Method, device and system for the production of electronic tags
By embedding the tag root key in the reader and performing secure authentication with the authentication UKey, the problems of increased production overhead and leakage caused by traditional key data writing methods are solved, achieving the dual effects of cost reduction and key security.
Patent Information
- Application Number
- CN202511319031.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-16
- Publication Date
- 2026-01-27
- Estimated Expiration
- 2045-09-16
AI Technical Summary
Traditional key data writing methods increase production overhead and may lead to key data interception on the channel, resulting in leakage.
The tag root key is embedded in the security chip in the reader. External security authentication is performed between the reader and the authentication UKey. The tag root key is used to distribute the dispersion factor to generate the tag key. The key is written inside the reader to avoid the key being transmitted over the network channel.
It reduces production costs, ensures key security, prevents key data from being stolen on the channel, and enhances the control over tag keys.
Smart Images

Figure CN120822535B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of wireless communication technology, and more specifically to a method for producing electronic tags, an apparatus for producing electronic tags, a system for producing electronic tags, a machine-readable storage medium, and a computer program product. Background Technology
[0002] RFID stands for Radio Frequency Identification. RFID electronic tags use chips to store electronic identification codes and other application information, and can communicate wirelessly via RFID readers. Currently, RFID electronic tags are widely used in shopping, logistics, and other fields, providing great convenience to our lives and work. Some application areas of tags have high security requirements. For example, RFID electronic tags installed on power grid equipment require that the data stored in the tag cannot be illegally tampered with. Therefore, based on traditional RFID electronic tags, electronic tags integrating national cryptographic algorithms have been developed. Currently, the production model for electronic tags with national cryptographic algorithms involves the customer providing a cryptographic machine, which is then given to a professional tag manufacturer. The manufacturer uses the cryptographic machine to calculate the tag key and writes it into the electronic tag.
[0003] In the use of electronic tags integrating national cryptographic algorithms, readers need to use the corresponding key and national cryptographic algorithm for authentication. Only after successful authentication can they gain read and write permissions to the data in the tag. Therefore, the key data in the tag becomes crucial to ensuring the security of electronic tag data. Although the tag's key data cannot be read after production and packaging, providing security at the storage level, the traditional method of writing key data involves the production host computer software obtaining the key from the server and then distributing it to the electronic tag reader (hereinafter referred to as the reader), which then writes it into the electronic tag. This production model increases production costs and is also susceptible to key data interception at the channel, leading to leakage. Summary of the Invention
[0004] The purpose of this invention is to provide a method, apparatus and system for producing electronic tags, in order to solve the problem that traditional key data writing methods not only increase production costs, but also may result in key data being intercepted on the channel and causing leakage.
[0005] To achieve the above objectives, embodiments of the present invention provide a method for producing electronic tags, comprising:
[0006] The first security chip in the reader that controls the electronic tag performs external security authentication with the authentication UKey, so that the reader can obtain the right to use the tag root key in the first security chip;
[0007] The first device is controlled to send a write command to the reader; the write command carries the dispersion factor of the electronic tag;
[0008] The reader is controlled to distribute the dispersion factor using the tag root key to obtain the tag key of the electronic tag;
[0009] The reader is controlled to write the tag key into the electronic tag.
[0010] Optionally, the first security chip in the reader controlling the electronic tag performs external security authentication with the authentication UKey, including:
[0011] The system controls the first security chip and the authentication UKey to perform external security authentication based on a random number and the attribute identifier of the first security chip.
[0012] Optionally, the random number includes a first random number generated by the reader and a second random number generated by the authentication UKey; the step of controlling the first security chip and the authentication UKey to perform external security authentication based on the random number and the attribute identifier of the first security chip includes:
[0013] The first device is controlled to send a first random number and the attribute identifier of the first security chip to the second device;
[0014] The control device sends the first random number and the attribute identifier to the authentication UKey;
[0015] The authentication UKey is controlled to combine the second random number and the first random number to obtain a first fused random number;
[0016] The authentication UKey is controlled to distribute the attribute identifier using a first preset key to obtain an authentication key;
[0017] The authentication UKey is controlled to encrypt the first fused random number using the authentication key to obtain the first encrypted data;
[0018] The second device is controlled to send the first encrypted data to the first device;
[0019] Control the first device to send the first encrypted data to the reader;
[0020] The first security chip is controlled to decrypt the first encrypted data using the authentication key to obtain a first decryption result;
[0021] If the comparison result between the first decryption result and the first fused random number indicates that they have the same first random number, the first security chip and the authentication UKey complete external security authentication.
[0022] Optionally, controlling the reader to distribute the dispersion factor using the tag root key to obtain the tag key of the electronic tag includes:
[0023] The first security chip is controlled to decrypt the tag root key using the tag root key protection key to obtain the tag root key decryption result;
[0024] The first security chip is controlled to use the decryption result of the tag root key to disperse the dispersion factor, thereby obtaining the tag key of the electronic tag.
[0025] Optionally, the method further includes:
[0026] The reader and the updated UKey establish a session; the updated UKey carries the updated tag root key.
[0027] The updated UKey is controlled to send the updated tag root key to the first security chip of the reader using the session key, so that the first security chip can complete the update of the tag root key ciphertext.
[0028] Optionally, the update tag root key in the update UKey is updated through the following steps:
[0029] The cryptographic master station and the updated UKey are controlled to perform security authentication so that the cryptographic master station and the updated UKey generate the same session key respectively;
[0030] The control UKey issuance program sends an update tag root key acquisition command to the cryptographic machine master station;
[0031] The master station of the cryptographic machine is controlled to respond to the instruction to obtain the updated tag root key, encrypt the updated tag root key using the session key, obtain the updated tag root key ciphertext, and send the updated tag root key ciphertext to the UKey issuing program;
[0032] The control system sends the updated tag root key ciphertext to the updated UKey;
[0033] The system controls the update UKey to decrypt the ciphertext of the update tag root key based on the session key to obtain the update tag root key, and then updates the tag root key based on the update tag root key.
[0034] Optionally, the control cryptographic master station and the updated UKey perform security authentication to ensure that the cryptographic master station and the updated UKey generate the same session key, including:
[0035] The control UKey issuance procedure sends a third random number and the manufacturer identifier of the electronic tag to the cryptographic machine master station; the third random number is generated based on the updated UKey.
[0036] The cryptographic machine master station is controlled to combine the fourth random number and the third random number to obtain the second fused random number; the fourth random number is generated based on the cryptographic machine master station.
[0037] The master station of the cryptographic machine is controlled to distribute the manufacturer's identifier based on a second preset key to obtain a first communication key;
[0038] The system controls the cryptographic machine master station to encrypt the second fused random number based on the first communication key to obtain second encrypted data, and sends the second encrypted data to the UKey issuing program.
[0039] The control unit sends the second encrypted data to the updated UKey;
[0040] The updated UKey is controlled to decrypt the second encrypted data using the first communication key to obtain a second decryption result;
[0041] If the comparison result between the second decryption result and the second fused random number indicates that they have the same third random number, the control UKey issuing program sends the fourth random number in the second decryption result and the manufacturer identifier to the cryptographic machine master station.
[0042] If the comparison result between the fourth random number in the second decryption result and the fourth random number generated by the cryptographic master station indicates that they are the same, control the cryptographic master station and the updated UKey to generate the same session key respectively.
