RFID tag security protection method and system fusing encryption and identity authentication

By generating dynamic trust tokens, synchronizing real-time status, and using data completion algorithms, the problem of untimely updates to information verification status in the supply chain is solved, achieving the integrity and continuity of the information chain and improving the security and collaboration efficiency of the supply chain.

CN120856466BActive Publication Date: 2025-12-09GUO WANG ZHE JIANG SHENG DIAN LI YOU XIAN GONG SI HANG ZHOU SHI XIAO SHAN QU GONG DIAN GONG SI +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202511333770.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-18
Publication Date
2025-12-09
Estimated Expiration
2045-09-18

AI Technical Summary

Technical Problem

In a dynamic environment of multi-party collaboration, how to ensure the integrity and continuity of information links, especially the problem of information verification status not being updated in a timely manner due to frequent switching of participants in the supply chain, leading to information transmission interruptions.

Method used

By generating temporary trust tokens with dynamic validity periods, the system monitors node status in real time for state synchronization, identifies interrupted nodes and generates repair links to bypass them, uses a data completion algorithm to generate completion values ​​for missing data, and identifies and suspends the authentication operation of nodes that fail authentication until they pass the verification.

Benefits of technology

By building flexible trust mechanisms and data repair methods, the continuity of information verification and the integrity of the chain are ensured, thereby improving the security and smoothness of the supply chain and enhancing the system's fault tolerance and self-repair capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120856466B_ABST
    Figure CN120856466B_ABST
Patent Text Reader

Abstract

The application discloses a kind of fusion encryption, RFID tag security protection method and system of identity authentication, it is related to network information security technical field, through fusion encryption, identity authentication mechanism, the dynamic trust token of third party node is generated by combining behavior data and interaction log, real-time monitoring node state to carry out state synchronization, also proposed to the repair of interrupted link, data completion and node checking scheme, using the scheme of the present application can construct flexible trust mechanism and data repair means, ensure the continuity of information verification and the integrity of link, realize the dynamic authority control of third party node, guarantee the integrity and real-time of data, enhance the fault tolerance and self-repairing ability of system, to improve the overall security of supply chain, operational efficiency and collaboration smoothness, meet the complex and changeable supply chain dynamic management needs.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network information security, and in particular to an RFID tag security protection method and system integrating encryption and identity authentication. BACKGROUND

[0002] In supply chain management, label technology plays a crucial role as an important tool for connecting multi-party collaboration, especially in ensuring information security and data traceability. With the complexity of supply chain networks, especially in scenarios involving multi-level distribution, how to ensure the continuity and security of information transmission has become a difficult problem that the industry needs to overcome.

[0003] Multiple subjects are involved in the supply chain, especially when external logistics services are introduced in the distribution link. Frequent switching of participants makes the status of information verification unable to be updated in a timely manner. This out-of-sync state can further cause information to be interrupted in the transmission link, making it impossible for subsequent links to obtain complete data support, thereby affecting the smoothness of the entire collaboration process.

[0004] Traditional methods often rely on a single protection method, lacking the ability to adapt to dynamic environmental changes. In particular, in multi-party involved distribution links, information synchronization and trust establishment often fail, resulting in low collaboration efficiency or even interruption. Existing technologies have obvious shortcomings in ensuring information security and collaboration efficiency. SUMMARY

[0005] The technical problem to be solved by the present application is how to ensure the integrity and reliability of the information link in a dynamic environment of multi-party collaboration. The present application provides an RFID tag security protection method and system integrating encryption and identity authentication, which can build a flexible trust mechanism and data repair method to ensure the continuity of information verification and the integrity of the link.

[0006] To solve the above technical problems, the present application provides an RFID tag security protection method integrating encryption and identity authentication, comprising:

[0007] When a third-party node requests an RFID read-write operation through an authentication node, the behavior data of the authentication node and the interaction log between the third-party node and the authentication node are obtained, and a dynamically valid temporary trust token is generated for the third-party node according to the behavior data and the interaction log;

[0008] Compare the real-time state information between each authentication node and third-party node, filter out unsynchronized nodes, and obtain a node consistency score according to the real-time state information. If the node consistency score is less than a preset consistency score threshold, perform state synchronization through multicast;

[0009] When the unsynchronized node is identified, the communication state of each node with its neighbor node is detected, the interrupt node is identified, the repair link bypassing the interrupt node is generated combined with the link topology and the historical transmission path, and the data transmission is performed by using the repair link;

[0010] The gap data of the interrupt node is acquired, the complement value of the gap data is generated by using a data complement algorithm, the gap data is interpolated and complemented according to the complement value, and the complete authentication data is obtained;

[0011] According to the complete authentication data, the authentication failure node is identified, the authentication operation of the authentication failure node is suspended, the data verification of the authentication failure node is performed until the data verification passes the preset threshold of verification times in succession, and the authentication operation of the authentication failure node is restarted.

[0012] As an improvement of the above-mentioned scheme, when the third-party node requests to perform the RFID read-write operation through the authentication node, the behavior data of the authentication node and the interaction log between the third-party node and the authentication node are acquired, and a temporary trust token with a dynamic validity period is generated for the third-party node according to the behavior data and the interaction log, including:

[0013] When the third-party node requests to perform the RFID read-write operation through the authentication node, the behavior data of the authentication node and the interaction log between the third-party node and the authentication node are acquired;

[0014] According to the behavior data, the trust credential established between the authentication nodes is extracted to obtain a trust credential feature;

[0015] According to the interaction log, a behavior feature vector of the third-party node is obtained;

[0016] The cosine similarity of the trust credential feature and the behavior feature vector is calculated to obtain a similarity value as a trust score;

[0017] According to the trust score and the trust credential, a temporary trust token with a dynamic validity period is generated for the third-party node.

[0018] As an improvement of the above-mentioned scheme, according to the trust score and the trust credential, a temporary trust token with a dynamic validity period is generated for the third-party node, including:

[0019] According to the trust credential, the authentication switching times of the authentication node within a preset time window and the historical authentication data are obtained; the historical authentication data includes a historical authentication success rate, an average response time and an abnormal behavior times;

[0020] According to the authentication switching times and the length of the preset time window, the switching frequency of the authentication node is calculated;

[0021] generating an initial temporary trust token of the authentication node according to the switching frequency and the historical authentication data; the initial temporary trust token comprising a node identifier, a validity period and an authority scope;

[0022] if the trust score is not greater than a preset trust score threshold, reducing the trust score according to a preset attenuation coefficient; the trust score being used to adjust the validity period;

[0023] generating a temporary trust token for the third-party node according to the trust score and the initial temporary trust token.

