information to obtain a concatenated encoded byte stream.
[0116] Step 8: Send the above-mentioned tag dynamic fingerprint information and the above-mentioned spliced encoded byte stream to the above-mentioned application terminal.
[0117] Optionally, after sending the aforementioned tag dynamic fingerprint information and the aforementioned concatenated encoded byte stream to the aforementioned application terminal, the above method may further include the following steps:
[0118] The first step is to control the aforementioned application terminal to send the aforementioned tag dynamic fingerprint information and the aforementioned spliced encoded byte stream to the aforementioned anti-counterfeiting verification platform.
[0119] The second step involves controlling the anti-counterfeiting verification platform to decode the received concatenated encoded byte stream, obtaining a first decoded string, a second decoded string, and a third decoded string. The first decoded string can be a byte stream obtained by decoding the public key encoded byte stream. The second decoded string can be a byte stream obtained by decoding the tag verification byte stream. The third decoded byte stream can be a string obtained by decoding the byte stream corresponding to the encrypted tag dynamic fingerprint information. In practice, the executing entity can first extract and decode the concatenated encoded byte stream according to the coordinate encoding format of the temporary tag public key to obtain the first decoded string. Then, since the tag verification byte stream is of fixed length, a byte stream of the corresponding length of the tag verification byte stream is extracted from the concatenated encoded byte stream after removing the byte stream corresponding to the first decoded string and decoded to obtain the second decoded string. Finally, the concatenated encoded byte stream after removing the byte streams corresponding to the first and second decoded strings is decoded to obtain the third decoded string.
[0120] The third step involves determining the product of the verification platform's private key and the first decoded string, which serves as the verification coordinates. The verification platform's private key is stored in the platform's encrypted hardware component. This encrypted hardware component can be an HSM (Hardware Security Module). Storing the verification platform's private key in the encrypted hardware component prevents its plaintext export, enhancing its security and preventing interception by attackers.
[0121] Fourth, based on the aforementioned verification endpoint coordinates and tag hash value, generate a verification endpoint derived key. This derived key can be either the session key used to generate the verification endpoint coordinates and tag hash value, or a key used for further encryption.
[0122] As an example, the aforementioned execution entity can first concatenate the horizontal and vertical coordinates corresponding to the aforementioned verification coordinates with the aforementioned tag hash value to obtain a concatenated coordinate string. Then, the concatenated coordinate string and the fingerprint bit binary string corresponding to the received second decoded string are input into the key derivation function to obtain the verification-end derived key.
[0123] The fifth step is to determine the XOR operation between the above-mentioned verification end derived key and the above-mentioned second decoding string to obtain the verification end decryption information.
[0124] Step 6: Concatenate the decrypted information and coordinates from the verification end, and input them into the data integrity verification function to obtain the verification string. This verification string indicates whether the received decoded information and the sent tag dynamic fingerprint information are identical. The data integrity verification function can be used to verify the integrity and tamper-proof nature of the received tag dynamic fingerprint information. For example, the data integrity verification function could be the SM3 algorithm.
[0125] Step 7: In response to the determination that the above verification string and the above third decoding string are the same, data extraction is performed on the above verification decryption information to obtain the decrypted tag identification information, the decrypted timestamp and the decrypted random number.
[0126] Step 8: Perform multi-level verification on the decrypted tag identification information, the decrypted timestamp, and the decrypted random number to obtain a multi-level verification result information set. This multi-level verification result information set may include: verification information indicating whether the decrypted tag identification information is the same as the tag identification information stored in the RFID tag storage terminal, whether the decrypted timestamp is within a preset timestamp window, and whether the decrypted random number has been reused.
[0127] Step 9: In response to the determination that each level of verification result information in the above multi-level verification result information set represents successful verification, the above successful verification information and the above decrypted tag identification information are sent to the above application terminal.
[0128] Further reference Figure 5 As an implementation of the methods shown in the above figures, this disclosure provides some embodiments of an anti-counterfeiting verification device for goods based on a radio frequency identification anti-counterfeiting system. These device embodiments are similar to... Figure 2 Corresponding to the method embodiments shown, this product anti-counterfeiting verification device based on the radio frequency identification anti-counterfeiting system can be specifically applied to various electronic devices.