[0043] Optionally, controlling the update UKey to send the update tag root key to the reader's first security chip using a session key, so that the first security chip completes the update of the tag root key ciphertext, includes:
[0044] The updated UKey is controlled to distribute the attribute identifiers of the first security chip to obtain the third encrypted data;
[0045] The update UKey is controlled to encrypt the update tag root key using the third encrypted data to obtain the target update tag root key ciphertext;
[0046] The update UKey is controlled to encrypt the target update tag root key ciphertext using the session key to obtain the target update tag root key second ciphertext, and the target update tag root key second ciphertext is sent to the first security chip of the reader;
[0047] The first security chip is controlled to decrypt the second ciphertext of the target update tag root key using the session key to obtain the ciphertext of the update tag root key, and to update the tag root key ciphertext based on the ciphertext of the update tag root key.
[0048] On the other hand, embodiments of the present invention also provide an electronic tag production apparatus, comprising:
[0049] The first control module is used to control the first security chip in the electronic tag reader to perform external security authentication with the authentication UKey, so that the reader can obtain the right to use the tag root key in the first security chip;
[0050] The second control module is used to control the first device to send a write command to the reader; the write command carries the dispersion factor of the electronic tag;
[0051] The third control module is used to control the reader to disperse the dispersion factor using the tag root key to obtain the tag key of the electronic tag;
[0052] The fourth control module is used to control the reader to write the tag key into the electronic tag.
[0053] Optionally, the first security chip in the reader controlling the electronic tag performs external security authentication with the authentication UKey, including:
[0054] The system controls the first security chip and the authentication UKey to perform external security authentication based on a random number and the attribute identifier of the first security chip.
[0055] Optionally, the random number includes a first random number generated by the reader and a second random number generated by the authentication UKey; the step of controlling the first security chip and the authentication UKey to perform external security authentication based on the random number and the attribute identifier of the first security chip includes:
[0056] The first device is controlled to send a first random number and the attribute identifier of the first security chip to the second device;
[0057] The control device sends the first random number and the attribute identifier to the authentication UKey;
[0058] The authentication UKey is controlled to combine the second random number and the first random number to obtain a first fused random number;
[0059] The authentication UKey is controlled to distribute the attribute identifier of the first security chip using a first set key to obtain an authentication key;
[0060] The authentication UKey is controlled to encrypt the first fused random number using the authentication key to obtain the first encrypted data;
[0061] The second device is controlled to send the first encrypted data to the first device;
[0062] Control the first device to send the first encrypted data to the reader;
[0063] The first security chip is controlled to decrypt the first encrypted data using the authentication key to obtain a first decryption result;
[0064] If the comparison result between the first decryption result and the first fused random number indicates that they have the same first random number, the first security chip and the authentication UKey complete external security authentication.
[0065] Optionally, controlling the reader to distribute the dispersion factor using the tag root key to obtain the tag key of the electronic tag includes:
[0066] The first security chip is controlled to decrypt the tag root key using the tag root key protection key to obtain the tag root key decryption result;
[0067] The first security chip is controlled to use the decryption result of the tag root key to disperse the dispersion factor, thereby obtaining the tag key of the electronic tag.
[0068] Optionally, the device further includes:
[0069] The fifth control module is used to control the reader and the update UKey to establish a session; the update UKey carries the update tag root key; and controls the update UKey to send the update tag root key to the first security chip of the reader using the session key, so that the first security chip can complete the update of the tag root key ciphertext.
[0070] Optionally, the update tag root key in the update UKey is updated through the following steps:
[0071] The cryptographic master station and the updated UKey are controlled to perform security authentication so that the cryptographic master station and the updated UKey generate the same session key respectively;
[0072] The control UKey issuance program sends an update tag root key acquisition command to the cryptographic machine master station;
[0073] The master station of the cryptographic machine is controlled to respond to the instruction to obtain the updated tag root key, encrypt the updated tag root key using the session key, obtain the updated tag root key ciphertext, and send the updated tag root key ciphertext to the UKey issuing program;
[0074] The control system sends the updated tag root key ciphertext to the updated UKey;
[0075] The system controls the update UKey to decrypt the ciphertext of the update tag root key based on the session key to obtain the update tag root key, and then updates the tag root key based on the update tag root key.
[0076] Optionally, the control cryptographic master station and the updated UKey perform security authentication to ensure that the cryptographic master station and the updated UKey generate the same session key, including:
[0077] The control UKey issuance procedure sends a third random number and the manufacturer identifier of the electronic tag to the cryptographic machine master station; the third random number is generated based on the updated UKey.
[0078] The cryptographic machine master station is controlled to combine the fourth random number and the third random number to obtain the second fused random number; the fourth random number is generated based on the cryptographic machine master station.
[0079] The master station of the cryptographic machine is controlled to distribute the manufacturer's identifier based on a second preset key to obtain a first communication key;
[0080] The system controls the cryptographic machine master station to encrypt the second fused random number based on the first communication key to obtain second encrypted data, and sends the second encrypted data to the UKey issuing program.
[0081] The control unit sends the second encrypted data to the updated UKey;
[0082] The updated UKey is controlled to decrypt the second encrypted data using the first communication key to obtain a second decryption result;
[0083] If the comparison result between the second decryption result and the second fused random number indicates that they have the same third random number, the control UKey issuing program sends the fourth random number in the second decryption result and the manufacturer identifier to the cryptographic machine master station.
[0084] If the comparison result between the fourth random number in the second decryption result and the fourth random number generated by the cryptographic master station indicates that they are the same, control the cryptographic master station and the updated UKey to generate the same session key respectively.
[0085] Optionally, controlling the update UKey to send the update tag root key to the reader's first security chip using a session key, so that the first security chip completes the update of the tag root key ciphertext, includes:
[0086] The updated UKey is controlled to distribute the attribute identifiers of the first security chip to obtain the third encrypted data;
[0087] The update UKey is controlled to encrypt the update tag root key using the third encrypted data to obtain the target update tag root key ciphertext;
[0088] The update UKey is controlled to encrypt the target update tag root key ciphertext using the session key to obtain the target update tag root key second ciphertext, and the target update tag root key second ciphertext is sent to the first security chip of the reader;
[0089] The first security chip is controlled to decrypt the second ciphertext of the target update tag root key using the session key to obtain the ciphertext of the update tag root key, and to update the tag root key ciphertext based on the ciphertext of the update tag root key.
[0090] On the other hand, the present invention also provides an electronic tag production system, comprising: a first device, an electronic tag reader electrically connected to the first device, a second device communicatively connected to the first device, an authentication UKey electrically connected to the second device, and an electronic tag communicatively connected to the reader;
[0091] The authentication UKey is used to perform external security authentication with the first security chip in the reader, so that the reader can obtain the right to use the tag root key in the first security chip.
[0092] The first device is used to send a write command to the reader; the write command carries the dispersion factor of the electronic tag;
[0093] The reader is used to disperse the dispersion factor using the tag root key to obtain the tag key of the electronic tag; and to write the tag key into the electronic tag.
[0094] On the other hand, the present invention also provides a machine-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the above-described method for producing electronic tags.
[0095] On the other hand, the present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method for producing electronic tags.
[0096] Through the above technical solution, this invention embeds the tag root key within the reader. This method reduces the cost of cryptographic machines deployed by customers at tag manufacturers, lowering production expenses. Furthermore, by embedding the tag root key within the security chip of the reader, the calculation and filling of the tag key occur entirely within the reader. Production software no longer participates in the key calculation process, ensuring the security of the tag key and preventing its interception over physical channels. Thus, this invention solves the problem that traditional key data writing methods increase production costs and are susceptible to interception and leakage over channels.