[0024] As an improvement of the above-mentioned scheme, the real-time state information of each authentication node and third-party node is compared to screen out unsynchronized nodes, and a node consistency score is obtained according to the real-time state information; if the node consistency score is less than a preset consistency score threshold, state synchronization is performed through multicast, comprising:

[0025] obtaining real-time state information of each authentication node and third-party node, screening out unsynchronized nodes according to the real-time state information, and generating a state update instruction;

[0026] sending the state update instruction to the unsynchronized nodes to obtain a state synchronization data packet; the state synchronization data packet comprising pre-change and post-change states and a synchronization timestamp;

[0027] calculating a deviation value of node interaction frequency from average interaction frequency according to the synchronization timestamp to obtain a node consistency score;

[0028] if the node consistency score is less than a preset consistency score threshold, sending the real-time state information of the unsynchronized nodes to all nodes in a network segment where the unsynchronized nodes are located through multicast.

[0029] As an improvement of the above-mentioned scheme, the obtaining of real-time state information of each authentication node and third-party node, screening out unsynchronized nodes according to the real-time state information, and generating a state update instruction, comprises:

[0030] obtaining real-time state information of each authentication node and third-party node through a heartbeat detection mechanism; the real-time state information comprising node online state, authentication capability state and load state;

[0031] if the real-time state information of the nodes interacting with each other is inconsistent, screening out unsynchronized nodes and generating a state update instruction comprising a node identifier, a state item to be updated and an update timestamp.

[0032] As an improvement of the above scheme, when the unsynchronized node is identified, the communication state of each node and its neighbor node is detected, the interrupt node is identified, the repair link bypassing the interrupt node is generated combined with the link topology and the historical transmission path, and the data transmission is performed using the repair link, comprising:

[0033] When the unsynchronized node is identified, the communication state of each node and its neighbor node is detected according to the node physical connection information and the logical communication relationship, and the node that does not receive the response message from the adjacent node within the preset time is identified as the interrupt node;

[0034] The source node and the target node of the last successful communication of the interrupt node are obtained, and the candidate path bypassing the interrupt node from the source node to the target node is generated according to the link topology;

[0035] The transmission success rate of the candidate path is calculated according to the historical transmission path;

[0036] The repair link is selected from the candidate path according to the transmission success rate;

[0037] The data transmission is performed using the repair link according to the format requirement of each node in the repair link.

[0038] As an improvement of the above scheme, the data transmission is performed using the repair link according to the format requirement of each node in the repair link, comprising:

[0039] The data encoding mode and the field definition supported by each node are read to obtain the format requirement;

[0040] The format conversion mapping table is constructed according to the format requirement;

[0041] The link connection information of the repair link is converted into standardized data recognizable by each node according to the format conversion mapping table;

[0042] The data transmission is performed using the standardized data on the repair link.

[0043] As an improvement of the above scheme, the gap data of the interrupt node is obtained, the complement value of the gap data is generated using a data complement algorithm, the gap data is interpolated and complemented according to the complement value to obtain complete authentication data, comprising:

[0044] The gap data generated during the link interruption of the interrupt node is obtained; the gap data includes numerical type fields and split type fields;

[0045] For the numerical type field, the numerical values of the previous and subsequent time points are obtained, and the first field interpolation of the missing point in the middle is calculated according to the time interval ratio;

[0046] For the type field, the number of occurrences of each type is counted, and a second initial field interpolation containing all missing field completion values is generated according to the type value with the most occurrences;

[0047] The second initial field interpolation is matched with the format requirements of the interrupt node to obtain a second field interpolation;

[0048] The gap data is interpolated and completed according to the first field interpolation and the second field interpolation to obtain complete authentication data.

[0049] As an improvement of the above scheme, according to the complete authentication data, the authentication failure node is identified, the authentication operation of the authentication failure node is suspended, data verification is performed on the authentication failure node, and the authentication operation of the authentication failure node is restarted until the data verification passes the preset verification number threshold continuously, which includes:

[0050] According to the complete authentication data, nodes with an authentication failure number greater than a preset failure number threshold are extracted as to-be-verified nodes;

[0051] The data content of the to-be-verified node is compared and verified with the original storage data, the number of failed items in the verification failure is counted, and the to-be-verified node with a number of failed items greater than a preset failure number threshold is identified as an authentication failure node;

[0052] The authentication operation of the authentication failure node is suspended;

[0053] The authentication data of the authentication failure node is obtained from the original storage data, and the authentication data is continuously sent to the authentication failure node to obtain an authentication result;

[0054] If the authentication result is passed in the continuous preset verification number threshold, the authentication operation of the authentication failure node is restarted.

[0055] The embodiment of the application also provides an RFID tag security protection system integrating encryption and identity authentication, which comprises:

[0056] A third-party authentication module is configured to, when a third-party node requests to perform an RFID read-write operation through an authentication node, acquire behavior data of the authentication node and an interaction log between the third-party node and the authentication node, and generate a temporary trust token with a dynamic validity period for the third-party node according to the behavior data and the interaction log;

[0057] The node consistency module is used to compare the real-time status information between each certified node and third-party node, filter out unsynchronized nodes, and obtain a node consistency score based on the real-time status information. If the node consistency score is less than a preset consistency score threshold, the status is synchronized through multicast.

[0058] The data synchronization module is used to detect the communication status of each node with its neighboring nodes when an unsynchronized node is detected, identify the interrupted node, and generate a repair link to bypass the interrupted node by combining the link topology and historical transmission path, and use the repair link for data transmission.

[0059] The data completion module is used to obtain the gap data of the interrupted node, generate the completion value of the gap data using a data completion algorithm, and perform interpolation to complete the gap data based on the completion value to obtain complete authentication data.

[0060] The abnormal node verification module is used to identify authentication failure nodes based on the complete authentication data, suspend the authentication operation of the authentication failure nodes, perform data verification on the authentication failure nodes until the data verification passes the preset verification number threshold consecutively, and then restart the authentication operation of the authentication failure nodes.

[0061] Compared with existing technologies, this invention discloses an RFID tag security protection method and system that integrates encryption and identity authentication. When a third-party node requests RFID read / write operations through an authentication node, it acquires the behavior data of the authentication node and the interaction logs between the third-party node and the authentication node. Based on the behavior data and the interaction logs, it generates a dynamically valid temporary trust token for the third-party node. It compares the real-time status information between each authentication node and the third-party node, filters out unsynchronized nodes, and obtains a node consistency score based on the real-time status information. If the node consistency score is less than a preset consistency score threshold, it performs state synchronization through multicast. When an unsynchronized node is encountered, the communication status of each node with its neighboring nodes is detected, the interrupted node is identified, and a repair link is generated to bypass the interrupted node by combining the link topology and historical transmission paths. Data transmission is then performed using this repair link. The missing data of the interrupted node is obtained, and a data completion algorithm is used to generate a completion value for the missing data. The missing data is then interpolated and completed based on the completion value to obtain complete authentication data. Based on the complete authentication data, the authentication failure node is identified, its authentication operation is paused, and data verification is performed on it until it passes a preset verification count threshold consecutively. Then, the authentication operation of the failed node is restarted. This embodiment of the invention enables the construction of a flexible trust mechanism and data repair methods, ensuring the continuity of information verification and the integrity of the link. Attached Figure Description

[0062] Figure 1 is a step flow diagram of a security protection method of an RFID tag integrating encryption and identity authentication provided by an embodiment of the present application.