[0129] like Figure 5 As shown, an anti-counterfeiting verification device 500 based on a radio frequency identification (RFID) anti-counterfeiting system includes: a two-way authentication unit 501, a control unit 502, a first generation unit 503, a second generation unit 504, a hardware-software combined signature unit 505, a multi-level anti-counterfeiting verification unit 506, and an alarm unit 507. The two-way authentication unit 501 is configured to control the RFID tag storage terminal and the application terminal to perform two-way authentication to obtain a two-way authentication information set. The control unit 502 is configured to, in response to determining that the two-way authentication information set indicates successful verification, control the application terminal to generate a dynamic quantum random number and an anti-counterfeiting verification timestamp. The first generation unit 503 is configured to, in response to detecting that the RFID tag storage terminal receives a challenge request information sent by the application terminal, determine dynamic fingerprint generation method information. The second generation unit 504 is configured to, in response to determining that the dynamic fingerprint generation method information is signature fingerprint generation method information, generate tag dynamic fingerprint information based on the received dynamic quantum random number, the anti-counterfeiting verification timestamp, and the stored tag identification information. The hardware-software signature unit 505 is configured to: perform hardware-software signature processing on the tag dynamic fingerprint information based on the tag's private key physically stored in the RFID tag storage terminal, to obtain the signed tag dynamic fingerprint information. The multi-level anti-counterfeiting verification unit 506 is configured to: perform multi-level anti-counterfeiting verification on the received tag dynamic fingerprint information, the signed tag dynamic fingerprint information, and the tag-end issuance certificate information based on the verification platform public key of the anti-counterfeiting verification platform, to obtain anti-counterfeiting verification result information. The multi-level anti-counterfeiting verification includes: issuance certificate verification, data integrity verification, and timeliness verification. The alarm unit 507 is configured to: trigger an alarm in response to the determination that the anti-counterfeiting verification result information indicates verification failure, and perform blockchain-based counterfeiting tracking processing on the tag-end identification information.
[0130] It is understandable that the units described in the RFID-based anti-counterfeiting verification device 500 are related to the reference. Figure 1 The steps in the described method correspond to each other. Therefore, the operations, features, and beneficial effects described above for the method are also applicable to the anti-counterfeiting verification device 500 based on the radio frequency identification anti-counterfeiting system and the units contained therein, and will not be repeated here.
[0131] The following is for reference. Figure 6 It shows a schematic diagram of the structure of an electronic device (e.g., an electronic device) 600 suitable for implementing some embodiments of the present disclosure. Figure 6 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments of this disclosure.
[0132] like Figure 6 As shown, electronic device 600 may include a processing device (e.g., a central processing unit, a graphics processor, etc.) 601, which can perform various appropriate actions and processes according to a program stored in read-only memory (ROM) 602 or a program loaded from storage device 608 into random access memory (RAM) 603. RAM 603 also stores various programs and data required for the operation of electronic device 600. Processing device 601, ROM 602, and RAM 603 are interconnected via bus 604. Input / output (I / O) interface 605 is also connected to bus 604.
[0133] Typically, the following devices can be connected to I / O interface 605: input devices 606 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 607 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 608 including, for example, magnetic tapes, hard disks, etc.; and communication devices 609. Communication device 609 allows electronic device 600 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 5 An electronic device 600 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively. Figure 6 Each box shown can represent a device or multiple devices as needed.
[0134] In particular, according to some embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, some embodiments of this disclosure include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 609, or installed from a storage device 608, or installed from a ROM 602. When the computer program is executed by the processing device 601, it performs the functions defined above in the methods of some embodiments of this disclosure.
[0135] It should be noted that, in some embodiments of this disclosure, the computer-readable medium described above may be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium may be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In some embodiments of this disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In some embodiments of this disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.
[0136] In some implementations, clients and servers can communicate using any currently known or future-developed network protocol such as HTTP (Hypertext Transfer Protocol) and can interconnect with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include local area networks (“LANs”), wide area networks (“WANs”), the Internet (e.g., the Internet of Things), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed networks.
[0137] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device. The aforementioned computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to proceed to steps 201 to 207.
[0138] Computer program code for performing operations of some embodiments of this disclosure can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, and C++, and conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0139] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0140] The units described in some embodiments of this disclosure can be implemented in software or hardware. The described units can also be housed in a processor; for example, a processor may be described as including a control unit, a two-way authentication unit, a first generation unit, a second generation unit, a hardware-software combined signature unit, a multi-level anti-counterfeiting verification unit, and an alarm unit. The names of these units do not necessarily limit the specific unit; for example, two-way authentication can also be described as "a unit that controls the RFID tag storage terminal and the application terminal to perform two-way authentication to obtain a two-way authentication information set."
[0141] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: Field Programmable Gate Arrays (FPGAs), Application-Specific Integrated Circuits (ASICs), Application Standard Products (ASSPs), System-on-Chip (SoCs), Complex Programmable Logic Devices (CPLDs), and so on.
[0142] The above description is merely a selection of preferred embodiments of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of the invention involved in the embodiments of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described inventive concept. For example, technical solutions formed by substituting the above-described features with (but not limited to) technical features with similar functions disclosed in the embodiments of this disclosure.