[0097] Other features and advantages of the embodiments of the present invention will be described in detail in the following detailed description section. Attached Figure Description
[0098] The accompanying drawings are provided to further illustrate embodiments of the present invention and form part of the specification. They are used together with the following detailed description to explain the embodiments of the present invention, but do not constitute a limitation thereof. In the drawings:
[0099] Figure 1 This is a flowchart illustrating the production method of the electronic tag provided by the present invention;
[0100] Figure 2 This is a schematic diagram of the key filling method in the existing approach;
[0101] Figure 3 This is a schematic diagram of the structure of the reader provided by the present invention;
[0102] Figure 4 This is a schematic diagram of the key filling method provided by the present invention;
[0103] Figure 5 This is a schematic diagram of the structure of the authentication UKey provided by the present invention;
[0104] Figure 6 This is a schematic diagram of the key update method provided by the present invention;
[0105] Figure 7 This is a schematic diagram of the electronic tag production device provided by the present invention;
[0106] Figure 8 This is a schematic diagram of the electronic tag production system provided by the present invention. Detailed Implementation
[0107] The specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are for illustration and explanation only and are not intended to limit the scope of the present invention.
[0108] Key filling modes in existing methods, such as Figure 2 As shown:
[0109] The production software (or production host computer software) runs on computer equipment in the production workshop, which can be connected to the reader via USB. The computer equipment in the production workshop is connected to the production encryption machine in the production data room via a local area network. The existing RFID electronic tag key filling process is as follows:
[0110] 1. The production software controls the reader to read dispersion factors (such as the tag's TID code or other information codes associated with the tag) from the RFID electronic tag.
[0111] 2. The production software sends the dispersion factor to the production cryptographic machine via the network. The production cryptographic machine then distributes the tag key from the tag root key stored in it and returns it to the production software.
[0112] 3. The production software sends a write command to the reader and sends the tag key as write data to the reader.
[0113] 4. The reader writes the tag key into the key storage area of the RFID electronic tag.
[0114] 5. Repeat steps 1-4 for the production of the next electronic tag.
[0115] The internal structure of the reader is as follows: Figure 3 As shown, the reader consists of an MCU unit, a security chip, and an RF module. The MCU unit is the control core of the reader, responsible for communication with the host computer software and controlling other modules within the reader. The security chip performs national cryptographic calculations, providing this capability during national cryptographic authentication with the tag. The security chip also has its own key storage function. The RF module is used for wireless communication with the RFID tag.
[0116] It is evident that traditional key data writing methods not only increase production costs but also pose a risk of key data interception during transmission, leading to key data leakage. Therefore, embodiments of the present invention provide a method, apparatus, and system for producing electronic tags to address the problems of increased production costs and potential key data interception during transmission, resulting in leakage, associated with traditional key data writing methods.
[0117] Method Implementation Examples
[0118] Please refer to Figure 1This invention provides a method for producing electronic tags, comprising:
[0119] Step 100: Control the first security chip in the reader of the electronic tag to perform external security authentication with the authentication UKey, so that the reader can obtain the right to use the tag root key in the first security chip.
[0120] The electronic tag production method of the present invention is applied to an electronic tag production system. Please refer to... Figure 4 The electronic tag production system includes a first device, an electronic tag reader electrically connected to the first device, a second device communicatively connected to the first device, an authentication UKey electrically connected to the second device, and electronic tags (RFID) communicatively connected to the reader. In one embodiment, the first device may be a computer device located in the production workshop. Production software is deployed in the computer device in the production workshop. The second device may be a computer device located in the production data room. UKey service software is deployed in the computer device in the production data room. It should be noted that the authentication UKey and the first security chip in the reader can be issued once at the customer's location; the customer does not need to provide a password machine to the tag manufacturer. Furthermore, the installation location of the existing security chip in the tag reader does not require changing the physical structure of the reader. Please refer to... Figure 5 The authentication UKey includes a security chip and an MCU unit that performs national cryptographic calculations with the security chip. The authentication UKey communicates with the UKey service software. It should be noted that the UKey in this embodiment is divided into an authentication UKey and an update UKey. The authentication UKey is used to authenticate with the security chip in the reader and enable key usage permissions; the update UKey is used to update the tag root key in the reader.
[0121] When the production workshop needs to execute a production task, the UKey management personnel (workshop production managers) connect the authentication UKey to the second device via USB. Production workers open the production software, controlling the communication between the production software of the first device and the UKey service software of the second device. They also control the first security chip in the reader to perform external security authentication with the authentication UKey, enabling the reader to obtain access to the tag root key in the security chip. This access is maintained until production ends (when the reader is powered off).
[0122] Step 200: Control the first device to send a write command to the reader.
[0123] In the tag key filling process, production workers control the first device via production software to send a write command to the reader. The write command carries the dispersion factor of the electronic tag. The dispersion factor can be a unique identifier for the electronic tag. For example, the dispersion factor can be the tag TID or other serial number that uniquely identifies the tag. In one embodiment, when the production host computer software fills the electronic tag with a key, it only needs to send a write command to the reader via the production host computer software of the first device, passing the tag's dispersion factor (unique identifier, such as the tag TID or other serial number that uniquely identifies the tag) as a parameter to the reader. A complete write command includes at least the factors shown in Table 1:
[0124] Table 1
[0125]
[0126] After receiving a write command, the reader performs rule judgment. If the command code is determined to be a write command, the storage area is the tag key storage area, and the offset address is the offset of the key in the storage area, it is determined that a key data writing operation for the electronic tag is currently being performed. The reader then sends a dispersion factor to the first security chip.
[0127] Step 300: Control the reader to disperse the dispersion factor using the tag root key to obtain the tag key of the electronic tag.
[0128] Given the dispersion factor of the electronic tag, the reader internally calls (utilizes) the tag root key to disperse the dispersion factor, thereby obtaining the tag key of the electronic tag.
[0129] Step 400: Control the reader to write the tag key into the electronic tag.
[0130] Finally, the reader is controlled to write the tag key into the electronic tag. In this embodiment of the invention, the tag root key is stored inside the reader's first security chip. During the key filling process, the production host computer software controls the reader to perform external security authentication with the authentication UKey, enabling the reader to obtain access to the tag root key in the security chip. Then, the tag key is filled offline within the reader, eliminating the need for the tag key data to be transmitted over a network channel. This ensures secure key writing and reduces the cost of deploying a cryptographic machine in the production data room. In other words, by embedding the tag root key inside the tag reader, while leaving the production cryptographic machine at the customer's location, the production cost of RFID tags is reduced. Because the tag's root key is embedded inside the reader, the tag's key does not need to be transmitted over a network channel during production, ensuring the key data security and preventing eavesdropping. This embodiment of the invention manages the access rights to the root key through the authentication UKey; if the reader is lost, it cannot be used normally. The method of this embodiment of the invention reduces production costs, prevents key data eavesdropping, and enhances the control over the use of tag keys.
[0131] This invention embeds the tag root key within the reader, reducing the cost of cryptographic machines deployed by customers at tag manufacturers and lowering production expenses. Furthermore, by embedding the tag root key within the reader's security chip, the calculation and filling of the tag key occur entirely within the reader. Production software is no longer involved in the key calculation process, ensuring the tag key's security and making it difficult to intercept over physical channels. Therefore, this invention solves the problems of traditional key data writing methods, which increase production costs and are susceptible to key data interception and leakage over channels.
[0132] In other aspects of the embodiments of the present invention, step 100, controlling the first security chip in the reader of the electronic tag to perform external security authentication with the authentication UKey, includes: controlling the first security chip and the authentication UKey to perform external security authentication based on a random number and the attribute identifier of the first security chip.
[0133] In one embodiment, the attribute identifier can be the attribute identifier information of the first security chip, such as the production serial number of the first security chip. This embodiment of the invention uses the production serial number of the first security chip as an example for explanation. This embodiment of the invention controls the first security chip and the authentication UKey to perform external security authentication based on a random number and the attribute identifier of the first security chip, thereby allowing the reader to obtain usage rights to the tag root key in the first security chip.