[0063] Figure 2 is a structural diagram of a security protection system of an RFID tag integrating encryption and identity authentication provided by an embodiment of the present application. DETAILED DESCRIPTION

[0064] The technical solutions in the embodiments of the present application will be clearly and completely described with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the protection scope of the present application.

[0065] In the description and claims of the specification, it is to be understood that the terms first, second, etc. are used only for the purpose of description and are not to be construed as indicating or implying relative importance or an indicated number of technical features. They are not necessarily used to describe a sequence or a chronological order. In appropriate cases, the terms are interchangeable. Thus, features described with the term "first" can be described with the term "second" without departing from the scope of the present application.

[0066] In the supply chain management based on the RFID tag, the nodes contacting the RFID tag increase with the increase of the number of partners. For the nodes with high stability such as distributors and suppliers, they can be authenticated to become authenticated nodes, and each authenticated node can access a temporary third-party node to meet the temporary needs of logistics, warehousing and the like.

[0067] However, the current dilemma in the supply chain management is that the frequent switching of the participants cannot update the state of information verification in time. This out-of-sync state will further cause the interruption of information on the transmission link, so that the subsequent link cannot obtain complete data support, and thus affects the smoothness of the entire cooperation process.

[0068] Based on the above consideration, the embodiments of the present application provide a security protection method of an RFID tag integrating encryption and identity authentication. Please refer to Figure 1 In the present embodiment, the security protection method of the RFID tag integrating encryption and identity authentication is specifically executed through steps S1 to S5.

[0069] S1, when a third-party node requests to perform an RFID read-write operation through an authentication node, obtaining behavior data of the authentication node and an interaction log between the third-party node and the authentication node, and generating a temporary trust token with a dynamic validity period for the third-party node according to the behavior data and the interaction log.

[0070] In the embodiments of the present application, the cooperation of the third-party node is generally temporary cooperation with the authentication node, which can be directly managed by the authentication node in the supply chain without being registered as an authentication node. The verification time of the third-party node is limited by the temporary trust token, which provides the third-party node with time-limited access rights, avoiding the problem of security leakage caused by the third-party node holding verification rights for a long time.

[0071] It should be noted that by comprehensively considering the behavior data of the authentication node and the interaction log between the third-party node and the authentication node, the reliability of the authentication node and the authenticity of the third-party node can be verified, and the validity period of the temporary trust token can be further adjusted to improve the security of temporary cooperation.

[0072] S2, comparing real-time state information between each authentication node and third-party node, screening unsynchronized nodes, obtaining a node consistency score according to the real-time state information, and if the node consistency score is less than a preset consistency score threshold, performing state synchronization through multicast.

[0073] By comparing real-time state data and screening unsynchronized nodes, the problem of node state lag can be avoided, ensuring the consistency of data; further based on the consistency score dynamic multicast synchronization, the synchronization efficiency can be improved.

[0074] S3, when an unsynchronized node is identified, detecting the communication state of each node and its neighbor node, identifying an interrupted node, generating a repair link bypassing the interrupted node in combination with link topology and historical transmission path, and performing data transmission using the repair link.

[0075] It should be noted that when an unsynchronized node is identified, some authentication nodes or third-party nodes may be in an interrupted state. By identifying the interrupted node and combining link topology and historical transmission path, a repair link can be quickly generated without waiting for the interrupted node to recover, improving the fault tolerance of the system and ensuring data continuity.

[0076] S4, obtaining gap data of the interrupted node, generating a completion value of the gap data using a data completion algorithm, and interpolating and completing the gap data according to the completion value to obtain complete authentication data.

[0077] The missing of data such as authentication information during the node interruption process is prevented from causing the downstream node after the interrupted node to recover to be unable to obtain complete information by generating a complement value of the missing data by the data complement algorithm, and the data integrity is ensured.

[0078] S5, according to the complete authentication data, identifying an authentication failure node, suspending the authentication operation of the authentication failure node, performing data verification on the authentication failure node, and restarting the authentication operation of the authentication failure node until the data verification continuously passes a preset threshold of verification times.

[0079] The node that fails multiple times in authentication is risky to the whole supply chain, in the embodiment of the application, in addition to dynamically adjusting the validity period of the temporary trust token, the authentication failure node is also identified and its authentication operation is suspended to avoid its continuous output of invalid information, and the authentication state of the authentication failure node is continuously monitored until the authentication operation is restarted after the data verification continuously passes a preset threshold of verification times, thereby avoiding the contingency of the verification result and increasing the stability of the whole supply chain.

[0080] In the above scheme, by fusing encryption and identity authentication mechanism, the dynamic trust token of the third-party node is generated by combining behavior data and interaction logs, the node state is monitored in real time to perform state synchronization, and the scheme of repairing the interrupted link, data complement and node verification is also proposed, which can construct a flexible trust mechanism and data repair means, ensure the continuity of information verification and the integrity of the link, realize dynamic permission control of the third-party node, ensure the integrity and real-time of data, enhance the fault tolerance and self-repairing ability of the system, and further improve the security, operation efficiency and cooperation fluency of the whole supply chain, and meet the dynamic management needs of the complex and changeable supply chain.

[0081] As a preferred embodiment, in step S1, when the third-party node requests to perform RFID read-write operation through the authentication node, the behavior data of the authentication node and the interaction log between the third-party node and the authentication node are obtained, and a temporary trust token with a dynamic validity period is generated for the third-party node according to the behavior data and the interaction log, which is specifically executed by steps S11-S15.

[0082] S11, when the third-party node requests to perform RFID read-write operation through the authentication node, the behavior data of the authentication node and the interaction log between the third-party node and the authentication node are obtained;

[0083] S12, according to the behavior data, the trust credential established between the authentication nodes is extracted to obtain a trust credential feature;

[0084] S13, according to the interaction log, the behavior feature vector of the third-party node is obtained;

[0085] S14, calculating a cosine similarity of the trust credential feature and the behavior feature vector to obtain a similarity value as a trust score;

[0086] S15, generating a temporary trust token with a dynamic validity period for the third-party node according to the trust score and the trust credential.

[0087] In some preferred embodiments, the behavior data is data generated by the authentication node when performing authentication operations, and the behavior data includes authentication request timestamps, authentication response delays, and authentication method types. In other preferred embodiments, the behavior data further includes interaction logs between authentication nodes and between authentication nodes and third-party nodes, and the interaction logs include interaction node identifiers, interaction content summaries, and interaction result statuses.

[0088] It should be noted that the trust credential is generally issued directly by the supply chain management end, but other authentication nodes connected to the authentication node can also access their trust credentials, so the extraction of the trust credential in step S12 can be from the supply chain management end or from other authentication nodes.

[0089] In some preferred embodiments, the trust credential includes historical authentication success rates, average response times, and abnormal behavior frequencies.