Claims
1. A method for verifying the authenticity of goods based on a radio frequency identification (RFID) anti-counterfeiting system, comprising an RFID tag storage terminal, an application terminal, and an anti-counterfeiting verification platform: Control the RFID tag storage terminal and the application terminal to perform two-way authentication to obtain a two-way authentication information set; In response to determining that all the two-way authentication information sets represent successful authentication, the application terminal is controlled to generate dynamic quantum random numbers and anti-counterfeiting verification timestamps. In response to detecting that the RFID tag storage terminal has received a challenge request information sent by the application terminal, the dynamic fingerprint generation method information is determined; In response to determining that the dynamic fingerprint generation method information is signature fingerprint generation method information, the tag dynamic fingerprint information is generated based on the received dynamic quantum random number, anti-counterfeiting verification timestamp and stored tag end identification information; Based on the tag private key physically stored in the RFID tag storage terminal, the tag dynamic fingerprint information is subjected to a combination of hardware and software signature processing to obtain the signed tag dynamic fingerprint information. Based on the verification platform public key of the anti-counterfeiting verification platform, the received tag dynamic fingerprint information, signed tag dynamic fingerprint information and tag-end issued certificate information are subjected to multi-level anti-counterfeiting verification to obtain anti-counterfeiting verification result information. The multi-level anti-counterfeiting verification includes: issued certificate verification, data integrity verification and timeliness verification. In response to the determination that the anti-counterfeiting verification result information indicates verification failure, an alarm is triggered, and the label identification information is subjected to blockchain-based counterfeiting tracking processing.
2. The method according to claim 1, wherein, Before responding to determining that the anti-counterfeiting verification result information indicates verification failure, triggering an alarm, and performing blockchain-based counterfeiting tracking processing on the label identification information, the method further includes: In response to determining that the dynamic fingerprint generation method information is encryption / decryption fingerprint generation method information, the radio frequency identification tag storage terminal is controlled to determine the tag hash value of the tag terminal identification information and the verification platform public key of the anti-counterfeiting verification platform terminal; Generate a temporary tag key pair for the RFID tag storage terminal, wherein the temporary tag key pair includes: a temporary tag private key and a temporary tag public key; Based on the tag dynamic fingerprint information, the tag hash value, and the temporary tag key pair, an elliptic derived key is generated; The coordinates of the public key of the temporary tag are encoded to obtain a public key encoded byte stream; Based on the elliptic derived key, the tag dynamic fingerprint information is encrypted to obtain the encrypted tag dynamic fingerprint information; Based on the coordinates of the temporary tag public key, the data integrity of the tag dynamic fingerprint information is verified to obtain the tag verification byte stream; The public key encoded byte stream, the tag verification byte stream, and the encrypted tag dynamic fingerprint information are concatenated to obtain a concatenated encoded byte stream. The tag's dynamic fingerprint information and the spliced encoded byte stream are sent to the application terminal.
3. The method according to claim 2, wherein, After sending the tag dynamic fingerprint information and the concatenated encoded byte stream to the application terminal, the method further includes: Control the application terminal to send the tag dynamic fingerprint information and the spliced encoded byte stream to the anti-counterfeiting verification platform terminal; The anti-counterfeiting verification platform is controlled to decode the received spliced encoded byte stream to obtain a first decoded string, a second decoded string, and a third decoded string; The product of the verification platform private key and the first decoded string is determined as the verification platform coordinates, wherein the verification platform private key is stored in the platform encryption hardware component; Generate a derived key for the verification terminal based on the verification terminal coordinates and the tag hash value; The XOR operation between the derived key of the verification end and the second decoded string is determined to obtain the decryption information of the verification end; The decryption information and coordinates of the verification terminal are concatenated and then input into the data integrity verification function to obtain the verification terminal verification string; In response to determining that the verification string and the third decoding string are the same, data extraction is performed on the decryption information of the verification end to obtain the decrypted tag identification information, the decrypted timestamp and the decrypted random number; Multi-level verification is performed on the decrypted tag identification information, the decrypted timestamp, and the decrypted random number to obtain a multi-level verification result information set. In response to determining that each level of the verification result information in the multi-level verification result information set represents successful verification, the successful verification information and the decrypted tag identification information are sent to the application terminal.
4. The method according to claim 1, wherein, The method involves performing multi-level anti-counterfeiting verification on the received tag dynamic fingerprint information, signed tag dynamic fingerprint information, and tag-end issued certificate information based on the verification platform public key of the anti-counterfeiting verification platform, to obtain anti-counterfeiting verification result information, including: The anti-counterfeiting verification platform terminal is controlled to perform digital certificate verification on the certificate information issued by the label terminal according to the public key of the verification platform, and obtain certificate verification result information; The tag dynamic fingerprint information is input into the tag fingerprint hash value generation function to obtain the dynamic fingerprint hash value; Based on the tag's public key and the signed tag's dynamic fingerprint information, the hash value of the dynamic fingerprint is verified to obtain hash value verification result information; Determine whether the verification timestamp in the dynamic fingerprint information of the tag is within a preset timestamp window, and obtain timestamp verification result information; The certificate verification result information, the hash value verification result information, and the timestamp verification result information are determined as anti-counterfeiting verification result information. In response to the determination that the certificate verification result information, the hash value verification result information, and the timestamp verification result information all indicate successful verification, the random hash value of the random number in the tag dynamic fingerprint information is determined, and the random hash value and the verification information indicating successful verification are sent to the application terminal.