[0134] In one embodiment, the random number includes a first random number generated by the reader and a second random number generated by the authentication UKey; controlling the first security chip and the authentication UKey to perform external security authentication based on the random number and the attribute identifier of the first security chip includes: controlling the first device to send the first random number and the attribute identifier of the first security chip to a second device; controlling the second device to send the first random number and the attribute identifier of the first security chip to the authentication UKey; controlling the authentication UKey to combine the second random number and the first random number to obtain a first fused random number; controlling the authentication UKey to use a first set key to disperse the attribute identifier of the first security chip to obtain an authentication key; controlling the authentication UKey to use the authentication key to encrypt the first fused random number to obtain first encrypted data; controlling the second device to send the first encrypted data to the first device; controlling the first device to send the first encrypted data to the reader; controlling the first security chip to use the authentication key to decrypt the first encrypted data to obtain a first decryption result; if the comparison result between the first decryption result and the first fused random number indicates that they have the same first random number, the first security chip and the authentication UKey complete the external security authentication.
[0135] Specifically, the UKey management personnel connect the authentication UKey to the USB port of the computer device deploying the UKey service software in the production data room. Then, after the production host computer software on the first device starts, it first calls the reader interface to obtain a random number Rr (i.e., the first random number) from the security chip in the reader, and sends the production serial number of the first security chip and the random number Rr to the UKey service software on the second device deployed in the production data room. Subsequently, the UKey service software on the second device sends the production serial number of the first security chip and the random number Rr to the authentication UKey. The authentication UKey then generates a random number Ru (the second random number) and combines the random numbers Rr and Ru into RrRu (i.e., the first fused random number). The authentication UKey then calls the first set key KeyAuthU to distribute the production serial number of the first security chip to obtain an authentication key KeyAuthUR that matches the security chip in the reader. The authentication UKey then uses the authentication key KeyAuthUR to encrypt RrRu to obtain Re (i.e., the first encrypted data). It should be noted that the purpose of the random number Ru (the second random number) here is to generate different Re values even for the same random number Rr (i.e., the first random number), ensuring that this process is difficult to crack. The UKey service software of the second device then returns Re (the first encrypted data) to the production host computer software of the first device. The production host computer software of the first device receives Re and sends it to the reader. The reader sends Re to the first security chip. The first security chip decrypts Re using the authentication key KeyAuthUR to obtain RrRu, compares it with Rr, completes authentication, and grants access to the tag root key. This access remains open until the reader loses power.
[0136] It should be noted that the authentication key is obtained by distributing the KeyAuth from the cryptographic machine to the manufacturer identifier (e.g., manufacturer code) of the electronic tag, ensuring that each manufacturer's KeyAuthU is unique. Then, the KeyAuthU is further distributed using the serial number of the security chip in each reader to obtain KeyAuthUR, ensuring that each reader's security chip's KeyAuthUR is unique. The KeyAuthU in the authentication UKey is used for external authentication with the KeyAuthUR in the reader chip. Only after successful authentication can the reader obtain access to the tag root key KeyTRootEn. In this embodiment, KeyTRootEn from the cryptographic machine is installed into the security chip of the updated UKey and the reader, and used as the root key of the tag key. The tag root key installed in the reader's security chip is encrypted with the same encryption key as KeyDeUR. When installing this key into the reader's security chip, the access permission for this key must be set to "enabled by authentication key," meaning that external authentication with the chip's authentication key KeyAuthUR is required before the reader can obtain access to this key.
[0137] Therefore, this embodiment of the invention uses a reader in conjunction with an authentication UKey. The authentication UKey is kept by production control personnel. Without "external authentication" between the authentication key in the UKey and the authentication key in the reader, the reader cannot use the tag root key in the first security chip. This effectively protects the use of the tag root key, ensuring key security; even if the reader is lost, it cannot be used. This embodiment of the invention stores the tag root key in encrypted form, further ensuring key security.
[0138] In other aspects of the embodiments of the present invention, step 300, controlling the reader to disperse the dispersion factor using the tag root key to obtain the tag key of the electronic tag, includes: controlling the first security chip to decrypt the tag root key using the tag root key protection key to obtain the tag root key decryption result; controlling the first security chip to disperse the dispersion factor using the tag root key decryption result to obtain the tag key of the electronic tag.
[0139] Since the tag root key of the first security chip in the reader is encrypted key ciphertext, the first security chip first decrypts the tag root key KeyTRootEn using the tag root key protection key KeyDeUR to generate the tag root key decryption result KeyTRoot. Then, it uses the tag root key decryption result KeyTRoot to distribute the data by a dispersion factor, obtaining the tag key KeyT corresponding to the current electronic tag, which is returned to the reader. The reader obtains the tag key KeyT and writes it into the electronic tag via an radio frequency signal.
[0140] It should be noted that the tag root key protection key is obtained by distributing the KeyP in the cryptographic machine to the manufacturer identifier of the electronic tag (e.g., manufacturer code) to obtain KeyEnU, ensuring that each manufacturer's KeyEnU is unique. Then, KeyEnU is further distributed using the chip serial number in each reader to obtain the tag root key protection key KeyDeUR, ensuring that the KeyDeUR in each reader's security chip is unique. When updating KeyTRoot to the security chip in the reader, the serial number of the security chip in the reader is first distributed using KeyEnU to generate an encryption key consistent with KeyDeUR. This KeyTRoot is then encrypted to generate the tag root key KeyTRootEn, which is then updated into the reader's security chip.
[0141] As can be seen from the above tag key calculation and filling operations, an authentication UKey distributed to a tag manufacturer can control all readers also distributed to that manufacturer, and devices from different manufacturers cannot be used interchangeably. However, when filling electronic tags with keys, the calculation and writing operations of the tag key are performed on the reader side; the production host computer software no longer participates in the calculation process, thus achieving secure protection of the tag key.
[0142] In other aspects of this invention, after step 400, the method further includes: controlling the reader and the update UKey to establish a session; the update UKey carrying an update tag root key; controlling the update UKey to send the update tag root key to the first security chip of the reader using the session key, so that the first security chip completes the update of the tag root key ciphertext.
[0143] When producing electronic tags with different key types, or when key changes (corresponding to different types of electronic tags or key iterations), the tag root key KeyTRootEn in the reader needs to be updated. In the customer's production environment, an updated UKey is obtained by updating the tag root key in the initial UKey. This requires the customer to bring the updated UKey with the new tag key KeyTRootEn to the production data room, and then use the updated UKey to update the KeyTRootEn of the security chip in the manufacturer's reader. Please refer to [link / reference]. Figure 6 When it is necessary to update the tag key of the security chip in the reader, the UKey management personnel (customer's management personnel) bring the update UKey to the production data room and connect the update UKey to a second device in the production data room via USB. The UKey service software is then opened to control the update UKey to establish a session with the reader and to use the session key to update the new tag root key into the reader's security chip.
[0144] In one embodiment, the update tag root key in the update UKey is updated through the following steps: controlling the cryptographic master station and the update UKey to perform security authentication so that the cryptographic master station and the update UKey generate the same session key respectively; controlling the UKey issuing program to send an update tag root key acquisition instruction to the cryptographic master station; controlling the cryptographic master station to respond to the update tag root key acquisition instruction, encrypting the update tag root key using the session key to obtain the update tag root key ciphertext, and sending the update tag root key ciphertext to the UKey issuing program; controlling the UKey issuing program to send the update tag root key ciphertext to the update UKey; controlling the update UKey to decrypt the update tag root key ciphertext based on the session key to obtain the update tag root key, and updating the tag root key based on the update tag root key.