[0090] Further, preferably, step S15, generating a temporary trust token with a dynamic validity period for the third-party node according to the trust score and the trust credential, includes:

[0091] According to the trust credential, obtaining authentication switching frequencies and historical authentication data of the authentication node within a preset time window; the historical authentication data includes historical authentication success rates, average response times, and abnormal behavior frequencies;

[0092] According to the authentication switching frequency and the length of the preset time window, calculating a switching frequency of the authentication node;

[0093] According to the switching frequency and the historical authentication data, generating an initial temporary trust token of the authentication node using a hash algorithm; the initial temporary trust token includes a node identifier, a validity period, and a permission range;

[0094] If the trust score is not greater than a preset trust score threshold, then the trust score is reduced according to a preset decay coefficient; the trust score is used to adjust the validity period;

[0095] According to the trust score and the initial temporary trust token, generating a temporary trust token for the third-party node.

[0096] It should be noted that the number of authentication switching of the authentication node within the preset time window can be calculated by the authentication request timestamp in the behavior data. In some preferred embodiments, when the switching frequency of the authentication node is greater than the preset switching frequency threshold, it is considered that the authentication node switches frequently, and when generating the temporary trust token of the authentication node, the validity period is shortened, and the trust value of the supply chain management end can also be adjusted to reduce the reliability.

[0097] In some preferred embodiments, the calculation of switching frequency adopts a sliding time window mechanism. The time window is set to 10 minutes, and the number of authentication switching of the node within the window is counted. If a node switches more than 5 times within 10 minutes, it is determined to be high-frequency switching. At this time, the system automatically triggers the temporary trust token generation mechanism, inputs the three trust credential values of the node and the current timestamp into the hash algorithm to generate a 256-bit token string. The validity period of the token is set to 30 minutes, and the authority range is limited to basic authentication operation to avoid the execution of high-risk operations. The trust establishment process when the third-party logistics intervenes is more complex.

[0098] Illustratively, when the third-party node requests to perform RFID read-write operation through the authentication node, the authentication request timestamp, authentication response delay and authentication mode type of the authentication node are obtained, and the interaction log between the authentication nodes is recorded, including the node identification of the interaction parties, interaction content summary and interaction result status. By analyzing the time sequence characteristics in the behavior data and the communication mode in the interaction log, the trust credentials established between the authentication nodes are extracted. The number of authentication switching of each authentication node within the preset time window is counted to obtain the switching frequency. If the switching frequency of a certain authentication node exceeds the preset threshold, the historical authentication success rate, average response time and abnormal behavior number of the node are used as input parameters to generate an initial temporary trust token with time limit by using a hash algorithm.

[0099] The behavior data feature vector of the third-party logistics node is calculated with the trust credential feature vector of the existing authentication node to obtain a similarity value as a trust score. If the trust score reaches the preset standard, the trust relationship between the third-party logistics and the authentication node is established, and the third-party logistics node identification, authentication node identification, trust score and temporary trust token are recorded in the trust relationship mapping table.

[0100] By reading the node information in the trust relationship mapping table, real-time authentication state data of the corresponding authentication node is collected, including authentication request queue length, authentication success rate and number of abnormal events, the collected authentication state data is compared with the trust score in the trust relationship mapping table, if the authentication success rate is lower than the expected value corresponding to the trust score or the number of abnormal events exceeds the preset threshold, the corresponding trust score is reduced according to the preset attenuation coefficient and the validity period of the temporary trust token is shortened, and the real-time authentication state of each authentication node is continuously monitored and recorded.

[0101] As a preferred embodiment, step S2, comparing the real-time state information between each authentication node and third-party node, screening unsynchronized nodes, obtaining node consistency score according to the real-time state information, if the node consistency score is less than the preset consistency score threshold, performing state synchronization through multicast, specifically through steps S21-S24:

[0102] S21, obtaining real-time state information of each authentication node and third-party node, screening unsynchronized nodes according to the real-time state information, and generating state update instruction;

[0103] S22, sending the state update instruction to the unsynchronized node to obtain state synchronization data packet; the state synchronization data packet includes pre-change and post-change state and synchronization timestamp;

[0104] S23, calculating the deviation value of node interaction frequency and average interaction frequency according to the synchronization timestamp to obtain node consistency score;

[0105] S24, if the node consistency score is less than the preset consistency score threshold, sending the real-time state information of the unsynchronized node to all nodes in the network segment where the unsynchronized node is located through multicast.

[0106] Further, preferably, step S21, obtaining real-time state information of each authentication node and third-party node, screening unsynchronized nodes according to the real-time state information, and generating state update instruction, includes:

[0107] Obtaining real-time state information of each authentication node and third-party node through a heartbeat detection mechanism; the real-time state information includes node online state, authentication capability state and load state;

[0108] If the real-time state information between the nodes that interact is inconsistent, then the unsynchronized nodes are screened and a state update instruction containing node identifier, state to be updated and update timestamp is generated.

[0109] In some preferred embodiments, the online status of the nodes is obtained through a heartbeat detection mechanism, each node periodically sends a heartbeat packet to the state management server, and if no heartbeat response is received for 3 consecutive times, it is marked as offline; the authentication capability state reflects the capability level of the node in processing authentication requests, which is divided into three levels of high, medium and low, and is dynamically adjusted according to the hardware configuration and current load of the node; the load state is comprehensively evaluated by monitoring the authentication request queue length and CPU usage. When comparing states, a field-by-field matching method is used, and when differences are found, an update process is immediately triggered. The generation and delivery process of the state update instruction has strict timing requirements.

[0110] Preferably, the state update instruction adopts a structured message format, including a 32-bit node identifier, an 8-bit state type code and a 64-bit timestamp. A reliable transmission protocol is used to communicate with the authentication node to ensure that the instruction is accurately delivered. After receiving the instruction, the target node performs the corresponding update operation according to the state type code: the state flag bit update directly modifies the flag variable in the memory; the trust credential update involves recalculating the authentication success rate, and the new success rate value is obtained by dividing the number of successful times in the last 100 authentications by 100; the interactive log append operation writes the change information to the persistent storage.

[0111] In some preferred embodiments, step S23 comprises:

[0112] According to the synchronization timestamp, the number of message exchanges between nodes within a unit of time is counted to obtain the node interaction frequency;

[0113] The deviation value of the node interaction frequency and the average interaction frequency is calculated, and the synchronization time difference is calculated;

[0114] According to the deviation value and the synchronization time difference, a weighted sum algorithm is used to obtain the node consistency score.

[0115] Illustratively, the interaction frequency is obtained by counting the number of message exchanges between nodes within a unit of time, the data transmission volume accumulates the number of bytes of all messages, and the interaction response time records the time interval from sending a request to receiving a response. The calculation process of the authentication state consistency score adopts a weighted sum method: first, the deviation of each node interaction frequency and the average interaction frequency of all nodes is calculated, the larger the deviation value, the more abnormal the behavior of the node; second, the synchronization time difference, i.e. the difference between the current time and the last synchronization timestamp, is calculated; finally, according to the weight ratio of 0.6 and 0.4, the normalized frequency deviation and time difference are added to obtain a consistency score between 0 and 1.