5. The method according to claim 1, wherein, The control of the RFID tag storage terminal and the application terminal to perform two-way authentication to obtain a two-way authentication information set includes: Control the RFID tag storage terminal to generate the tag elliptic curve private key and the tag elliptic curve public key; The dot product of the tag elliptic curve private key and the application elliptic curve public key sent by the application terminal is determined and used as the tag shared key; The first tag verification information is obtained by performing an XOR operation on the tag shared key and the tag terminal identification information; A hash operation is performed on the tag shared key, the tag terminal identification information, and the application elliptic curve public key to obtain the second tag verification information; The anti-counterfeiting verification platform controls the dot product of the tag elliptic curve public key and the application elliptic curve private key sent by the RFID tag storage terminal, which is used as the anti-counterfeiting shared key. The anti-counterfeiting label verification information is obtained by performing an XOR operation between the first label verification information and the anti-counterfeiting shared key. Determine whether there is label identification information in the anti-counterfeiting verification platform that corresponds to the anti-counterfeiting label verification information; In response to determining that there is tag terminal identification information corresponding to the anti-counterfeiting tag verification information, a hash operation is performed on the anti-counterfeiting shared key, the tag terminal identification information and the application elliptic curve public key to obtain the third tag verification information; In response to determining that the third tag verification information is the same as the second tag verification information received by the application terminal, the information used by the RFID tag storage terminal to confirm the identity verification of the application terminal is determined as the first two-way authentication information.
6. The method according to claim 5, wherein, The method further includes: Control the application terminal to determine the tag incentive information corresponding to the tag terminal identification information; The first application verification information is obtained by performing an XOR operation on the tag identification information and the tag activation information; The second application verification information is obtained by performing an XOR operation between the anti-counterfeiting shared key and the tag incentive response information corresponding to the tag incentive information; The application terminal is controlled to determine the XOR operation between the received first application verification information and the tag terminal identification information to obtain the first application information to be verified. The first application information to be verified is input into the non-clonable function to obtain the second application information to be verified. The XOR operation between the received second application verification information and the tag shared key is used to obtain the third application verification information; In response to determining that the third application verification information and the second application information to be verified are the same, the information of the application terminal confirming the identity verification of the RFID tag storage terminal is determined as the second two-way identity verification information; The first two-way authentication information and the second two-way authentication information are determined as the two-way authentication information set.
7. A product anti-counterfeiting verification device based on a radio frequency identification (RFID) anti-counterfeiting system, comprising an RFID tag storage terminal, an application terminal, and an anti-counterfeiting verification platform terminal: The two-way authentication unit is configured to control the RFID tag storage terminal and the application terminal to perform two-way authentication to obtain a two-way authentication information set. The control unit is configured to control the application terminal to generate dynamic quantum random numbers and anti-counterfeiting verification timestamps in response to determining that all the two-way authentication information sets represent successful authentication. The first generation unit is configured to determine dynamic fingerprint generation method information in response to detecting that the RFID tag storage terminal receives challenge request information sent by the application terminal; The second generation unit is configured to generate tag dynamic fingerprint information in response to determining that the dynamic fingerprint generation method information is signature fingerprint generation method information, based on the received dynamic quantum random number, anti-counterfeiting verification timestamp and stored tag end identification information; The hardware-software signature unit is configured to perform hardware-software signature processing on the tag dynamic fingerprint information based on the tag private key physically stored at the RFID tag storage terminal, to obtain the signed tag dynamic fingerprint information. The multi-level anti-counterfeiting verification unit is configured to perform multi-level anti-counterfeiting verification on the received tag dynamic fingerprint information, signed tag dynamic fingerprint information and tag-end issued certificate information based on the verification platform public key of the anti-counterfeiting verification platform, and obtain anti-counterfeiting verification result information. The multi-level anti-counterfeiting verification includes: issued certificate verification, data integrity verification and timeliness verification. The alarm unit is configured to trigger an alarm in response to determining that the anti-counterfeiting verification result information indicates verification failure, and to perform blockchain-based counterfeiting tracking processing on the label identification information.
8. An electronic device, comprising: One or more processors; Storage device, on which one or more programs are stored, When the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in any one of claims 1-6.
9. A computer-readable medium having a computer program stored thereon, wherein, When the computer program is executed by a processor, it implements the method as described in any one of claims 1-6.