[0145] Specifically, in this embodiment of the invention, the cryptographic master station and the updated UKey can perform security authentication based on random numbers and the manufacturer's identifier (e.g., manufacturer code) of the electronic tag, so that the cryptographic master station and the updated UKey generate the same session key. Then, the UKey issuing program sends an update tag root key acquisition command to the cryptographic master station to obtain the manufacturer's identifier and a new tag key KeyTRoot. The cryptographic master station matches the session key KeyS with the manufacturer's identifier and encrypts the new KeyTRoot with the session key KeyS, obtaining the updated tag root key ciphertext, which is sent to the UKey issuing program. The UKey issuing program sends the updated tag root key ciphertext to the updated UKey. The updated UKey decrypts the updated tag root key ciphertext with the session key KeyS to obtain the updated tag root key, and updates the tag root key based on the updated tag root key to obtain the updated UKey. Thus, this embodiment of the invention, through the use of a reader and a UKey, meets the production needs of different types of electronic tags or the needs of key iteration.
[0146] In other aspects of the embodiments of the present invention, controlling the cryptographic master station and the updated UKey to perform security authentication so that the cryptographic master station and the updated UKey respectively generate the same session key includes: controlling the UKey issuance program to send a third random number and the manufacturer identifier of the electronic tag to the cryptographic master station; the third random number is generated based on the updated UKey; controlling the cryptographic master station to combine a fourth random number and the third random number to obtain a second fused random number; the fourth random number is generated based on the cryptographic master station; controlling the cryptographic master station to distribute the manufacturer identifier based on a second set key to obtain a first communication key; controlling the cryptographic master station to encrypt the second fused random number based on the first communication key to obtain second encrypted data. The system then sends the second encrypted data to the UKey issuing program; controls the UKey issuing program to send the second encrypted data to the updated UKey; controls the updated UKey to decrypt the second encrypted data using the first communication key to obtain a second decryption result; if the comparison result of the second decryption result and the second fused random number indicates that they have the same third random number, the system controls the UKey issuing program to send the fourth random number in the second decryption result and the manufacturer identifier to the cryptographic machine master station; if the comparison result of the fourth random number in the second decryption result and the fourth random number generated by the cryptographic machine master station indicates that they are the same, the system controls the cryptographic machine master station and the updated UKey to generate the same session key respectively.
[0147] Specifically, in the customer's production environment, the updated UKey is connected to the customer's computer equipment. The customer's computer equipment runs the UKey issuance program, which connects to the updated UKey and the cryptographic master station. The UKey issuance program obtains a random number Ru (i.e., the third random number) from the updated UKey and sends it to the cryptographic master station along with the manufacturer's identifier (e.g., manufacturer code) from the electronic tag. The cryptographic master station obtains a random number Rm (i.e., the fourth random number) from the cryptographic machine and combines the random numbers Ru and Rm into RuRm (i.e., the second fused random number). The cryptographic master station uses the second set key KeySURoot to disperse the manufacturer's identifier and obtain the first communication key KeySU. It then encrypts RuRm using the first communication key KeySU to obtain Re (the second encrypted data) and returns Re to the UKey issuance program. The UKey issuance program obtains Re and sends it to the updated UKey. The second security chip inside the updated UKey decrypts Re using the first communication key KeySU to obtain RuRm and compares it with Ru. The UKey issuance program then sends Rm (the fourth random number) and the manufacturer's identifier to the cryptographic master station. After the master cryptographic station obtains Rm, it compares Rm with the master's data and confirms that they match. At this point, both parties have completed authentication and simultaneously possess Ru (the third random number) and Rm (the fourth random number). Both parties can then generate the same session key KeyS based on Ru, Rm, and any pre-agreed rules.
[0148] It should be noted that the first communication key, KeySU, is the session key between the cryptographic machine and the updated UKey. The first communication key, KeySU, is obtained by distributing the manufacturer identifier (e.g., manufacturer code) of the electronic tag through KeySURoot in the cryptographic machine, ensuring that each manufacturer's KeySU is unique. The first communication key, KeySU, is used to establish a session with KeySURoot in the cryptographic machine. After the session is established, KeyTRoot in the UKey can be updated using a temporary session key.
[0149] This invention uses a cryptographic master station in conjunction with an authentication UKey to ensure the security of the authentication UKey during the key update process.
[0150] In other aspects of the embodiments of the present invention, controlling the update UKey to send the update tag root key to the first security chip of the reader using a session key, so that the first security chip completes the update of the tag root key ciphertext, includes: controlling the update UKey to distribute the attribute identifier of the first security chip to obtain third encrypted data; controlling the update UKey to encrypt the update tag root key using the third encrypted data to obtain target update tag root key ciphertext; controlling the update UKey to encrypt the target update tag root key ciphertext using the session key to obtain target update tag root key second ciphertext, and sending the target update tag root key second ciphertext to the first security chip of the reader; controlling the first security chip to decrypt the target update tag root key second ciphertext using the session key to obtain update tag root key ciphertext, and updating the tag root key ciphertext based on the update tag root key ciphertext.
[0151] Specifically, after the tag root key in the initial UKey is updated, an updated UKey is obtained. The customer takes the updated UKey to the tag manufacturer's production data room. A session is established between the updated UKey and the first security chip in the reader using UKey service software, for example, through a second communication key (KeySR and KeySRR). The session creation process refers to the security authentication process between the cryptographic master station and the updated UKey described above. After the session is established, the attribute identifier (production serial number) of the first security chip in the reader is distributed using KeyEU to obtain third encrypted data consistent with the tag root key protection key KeyDeUR. The updated UKey is then controlled to encrypt the new tag key KeyTRoot using the third encrypted data to obtain the target updated tag root key ciphertext. The update UKey is controlled to encrypt the target update tag root key ciphertext using the session key KeyS to obtain the target update tag root key second ciphertext, and then the target update tag root key second ciphertext is sent to the first security chip in the reader. The first security chip in the reader decrypts the target update tag root key second ciphertext using the session key to obtain the update tag root key ciphertext, and updates the tag root key ciphertext based on the update tag root key ciphertext.
[0152] It should be noted that the second communication key (KeySR and KeySRR) is the session key between the updated UKey and the reader. KeySR is obtained by distributing the KeySRRoot in the cryptographic machine to the manufacturer identifier (e.g., manufacturer code) of the electronic tag, ensuring that each manufacturer's KeySR is unique. Then, KeySRR is obtained by further distributing the KeySR to the chip serial number in each reader, ensuring that the KeySRR of the security chip in each reader is unique. The reader's KeySRR is used to establish a session with the KeySR in the updated UKey. After the session is established, the KeyTRoot in the UKey can be updated to the reader using a temporary session key. This embodiment of the invention implements the updating of the tag key in the reader of the electronic tag using the updated UKey.
[0153] In summary, the authentication UKey contains one key, KeyAuthU. The update UKey contains four keys: KeySU, KeySR, KeyEU, and KeyTRoot. The reader contains four keys: KeySRR, KeyTRootEn, KeyDeUR, and KeyAuthUR. The correspondence between these keys is shown in Table 2 below.