[0116] When the consistency score of a node is lower than the threshold value of 0.7, the system automatically encapsulates the complete state information of the node into a synchronization message package. The multicast mode is realized through the multicast address of the network layer, and all authenticated nodes in the same network segment can receive the message. After the receiving node parses the message package, it extracts the state information and compares it with the locally stored information to calculate the state difference value. The state difference value is obtained by normalizing the numerical difference of each state field and summing them up. When the state difference value of all related nodes is less than 0.1, it is determined that the authentication state consistency meets the requirements, and the entire synchronization process is completed, effectively avoiding authentication failure or security risks caused by unsynchronized node states.

[0117] As a preferred embodiment, in step S3, when an unsynchronized node is identified, the communication state of each node and its neighbor node is detected, the interrupted node is identified, a repair link bypassing the interrupted node is generated based on the link topology and the historical transmission path, and data transmission is performed using the repair link, which is executed through steps S31-S35:

[0118] S31, when an unsynchronized node is identified, the communication state of each node and its neighbor node is detected based on the node physical connection information and the logical communication relationship, and the node that does not receive a response message from the adjacent node within a preset time is identified as an interrupted node;

[0119] S32, the source node and the target node of the last successful communication of the interrupted node are obtained, and a candidate path bypassing the interrupted node from the source node to the target node is generated based on the link topology;

[0120] S33, the transmission success rate of the candidate path is calculated based on the historical transmission path;

[0121] S34, the repair link is selected from the candidate path based on the transmission success rate;

[0122] S35, data transmission is performed using the repair link based on the format requirements of each node in the repair link.

[0123] In the embodiment of the application, the interruption detection of the link depends on the continuous communication monitoring between nodes.

[0124] In a preferred embodiment, each authentication node maintains a neighbor node table, which records the node information directly connected thereto. The nodes confirm the connection state by periodically sending probe messages, and the probe message contains a sending timestamp and a sequence number.

[0125] Exemplarily, when node A sends a probe message to node B, if no confirmation response is received within a set timeout time, the number of failures is accumulated. After 3 consecutive probe failures, node A marks node B as unreachable. By analyzing the last successful communication record, the interruption between which two nodes can be accurately located. The acquisition and analysis of the link topology structure is the basis for repairing path planning.

[0126] In the embodiment of the present application, a global topology information library is maintained during the operation of the supply chain, which stores the unique identifier, IP address, port number of each node and the connection relationship with other nodes. When a link interruption is detected, the system reads the complete topology data and converts it into a graph structure representation, with nodes as vertices and connection relationships as edges. According to the interruption position, a depth-first search algorithm is used to traverse the graph structure, and all nodes are divided into two categories: nodes reachable from the source node are marked as reachable, and nodes that cannot be reached are marked as unreachable. This classification provides a clear search range for subsequent search for bypass paths. The evaluation of candidate paths involves statistical analysis of historical data.

[0127] When selecting a repair link in steps S33-S34, the use of each transmission path is based on the stored use, including the total number of data packets passing through the path, the number of successful arrivals at the target node, the average transmission delay and other indicators.

[0128] Exemplarily, a certain path has transmitted 1000 data packets in the past 24 hours, of which 950 have successfully arrived, so the success rate is 95%. When selecting a backup route, not only the success rate is considered, but also the path length is comprehensively evaluated. If the success rate of path A is 95% but needs to pass through 5 nodes, and the success rate of path B is 92% but only needs to pass through 3 nodes, the system will comprehensively score according to the preset weight coefficient and select the path with the highest score. The routing table updating and the execution process of link repair have strict timing requirements.

[0129] Further, preferably, step S35, according to the format requirements of each node in the repair link, uses the repair link for data transmission, including:

[0130] Reading the data encoding mode and field definition supported by each node to obtain the format requirements;

[0131] According to the format requirements, a format conversion mapping table is constructed;

[0132] According to the format conversion mapping table, the link connection information of the repair link is converted into standardized data recognizable by each node;

[0133] Using the standardized data to perform data transmission on the repair link.

[0134] Further, in some preferred embodiments, after converting the link connection information of the repair link into standardized data recognizable by each node according to the format conversion mapping table, the method further comprises:

[0135] According to the field definition in the standardized data, the matching of the data field type, length limit and nesting level is checked by comparing with the data structure specification stored by each authentication node, and the interface parameter requirements of each node are verified, to generate a structure compatibility check list; the structure compatibility check list includes matching items and non-matching items;

[0136] According to the non-matching items, the node pairs that need to be converted for security are identified, the encryption algorithm type, key length and encryption mode configured by the related nodes are read, and if the encryption modes between the nodes are inconsistent, decryption and re-encryption processing logic is inserted on the data transmission path, and the encryption conversion requirements of each node pair are recorded;

[0137] Based on the coverage of the format conversion mapping table, the matching rate of the structure compatibility check list and the number of encryption conversion requirements, the compatibility value of each node pair is calculated by weighting, and if the value exceeds the preset threshold, it is determined that the formats are compatible, otherwise the specific incompatible items are listed, and the determination results of all node pairs are summarized to form a complete format compatibility verification result.

[0138] In some preferred embodiments, when data transmission is performed using the repair link, first, a route update instruction is generated, which includes information such as target address, next hop address, priority, etc. that needs to be modified. After each node receives the instruction, the current route configuration is temporarily stored as a rollback backup, and then the new route rule is applied. The synchronization of authentication information is performed in the order from the source node to the target node, and after each node completes the local authentication state update, it sends a synchronization completion notification to the next node. The data retransmission mechanism adopts an exponential backoff strategy, with an initial retransmission interval of 100 milliseconds, and if an acknowledgement is still not received, the interval time is doubled, with a maximum of 5 retransmissions. By monitoring the data packet reception of the target node, when 10 complete data packets are received in succession, it is determined that the link repair is successful, and the entire process realizes fast fault recovery.

[0139] As a preferred implementation, step S4, obtaining the gap data of the interrupted node, generating a completion value of the gap data by using a data completion algorithm, and interpolating and completing the gap data according to the completion value to obtain complete authentication data, comprises:

[0140] Obtaining gap data generated by the interrupted node during link interruption; the gap data includes numerical fields and split type fields;

[0141] For the numerical type field, the values of the time points before and after are obtained, and the first field interpolation of the missing point in the middle is calculated according to the time interval ratio;

[0142] For the split type field, the number of occurrences of each category is counted, and the second initial field interpolation containing all missing field completion values is generated according to the category value with the most occurrences;

[0143] The second initial field interpolation is matched with the format requirements of the break node to obtain the second field interpolation;

[0144] The missing data is interpolated and completed according to the first field interpolation and the second field interpolation to obtain complete authentication data.

[0145] Preferably, the authentication data gap record generated during the link interruption is obtained, including the timestamp range of the missing data, the node identifier involved and the missing field type, and the incompatible items marked in the format compatibility verification result are read to identify which missing data is related to the format incompatibility problem, and a corresponding relationship table of missing data items and node format requirements is established to record the data type and value range required for each missing field. According to the data type and value range recorded in the corresponding relationship table, a predetermined number of complete authentication records are extracted before and after the missing time point, for numerical type fields, the values of the time points before and after are obtained, and the interpolation of the missing point in the middle is calculated according to the time interval ratio, for split type fields, the number of occurrences of each category in the records before and after is counted, and the category value with the most occurrences is selected to generate intermediate authentication data containing all missing field completion values. The intermediate authentication data is compared with the format requirements of the link interruption position node, if the data format does not match, the format is adjusted according to the preset encoding conversion table of the target node, including field name mapping, data type conversion and unit conversion, to generate standardized completion data that meets the receiving standard of the target node. The standardized completion data is inserted into the authentication data stream in the original timestamp order, the historical authentication records before the interruption, the standardized completion data and the newly added authentication records after the interruption are merged, and the complete authentication data set without missing is confirmed by checking the timestamp continuity and the completeness of the required fields.

[0146] Illustratively, when the link is interrupted for a certain period of time, the system automatically records the start and end time of the interruption, such as from 14:30:15 to 14:35:42, during which the authentication data transmission between node A and node B is interrupted. The gap record details the missing field types, including authentication token, user identifier, permission level, operation type and other key information. During the establishment of the corresponding relationship table, the system finds that node A requires an authentication token of 128-bit string, while node B accepts 64-bit format, and this format difference is recorded in the table, providing a clear conversion basis for subsequent data completion. Linear interpolation algorithm plays an important role in numerical type field completion.

[0147] In a specific embodiment, the authentication request frequency is 120 times per second at 14:30, 150 times per second at 14:36, and the value at 14:33 during the interruption needs to be completed. The system calculates the time ratio, 14:33 is 3 minutes away from 14:30, which accounts for half of the total time span of 6 minutes, so the interpolation result is 120 plus half of 30, i.e. 135 times per second. This method ensures smooth transition of data and avoids sudden changes. For a type field such as authentication method, the system counts 10 records before and after, and finds that password authentication appears 8 times and biometric authentication appears 2 times, so password authentication is selected as the completion value for the missing period. Format conversion and standardization processing ensure the availability of the completed data.

[0148] As a preferred embodiment, step S5, according to the complete authentication data, identifies an authentication failure node, suspends the authentication operation of the authentication failure node, performs data verification on the authentication failure node, and restarts the authentication operation of the authentication failure node when the data verification passes a preset verification number threshold continuously, including:

[0149] According to the complete authentication data, extracting a node with an authentication failure number greater than a preset failure number threshold as a to-be-verified node;

[0150] Comparing and verifying the data content of the to-be-verified node with the original storage data, counting the number of failed items of the verification, and identifying the to-be-verified node with a number of failed items greater than a preset failure number threshold as an authentication failure node;

[0151] Suspending the authentication operation of the authentication failure node;

[0152] Obtaining the authentication data of the authentication failure node from the original storage data, continuously downloading the authentication data to the authentication failure node to obtain an authentication result;

[0153] If the authentication result is passed in a continuous preset verification number threshold, restarting the authentication operation of the authentication failure node.

[0154] Preferably, the complete authentication data includes authentication records of all nodes in a specific time period, and each record has an explicit authentication result identifier. When the system traverses these records, it will focus on the entries with a result field of "FAIL" or an error code.

[0155] For example, node A has generated 500 authentication records in one hour, of which 45 show authentication failure, with a failure rate of 9%. The system sets the threshold value to 5%, so node A is marked as a node to be verified. This statistical identification method can accurately locate the nodes with authentication problems, avoiding the waste of resources for indiscriminate verification of all nodes.

[0156] It should be noted that different types of verification failure items have different severity. Time stamp format error may only be a format conversion problem, while digest value mismatch may mean that the data has been tampered with. The system assigns a weight to each failure type, with a format error weight of 1, a data missing weight of 3, and a digest mismatch weight of 5. When the weighted failure score exceeds the preset threshold of 10 points, the data re-distribution process is triggered. This weighting mechanism allows the system to distinguish between minor and major problems, avoiding frequent retransmission triggered by minor problems.

[0157] In some preferred embodiments, the preset verification number threshold is 5 times when performing the continuous verification process. That is, node B receives the re-distributed authentication data for the first time, and the system starts counting. If the second, third, fourth, and fifth authentication returns a success state, node B is marked as a continuous authentication pass. In this process, any failure will reset the counter and start counting again. With this strict continuous success requirement, the system can ensure that only truly stable and reliable nodes can obtain a continuous authentication pass status. The state record formed provides an explicit authentication capability evaluation for each node, providing a reliable basis for subsequent trust decision and routing selection.

[0158] In some preferred embodiments, by maintaining a trust credential database based on authentication data and interaction logs of each authentication node to implement security protection data for monitoring the supply chain, the RFID tag security protection method combining encryption and identity authentication further comprises:

[0159] If the nodes remain authenticated and the node states are consistent within a preset time, extract trust logs from each authentication node;

[0160] According to the time stamp of the trust log, sort the trust log by time, and pair the source node and the target node to form structured trust interaction data;

[0161] According to the structured trust interaction data, extract the complete data link of cross-organizational authentication, and encapsulate the transmission information in the complete link data into a record data packet;

[0162] According to the record data packet, the trust score and the trust credential database of each authentication node are updated; the trust credential database is constructed based on the authentication data and the interaction log of each authentication node;

[0163] According to the trust credential database, a network topology structure with nodes as vertices and trust relationships as edges is established.

[0164] The path information in the topology structure is compared with the preset supply chain business process, whether the data flow path meets the requirements is verified, and supply chain collaborative security protection data is output.

[0165] It should be noted that the trust score comprehensively considers multiple dimensions such as authentication success rate, average response time, interaction frequency and abnormal events.

[0166] Exemplarily, the authentication success rate accounts for 40% of the weight, the average response time accounts for 30% of the weight, the interaction frequency accounts for 20% of the weight, and the abnormal event rate accounts for 10% of the weight. The node pair A-B has performed 1000 authentications in the past 30 days, 980 times successfully, with a success rate of 98%; the average response time is 0.8 seconds, within the standard of 1 second; the average daily interaction is 33 times, which belongs to high-frequency interaction; only 2 timeout abnormalities occur. After weighted calculation, the trust score of the node pair is 92 points. This score value is stored in the database together with the timestamp and the validity period of 30 days as a new trust relationship entry.

[0167] By adopting the RFID tag security protection method provided by the embodiment of the application, through the fusion of the encryption and identity authentication mechanism, the dynamic trust token of the third-party node is generated by combining the behavior data and the interaction log, the node state is monitored in real time to perform state synchronization, and the scheme of repairing the interrupted link, data completion and node verification is also proposed. The flexible trust mechanism and data repair means can be constructed to ensure the continuity of information verification and the integrity of the link, realize the dynamic permission control of the third-party node, protect the integrity and real-time performance of the data, enhance the fault tolerance and self-repairing capability of the system, and further improve the security, operation efficiency and cooperation fluency of the whole supply chain, and meet the complex and variable supply chain dynamic management requirements.