[0154] Table 2
[0155]
[0156] The production of electronic tags in this embodiment of the invention operates on a production intranet, resulting in a relatively simple design that eliminates the need for monitoring systems such as certificate verification systems. The security authentication process, session establishment process, and session keys are all encrypted using the SM1 national cryptographic algorithm, and the decryption result is influenced by random numbers, making it difficult to crack. Furthermore, the reader is used in conjunction with a UKey, and the authentication UKey is kept by production management personnel. Without "external authentication" between the authentication key in the UKey and the authentication key in the reader, the reader cannot use the tag root key in the security chip, effectively protecting the use of the root key; even if the reader is lost, it cannot be used. Additionally, storing the tag root key in encrypted form further ensures key security. When a key update is needed, the customer brings the update UKey to the manufacturer to update the key in the reader's security chip. The issuance of both the UKey and the security chip in the reader is first-level distributed using the tag manufacturer's vendor code, thus preventing cross-contamination between production equipment from multiple manufacturers. The tag production environment in this embodiment of the invention does not require the deployment of a production cryptographic machine; the cryptographic machine is only retained in the customer's production environment. Furthermore, compared to traditional tag production methods, this method eliminates the need for the tag key or other encrypted data to be transmitted over physical channels. It only requires obtaining the tag key within the reader and writing it into the electronic tag. This reduces production costs and enhances data security.
[0157] Device Examples
[0158] Please refer to Figure 7 On the other hand, embodiments of the present invention also provide an electronic tag production apparatus, comprising:
[0159] The first control module 701 is used to control the first security chip in the reader of the electronic tag to perform external security authentication with the authentication UKey, so that the reader can obtain the right to use the tag root key in the first security chip;
[0160] The second control module 702 is used to control the first device to send a write command to the reader; the write command carries the dispersion factor of the electronic tag;
[0161] The third control module 703 is used to control the reader to disperse the dispersion factor using the tag root key to obtain the tag key of the electronic tag;
[0162] The fourth control module 704 is used to control the reader to write the tag key into the electronic tag.
[0163] This invention embeds the tag root key within the reader, reducing the cost of cryptographic machines deployed by customers at tag manufacturers and lowering production expenses. Furthermore, by embedding the tag root key within the reader's security chip, the calculation and filling of the tag key occur entirely within the reader. Production software is no longer involved in the key calculation process, ensuring the tag key's security and making it difficult to intercept over physical channels. Therefore, this invention solves the problems of traditional key data writing methods, which increase production costs and are susceptible to key data interception and leakage over channels.
[0164] Optionally, the first security chip in the reader controlling the electronic tag performs external security authentication with the authentication UKey, including:
[0165] The system controls the first security chip and the authentication UKey to perform external security authentication based on a random number and the attribute identifier of the first security chip.
[0166] Optionally, the random number includes a first random number generated by the reader and a second random number generated by the authentication UKey; the step of controlling the first security chip and the authentication UKey to perform external security authentication based on the random number and the attribute identifier of the first security chip includes:
[0167] The first device is controlled to send a first random number and the attribute identifier of the first security chip to the second device;
[0168] The control device sends the first random number and the attribute identifier to the authentication UKey;
[0169] The authentication UKey is controlled to combine the second random number and the first random number to obtain a first fused random number;
[0170] The authentication UKey is controlled to distribute the attribute identifiers of the first security chip using a first preset key to obtain an authentication key;
[0171] The authentication UKey is controlled to encrypt the first fused random number using the authentication key to obtain the first encrypted data;
[0172] The second device is controlled to send the first encrypted data to the first device;
[0173] Control the first device to send the first encrypted data to the reader;
[0174] The first security chip is controlled to decrypt the first encrypted data using the authentication key to obtain a first decryption result;
[0175] If the comparison result between the first decryption result and the first fused random number indicates that they have the same first random number, the first security chip and the authentication UKey complete external security authentication.
[0176] Optionally, controlling the reader to distribute the dispersion factor using the tag root key to obtain the tag key of the electronic tag includes:
[0177] The first security chip is controlled to decrypt the tag root key using the tag root key protection key to obtain the tag root key decryption result;
[0178] The first security chip is controlled to use the decryption result of the tag root key to disperse the dispersion factor, thereby obtaining the tag key of the electronic tag.
[0179] Optionally, the device further includes:
[0180] The fifth control module is used to control the reader and the update UKey to establish a session; the update UKey carries the update tag root key; and controls the update UKey to send the update tag root key to the first security chip of the reader using the session key, so that the first security chip can complete the update of the tag root key ciphertext.
[0181] Optionally, the update tag root key in the update UKey is updated through the following steps:
[0182] The cryptographic master station and the updated UKey are controlled to perform security authentication so that the cryptographic master station and the updated UKey generate the same session key respectively;
[0183] The control UKey issuance program sends an update tag root key acquisition command to the cryptographic machine master station;
[0184] The master station of the cryptographic machine is controlled to respond to the instruction to obtain the updated tag root key, encrypt the updated tag root key using the session key, obtain the updated tag root key ciphertext, and send the updated tag root key ciphertext to the UKey issuing program;
[0185] The control system sends the updated tag root key ciphertext to the updated UKey;
[0186] The system controls the update UKey to decrypt the ciphertext of the update tag root key based on the session key to obtain the update tag root key, and then updates the tag root key based on the update tag root key.
[0187] Optionally, the control cryptographic master station and the updated UKey perform security authentication to ensure that the cryptographic master station and the updated UKey generate the same session key, including:
[0188] The control UKey issuance procedure sends a third random number and the manufacturer identifier of the electronic tag to the cryptographic machine master station; the third random number is generated based on the updated UKey.
[0189] The cryptographic machine master station is controlled to combine the fourth random number and the third random number to obtain the second fused random number; the fourth random number is generated based on the cryptographic machine master station.
[0190] The master station of the cryptographic machine is controlled to distribute the manufacturer's identifier based on a second preset key to obtain a first communication key;
[0191] The system controls the cryptographic machine master station to encrypt the second fused random number based on the first communication key to obtain second encrypted data, and sends the second encrypted data to the UKey issuing program.
[0192] The control unit sends the second encrypted data to the updated UKey;
[0193] The updated UKey is controlled to decrypt the second encrypted data using the first communication key to obtain a second decryption result;
[0194] If the comparison result between the second decryption result and the second fused random number indicates that they have the same third random number, the control UKey issuing program sends the fourth random number in the second decryption result and the manufacturer identifier to the cryptographic machine master station.
[0195] If the comparison result between the fourth random number in the second decryption result and the fourth random number generated by the cryptographic master station indicates that they are the same, control the cryptographic master station and the updated UKey to generate the same session key respectively.
[0196] Optionally, controlling the update UKey to send the update tag root key to the reader's first security chip using a session key, so that the first security chip completes the update of the tag root key ciphertext, includes:
[0197] The updated UKey is controlled to distribute the attribute identifiers of the first security chip to obtain the third encrypted data;
[0198] The update UKey is controlled to encrypt the update tag root key using the third encrypted data to obtain the target update tag root key ciphertext;
[0199] The update UKey is controlled to encrypt the target update tag root key ciphertext using the session key to obtain the target update tag root key second ciphertext, and the target update tag root key second ciphertext is sent to the first security chip of the reader;
[0200] The first security chip is controlled to decrypt the second ciphertext of the target update tag root key using the session key to obtain the ciphertext of the update tag root key, and to update the tag root key ciphertext based on the ciphertext of the update tag root key.
[0201] The electronic tag production device includes a processor and a memory. The first control module 701, the second control module 702, the third control module 703 and the fourth control module 704 are all stored in the memory as program units. The processor executes the program units stored in the memory to realize the corresponding functions.
[0202] A processor contains a kernel, which retrieves the corresponding program units from memory. One or more kernels can be configured.
[0203] The memory may include non-permanent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.
[0204] On the other hand, please refer to Figure 8The present invention also provides an electronic tag production system, comprising: a first device 10, an electronic tag reader 20 electrically connected to the first device 10, a second device 30 communicatively connected to the first device 10, an authentication UKey 40 electrically connected to the second device 30, and an electronic tag 50 communicatively connected to the reader 20. The authentication UKey 40 is used for external security authentication with a first security chip in the reader 20, enabling the reader 20 to obtain access to the tag root key in the first security chip. The first device 10 is used to send a write command to the reader 20; the write command carries a dispersion factor of the electronic tag 50. The reader 20 is used to disperse the dispersion factor using the tag root key to obtain a tag key for the electronic tag 50; and to write the tag key into the electronic tag 50.
[0205] Before tag production, the security chip in the reader 20 is first externally authenticated via the authentication UKey40, granting the reader 20 access to the tag root key within the security chip. During the tag key filling process, only a write command and a scatter factor need to be sent to the reader 20. The reader 20 internally calls the tag root key to scatter and obtain the tag key, which is then filled into the RFID electronic tag 50. The implementation details of the external security authentication process of the security chip in the reader 20 via the authentication UKey40 and the tag key filling process can be found in the relevant descriptions in the above method embodiments, and will not be repeated here.
[0206] If the key in reader 20 needs to be updated, the key in the UKey is first updated in the customer's production environment. The customer brings the updated UKey to the production data room, and a session key is established between reader 20 and UKey through the UKey service software to update the new key into the security chip of reader 20. The implementation details of the tag key update process of the security chip of reader 20 can be found in the relevant descriptions in the above method embodiments, and will not be repeated here.
[0207] This invention embeds the tag root key within the reader 20. This method reduces the cost of cryptographic machines deployed by customers at tag manufacturers, lowering production expenses. Furthermore, by embedding the tag root key within the security chip of the reader 20, the calculation and filling of the tag key occur entirely within the reader 20. Production software is no longer involved in the key calculation process, ensuring the tag key's security and preventing its interception over physical channels. Therefore, this invention solves the problems of traditional key data writing methods, which increase production costs and are susceptible to key data interception and leakage over channels.
[0208] On the other hand, the present invention also provides a computer program product, the computer program product including a computer program that can be stored on a machine-readable storage medium. When the computer program is executed by a processor, the computer is able to execute a method for producing an electronic tag. The method includes: controlling a first security chip in a reader of the electronic tag to perform external security authentication with an authentication UKey, so that the reader obtains the right to use the tag root key in the first security chip; controlling a first device to send a write instruction to the reader; the write instruction carrying a dispersion factor of the electronic tag; controlling the reader to disperse the dispersion factor using the tag root key to obtain a tag key of the electronic tag; and controlling the reader to write the tag key into the electronic tag.
[0209] In another aspect, the present invention also provides a machine-readable storage medium storing a computer program thereon, which, when executed by a processor, implements a method for producing an electronic tag. The method includes: controlling a first security chip in a reader of the electronic tag to perform external security authentication with an authentication UKey, so that the reader obtains access to a tag root key in the first security chip; controlling a first device to send a write instruction to the reader; the write instruction carrying a dispersion factor of the electronic tag; controlling the reader to disperse the dispersion factor using the tag root key to obtain a tag key for the electronic tag; and controlling the reader to write the tag key into the electronic tag.
[0210] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0211] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0212] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for producing an electronic tag, characterized in that, include: The first security chip in the reader that controls the electronic tag performs external security authentication with the authentication UKey, so that the reader can obtain the right to use the tag root key in the first security chip; Control the first device to send a write command to the reader; The write instruction carries the dispersion factor of the electronic tag; The reader is controlled to distribute the dispersion factor using the tag root key to obtain the tag key of the electronic tag; The reader is controlled to write the tag key into the electronic tag; The first security chip in the reader controlling the electronic tag performs external security authentication with the authentication UKey, including: The first security chip and the authentication UKey are controlled to perform external security authentication based on random numbers and the attribute identifier of the first security chip; The random number includes a first random number generated by the reader and a second random number generated by the authentication UKey; the step of controlling the first security chip and the authentication UKey to perform external security authentication based on the random number and the attribute identifier of the first security chip includes: The first device is controlled to send a first random number and the attribute identifier of the first security chip to the second device; The control device sends the first random number and the attribute identifier to the authentication UKey; The authentication UKey is controlled to combine the second random number and the first random number to obtain a first fused random number; The authentication UKey is controlled to distribute the attribute identifier using a first preset key to obtain an authentication key; The authentication UKey is controlled to encrypt the first fused random number using the authentication key to obtain the first encrypted data; The second device is controlled to send the first encrypted data to the first device; Control the first device to send the first encrypted data to the reader; The first security chip is controlled to decrypt the first encrypted data using the authentication key to obtain a first decryption result; If the comparison result between the first decryption result and the first fused random number indicates that they have the same first random number, the first security chip and the authentication UKey complete external security authentication.
2. The method for producing electronic tags according to claim 1, characterized in that, The process of controlling the reader to distribute the dispersion factor using the tag root key to obtain the tag key of the electronic tag includes: The first security chip is controlled to decrypt the tag root key using the tag root key protection key to obtain the tag root key decryption result; The first security chip is controlled to use the decryption result of the tag root key to disperse the dispersion factor, thereby obtaining the tag key of the electronic tag.
3. The method for producing electronic tags according to claim 1, characterized in that, The method further includes: The reader and the updated UKey establish a session; the updated UKey carries the updated tag root key. The updated UKey is controlled to send the updated tag root key to the first security chip of the reader using the session key, so that the first security chip can complete the update of the tag root key ciphertext.
4. The method for producing an electronic tag according to claim 3, characterized in that, The updated tag root key in the updated UKey is updated through the following steps: The cryptographic master station and the updated UKey are controlled to perform security authentication so that the cryptographic master station and the updated UKey generate the same session key respectively; The control UKey issuance program sends an update tag root key acquisition command to the cryptographic machine master station; The master station of the cryptographic machine is controlled to respond to the instruction to obtain the updated tag root key, encrypt the updated tag root key using the session key, obtain the updated tag root key ciphertext, and send the updated tag root key ciphertext to the UKey issuing program; The control system sends the updated tag root key ciphertext to the updated UKey; The system controls the update UKey to decrypt the ciphertext of the update tag root key based on the session key to obtain the update tag root key, and then updates the tag root key based on the update tag root key.
5. The method for producing an electronic tag according to claim 4, characterized in that, The control cryptographic master station and the updated UKey perform security authentication to ensure that the cryptographic master station and the updated UKey generate the same session key, including: The control UKey issuance procedure sends a third random number and the manufacturer identifier of the electronic tag to the cryptographic machine master station; the third random number is generated based on the updated UKey. The cryptographic machine master station is controlled to combine the fourth random number and the third random number to obtain the second fused random number; the fourth random number is generated based on the cryptographic machine master station. The master station of the cryptographic machine is controlled to distribute the manufacturer's identifier based on a second preset key to obtain a first communication key; The system controls the cryptographic machine master station to encrypt the second fused random number based on the first communication key to obtain second encrypted data, and sends the second encrypted data to the UKey issuing program. The control unit sends the second encrypted data to the updated UKey; The updated UKey is controlled to decrypt the second encrypted data using the first communication key to obtain a second decryption result; If the comparison result between the second decryption result and the second fused random number indicates that they have the same third random number, the control UKey issuing program sends the fourth random number in the second decryption result and the manufacturer identifier to the cryptographic machine master station. If the comparison result between the fourth random number in the second decryption result and the fourth random number generated by the cryptographic master station indicates that they are the same, control the cryptographic master station and the updated UKey to generate the same session key respectively.
6. The method for producing an electronic tag according to claim 3, characterized in that, The control of the updated UKey to send the updated tag root key to the reader's first security chip using a session key, so that the first security chip completes the update of the tag root key ciphertext, includes: The updated UKey is controlled to distribute the attribute identifiers of the first security chip to obtain the third encrypted data; The update UKey is controlled to encrypt the update tag root key using the third encrypted data to obtain the target update tag root key ciphertext; The update UKey is controlled to encrypt the target update tag root key ciphertext using the session key to obtain the target update tag root key second ciphertext, and the target update tag root key second ciphertext is sent to the first security chip of the reader; The first security chip is controlled to decrypt the second ciphertext of the target update tag root key using the session key to obtain the ciphertext of the update tag root key, and to update the tag root key ciphertext based on the ciphertext of the update tag root key.