[0168] The embodiment of the application provides a RFID tag security protection system fusing encryption and identity authentication. Please refer to Figure 2 The RFID tag security protection system fusing encryption and identity authentication comprises a third-party authentication module 11, a node unification module 12, a data synchronization module 13, a data integrity module 14 and an abnormal node verification module 15, wherein:

[0169] The third-party authentication module 11 is configured to, when a third-party node requests to perform an RFID read-write operation through an authentication node, acquire behavior data of the authentication node and an interaction log between the third-party node and the authentication node, and generate a temporary trust token with a dynamic validity period for the third-party node according to the behavior data and the interaction log.

[0170] The node consistency module 12 is configured to compare real-time state information between authentication nodes and third-party nodes, filter out unsynchronized nodes, obtain a node consistency score according to the real-time state information, and perform state synchronization through multicasting if the node consistency score is less than a preset consistency score threshold.

[0171] The data synchronization module 13 is configured to, when an unsynchronized node is identified, detect a communication state of each node with its neighbor nodes, identify an interrupted node, generate a repair link bypassing the interrupted node in combination with a link topology and a historical transmission path, and perform data transmission by using the repair link.

[0172] The data integrity module 14 is configured to acquire gap data of the interrupted node, generate a completion value of the gap data by using a data completion algorithm, perform interpolation completion on the gap data according to the completion value, and obtain complete authentication data.

[0173] The abnormal node verification module 15 is configured to identify an authentication failure node according to the complete authentication data, suspend an authentication operation of the authentication failure node, perform data verification on the authentication failure node until a preset verification number threshold of continuous data verification is passed, and restart the authentication operation of the authentication failure node.

[0174] As a preferred implementation, the third-party authentication module 11 comprises:

[0175] The data acquisition unit is configured to, when a third-party node requests to perform an RFID read-write operation through an authentication node, acquire behavior data of the authentication node and an interaction log between the third-party node and the authentication node.

[0176] The first feature extraction unit is configured to extract a trust credential established between authentication nodes according to the behavior data, and obtain a trust credential feature.

[0177] The second feature extraction unit is configured to obtain a behavior feature vector of the third-party node according to the interaction log.

[0178] The trust score calculation unit is configured to calculate a cosine similarity of the trust credential feature and the behavior feature vector, obtain a similarity value as a trust score.

[0179] The temporary trust token generation unit is configured to generate a temporary trust token with a dynamic validity period for the third-party node according to the trust score and the trust credential.

[0180] Further, preferably, the temporary trust token generation unit is specifically configured to:

[0181] According to the trust credential, obtain the authentication switching frequency of the authentication node within a preset time window and historical authentication data; the historical authentication data includes historical authentication success rate, average response time and number of abnormal behaviors;

[0182] According to the authentication switching frequency and the length of the preset time window, calculate the switching frequency of the authentication node;

[0183] According to the switching frequency and the historical authentication data, generate the initial temporary trust token of the authentication node by using a hash algorithm; the initial temporary trust token includes node identification, validity period and authority range;

[0184] If the trust score is not greater than a preset trust score threshold, reduce the trust score according to a preset attenuation coefficient; the trust score is used to adjust the validity period;

[0185] According to the trust score and the initial temporary trust token, generate a temporary trust token for the third-party node.

[0186] As a preferred embodiment, the node consistency module 12 includes:

[0187] The instruction generation unit is configured to obtain real-time state information of each authentication node and third-party node, filter unsynchronized nodes according to the real-time state information, and generate a state update instruction;

[0188] The state update unit is configured to send the state update instruction to the unsynchronized nodes to obtain a state synchronization data packet; the state synchronization data packet includes pre-change and post-change states and a synchronization timestamp;

[0189] The consistency score calculation unit is configured to calculate a deviation value of node interaction frequency from average interaction frequency according to the synchronization timestamp to obtain a node consistency score;

[0190] The node synchronization unit is configured to, if the node consistency score is less than a preset consistency score threshold, send real-time state information of the unsynchronized nodes to all nodes in a network segment where the unsynchronized nodes are located by using a multicast mode.

[0191] Further, preferably, the instruction generation unit is specifically configured to:

[0192] The heartbeat packet is received through a heartbeat detection mechanism to obtain real-time state information of each authentication node and third-party node; the real-time state information includes online state, authentication capability state and load state of the node;

[0193] If the real-time state information of the interacting nodes is inconsistent, the unsynchronized nodes are screened, and a state update instruction containing the node identifier, the state item to be updated and the update timestamp is generated.

[0194] As a preferred embodiment, the data synchronization module 13 comprises:

[0195] The interrupted node identification unit is configured to identify the unsynchronized nodes, detect the communication state of each node and its neighbor node according to the node physical connection information and logical communication relationship, and identify a node that does not receive a response message from a neighboring node within a preset time as an interrupted node.

[0196] The candidate path generation unit is configured to obtain a source node and a target node of the interrupted node last successful communication, and generate a candidate path from the source node to the target node bypassing the interrupted node according to the link topology.

[0197] The success rate calculation unit is configured to calculate the transmission success rate of the candidate path according to the historical delivery path.

[0198] The repair link selection unit is configured to select a repair link from the candidate path according to the transmission success rate.

[0199] The interrupted recovery unit is configured to perform data transmission using the repair link according to the format requirement of each node in the repair link.

[0200] Further, preferably, the interrupted recovery unit is specifically configured to:

[0201] Read the number coding mode and field definition supported by each node to obtain the format requirement;

[0202] Construct a format conversion mapping table according to the format requirement;

[0203] Convert the link connection information of the repair link into standardized data recognizable by each node according to the format conversion mapping table;

[0204] Perform data transmission on the repair link using the standardized data.

[0205] As a preferred embodiment, the data integrity module 14 comprises:

[0206] A gap data acquisition unit is configured to acquire gap data generated by the interrupt node during link interruption, wherein the gap data comprises a numerical field and a category field.

[0207] A first field interpolation generation unit is configured to, for the numerical field, acquire numerical values at time points before and after the missing point, and calculate a first field interpolation of the missing point according to a time interval ratio.

[0208] A second initial field interpolation generation unit is configured to, for the category field, count occurrence numbers of each category, and generate a second initial field interpolation containing complete values of all missing fields according to a category value with the largest occurrence number.

[0209] A second field interpolation generation unit is configured to match the second initial field interpolation with format requirements of the interrupt node, to obtain a second field interpolation.

[0210] A data completion unit is configured to interpolate and complete the gap data according to the first field interpolation and the second field interpolation, to obtain complete authentication data.

[0211] As a preferred embodiment, the abnormal node verification module 15 comprises:

[0212] A node to be verified extraction unit is configured to extract, according to the complete authentication data, a node with a number of authentication failures greater than a preset failure number threshold, as a node to be verified.

[0213] An authentication failure node identification unit is configured to compare and verify data content of the node to be verified with original storage data, count a number of failed items in the verification, and identify the node to be verified as an authentication failure node if the number of failed items is greater than a preset failure number threshold.

[0214] An authentication suspension unit is configured to suspend an authentication operation of the authentication failure node.