7. An electronic tag production apparatus, characterized in that, include: The first control module is used to control the first security chip in the electronic tag reader to perform external security authentication with the authentication UKey, so that the reader can obtain the right to use the tag root key in the first security chip; The second control module is used to control the first device to send write commands to the reader; The write instruction carries the dispersion factor of the electronic tag; The third control module is used to control the reader to disperse the dispersion factor using the tag root key to obtain the tag key of the electronic tag; The fourth control module is used to control the reader to write the tag key into the electronic tag; The first security chip in the reader controlling the electronic tag performs external security authentication with the authentication UKey, including: The first security chip and the authentication UKey are controlled to perform external security authentication based on random numbers and the attribute identifier of the first security chip; The random number includes a first random number generated by the reader and a second random number generated by the authentication UKey; the step of controlling the first security chip and the authentication UKey to perform external security authentication based on the random number and the attribute identifier of the first security chip includes: The first device is controlled to send a first random number and the attribute identifier of the first security chip to the second device; The control device sends the first random number and the attribute identifier to the authentication UKey; The authentication UKey is controlled to combine the second random number and the first random number to obtain a first fused random number; The authentication UKey is controlled to distribute the attribute identifier using a first preset key to obtain an authentication key; The authentication UKey is controlled to encrypt the first fused random number using the authentication key to obtain the first encrypted data; The second device is controlled to send the first encrypted data to the first device; Control the first device to send the first encrypted data to the reader; The first security chip is controlled to decrypt the first encrypted data using the authentication key to obtain a first decryption result; If the comparison result between the first decryption result and the first fused random number indicates that they have the same first random number, the first security chip and the authentication UKey complete external security authentication.
8. The electronic tag production apparatus according to claim 7, characterized in that, The process of controlling the reader to distribute the dispersion factor using the tag root key to obtain the tag key of the electronic tag includes: The first security chip is controlled to decrypt the tag root key using the tag root key protection key to obtain the tag root key decryption result; The first security chip is controlled to use the decryption result of the tag root key to disperse the dispersion factor, thereby obtaining the tag key of the electronic tag.
9. The electronic tag production apparatus according to claim 8, characterized in that, The device further includes: The fifth control module is used to control the reader and the update UKey to establish a session; the update UKey carries the update tag root key; and controls the update UKey to send the update tag root key to the first security chip of the reader using the session key, so that the first security chip can complete the update of the tag root key ciphertext.
10. The electronic tag production apparatus according to claim 9, characterized in that, The updated tag root key in the updated UKey is updated through the following steps: The cryptographic master station and the updated UKey are controlled to perform security authentication so that the cryptographic master station and the updated UKey generate the same session key respectively; The control UKey issuance program sends an update tag root key acquisition command to the cryptographic machine master station; The master station of the cryptographic machine is controlled to respond to the instruction to obtain the updated tag root key, encrypt the updated tag root key using the session key, obtain the updated tag root key ciphertext, and send the updated tag root key ciphertext to the UKey issuing program; The control system sends the updated tag root key ciphertext to the updated UKey; The system controls the update UKey to decrypt the ciphertext of the update tag root key based on the session key to obtain the update tag root key, and then updates the tag root key based on the update tag root key.
11. The electronic tag production apparatus according to claim 10, characterized in that, The control cryptographic master station and the updated UKey perform security authentication to ensure that the cryptographic master station and the updated UKey generate the same session key, including: The control UKey issuance procedure sends a third random number and the manufacturer identifier of the electronic tag to the cryptographic machine master station; the third random number is generated based on the updated UKey. The cryptographic machine master station is controlled to combine the fourth random number and the third random number to obtain the second fused random number; the fourth random number is generated based on the cryptographic machine master station. The master station of the cryptographic machine is controlled to distribute the manufacturer's identifier based on a second preset key to obtain a first communication key; The system controls the cryptographic machine master station to encrypt the second fused random number based on the first communication key to obtain second encrypted data, and sends the second encrypted data to the UKey issuing program. The control unit sends the second encrypted data to the updated UKey; The updated UKey is controlled to decrypt the second encrypted data using the first communication key to obtain a second decryption result; If the comparison result between the second decryption result and the second fused random number indicates that they have the same third random number, the control UKey issuing program sends the fourth random number in the second decryption result and the manufacturer identifier to the cryptographic machine master station. If the comparison result between the fourth random number in the second decryption result and the fourth random number generated by the cryptographic master station indicates that they are the same, control the cryptographic master station and the updated UKey to generate the same session key respectively.
12. The electronic tag production apparatus according to claim 9, characterized in that, The control of the updated UKey to send the updated tag root key to the reader's first security chip using a session key, so that the first security chip completes the update of the tag root key ciphertext, includes: The updated UKey is controlled to distribute the attribute identifiers of the first security chip to obtain the third encrypted data; The update UKey is controlled to encrypt the update tag root key using the third encrypted data to obtain the target update tag root key ciphertext; The update UKey is controlled to encrypt the target update tag root key ciphertext using the session key to obtain the target update tag root key second ciphertext, and the target update tag root key second ciphertext is sent to the first security chip of the reader; The first security chip is controlled to decrypt the second ciphertext of the target update tag root key using the session key to obtain the ciphertext of the update tag root key, and to update the tag root key ciphertext based on the ciphertext of the update tag root key.
13. An electronic tag production system, characterized in that, include: A first device, a reader for an electronic tag electrically connected to the first device, a second device communicatively connected to the first device, an authentication UKey electrically connected to the second device, and an electronic tag communicatively connected to the reader; The authentication UKey is used to perform external security authentication with the first security chip in the reader, so that the reader can obtain the right to use the tag root key in the first security chip. The first device is used to send write commands to the reader; The write instruction carries the dispersion factor of the electronic tag; The reader is used to distribute the dispersion factor using the tag root key to obtain the tag key of the electronic tag; And writing the tag key into the electronic tag; The first security chip in the reader performs external security authentication with the authentication UKey, including: The first security chip and the authentication UKey are controlled to perform external security authentication based on random numbers and the attribute identifier of the first security chip; The random number includes a first random number generated by the reader and a second random number generated by the authentication UKey; the step of controlling the first security chip and the authentication UKey to perform external security authentication based on the random number and the attribute identifier of the first security chip includes: The first device is controlled to send a first random number and the attribute identifier of the first security chip to the second device; The control device sends the first random number and the attribute identifier to the authentication UKey; The authentication UKey is controlled to combine the second random number and the first random number to obtain a first fused random number; The authentication UKey is controlled to distribute the attribute identifier using a first preset key to obtain an authentication key; The authentication UKey is controlled to encrypt the first fused random number using the authentication key to obtain the first encrypted data; The second device is controlled to send the first encrypted data to the first device; Control the first device to send the first encrypted data to the reader; The first security chip is controlled to decrypt the first encrypted data using the authentication key to obtain a first decryption result; If the comparison result between the first decryption result and the first fused random number indicates that they have the same first random number, the first security chip and the authentication UKey complete external security authentication.
14. A machine-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method for producing electronic tags according to any one of claims 1 to 6.
15. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method for producing electronic tags according to any one of claims 1 to 6.
Citation Information
Patent Citations
Secret key management method of NFC (Near Field Communication) tag
CN114423006A
Authentication method, client and system based on dual quantum random number protection
CN117955708A