[0215] A verification unit is configured to acquire authentication data of the authentication failure node from the original storage data, and continuously send the authentication data to the authentication failure node to obtain an authentication result.

[0216] An authentication restart unit is configured to restart the authentication operation of the authentication failure node if the authentication result is passed in a continuous preset verification number threshold.

[0217] The RFID tag security protection system provided by the embodiment of the application fuses encryption and identity authentication, generates a dynamic trust token of a third-party node by combining behavior data and interaction logs, monitors a node state in real time to perform state synchronization, and further proposes a scheme for repairing an interrupted link, data completion and node verification, so that a flexible trust mechanism and data repair means can be constructed, the continuity of information verification and the integrity of a link are ensured, dynamic permission management of the third-party node is realized, the integrity and real-time performance of data are ensured, the fault tolerance and self-repairing capability of the system are enhanced, and then the overall security, operation efficiency and cooperation fluency of the supply chain are improved, and the complex and changeable supply chain dynamic management requirements are met.

[0218] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by a computer program instructing relevant hardware, and the program can be stored in a computer readable storage medium. When the program is executed, the program can include the processes of the above-mentioned embodiments of each method. The storage medium can be a magnetic disc, an optical disc, a read-only memory (ROM), a random access memory (RAM) or the like.

[0219] The above is the preferred embodiment of the application. It should be noted that those skilled in the art can make several improvements and refinements without departing from the principles of the application. These improvements and refinements are also considered within the protection scope of the application.

Claims

1. A method for protecting RFID tags by fusing encryption and identity authentication, characterized in that, The method comprises the following steps: When a third-party node requests to perform an RFID read-write operation through an authentication node, behavior data of the authentication node and an interaction log between the third-party node and the authentication node are obtained, and a temporary trust token with a dynamic validity period is generated for the third-party node according to the behavior data and the interaction log; Real-time state information between each authentication node and third-party node is compared, and unsynchronized nodes are screened out, a node consistency score is obtained according to the real-time state information, and if the node consistency score is less than a preset consistency score threshold, state synchronization is performed through multicasting; When an unsynchronized node is identified, the communication state of each node and its neighbor node is detected, an interrupted node is identified, a repair link bypassing the interrupted node is generated based on link topology and historical transmission path, and data transmission is performed using the repair link; Gap data of the interrupted node is obtained, a completion value of the gap data is generated using a data completion algorithm, the gap data is interpolated and completed according to the completion value, and complete authentication data is obtained; According to the complete authentication data, an authentication failure node is identified, the authentication operation of the authentication failure node is suspended, data verification is performed on the authentication failure node, and the authentication operation of the authentication failure node is restarted until the data verification passes a preset verification times threshold. When a third-party node requests to perform an RFID read-write operation through an authentication node, behavior data of the authentication node and an interaction log between the third-party node and the authentication node are obtained, and a temporary trust token with a dynamic validity period is generated for the third-party node according to the behavior data and the interaction log; When a third-party node requests to perform an RFID read-write operation through an authentication node, behavior data of the authentication node and an interaction log between the third-party node and the authentication node are obtained; According to the behavior data, a trust credential feature is obtained by extracting the trust credential established between the authentication nodes; According to the interaction log, a behavior feature vector of the third-party node is obtained; The cosine similarity of the trust credential feature and the behavior feature vector is calculated to obtain a similarity value as a trust score; According to the trust score and the trust credential, a temporary trust token with a dynamic validity period is generated for the third-party node.

2. The method of claim 1, wherein the method further comprises: According to the trust credential, the number of authentication switches of the authentication node within a preset time window and historical authentication data are obtained; the historical authentication data includes historical authentication success rate, average response time and number of abnormal behaviors; According to the number of authentication switches and the length of the preset time window, the switching frequency of the authentication node is calculated; According to the switching frequency and the historical authentication data, a hash algorithm is used to generate an initial temporary trust token of the authentication node; the initial temporary trust token includes node identification, validity period and permission range; If the trust score is not greater than a preset trust score threshold, the trust score is reduced according to a preset attenuation coefficient; the trust score is used to adjust the validity period. ​ According to the trust score and the initial temporary trust token, a temporary trust token is generated for the third-party node.

3. The RFID tag security protection method integrating encryption and identity authentication as described in claim 1, characterized in that, The real-time state information of each authentication node and third-party node is compared, and unsynchronized nodes are screened out. A node consistency score is obtained according to the real-time state information. If the node consistency score is less than a preset consistency score threshold, state synchronization is performed through multicast, including: Real-time state information of each authentication node and third-party node is obtained, and unsynchronized nodes are screened out according to the real-time state information, and a state update instruction is generated; The state update instruction is sent to the unsynchronized nodes to obtain a state synchronization data packet; the state synchronization data packet includes pre-change and post-change states and a synchronization timestamp; According to the synchronization timestamp, a deviation value of node interaction frequency and average interaction frequency is calculated to obtain a node consistency score; If the node consistency score is less than a preset consistency score threshold, the real-time state information of the unsynchronized nodes is sent to all nodes in the network segment where the unsynchronized nodes are located through multicast.

4. The RFID tag security protection method integrating encryption and identity authentication as described in claim 3, characterized in that, The real-time state information of each authentication node and third-party node is obtained, and unsynchronized nodes are screened out according to the real-time state information, and a state update instruction is generated, including: Real-time state information of each authentication node and third-party node is obtained through a heartbeat detection mechanism; the real-time state information includes node online state, authentication capability state and load state; If the real-time state information of the nodes that interact is inconsistent, unsynchronized nodes are screened out, and a state update instruction containing node identification, state items to be updated and an update timestamp is generated.

5. The RFID tag security protection method integrating encryption and identity authentication as described in claim 1, characterized in that, When an unsynchronized node is identified, the communication state of each node and its neighbor nodes is detected, and an interrupted node is identified. A repair link bypassing the interrupted node is generated based on link topology and historical transmission path, and data transmission is performed using the repair link, including: When an unsynchronized node is identified, the communication state of each node and its neighbor nodes is detected based on node physical connection information and logical communication relationship. A node that does not receive a response message from a neighboring node within a preset time is identified as an interrupted node; The source node and target node of the last successful communication of the interrupted node are obtained, and a candidate path bypassing the interrupted node from the source node to the target node is generated based on link topology; The transmission success rate of the candidate path is calculated based on the historical transmission path; A repair link is selected from the candidate path based on the transmission success rate; Data transmission is performed using the repair link based on the format requirements of each node in the repair link.

6. The method of claim 5, wherein the method further comprises: Data transmission is performed using the repair link based on the format requirements of each node in the repair link, including: The data encoding method and field definition supported by each node are read to obtain format requirements; A format conversion mapping table is constructed based on the format requirements; The link connection information of the repair link is converted into standardized data recognizable by each node based on the format conversion mapping table; The standardized data is used for data transmission on the repair link.

7. The RFID tag security protection method integrating encryption and identity authentication as described in claim 1, characterized in that, The acquisition of the gap data of the interrupt node adopts a data completion algorithm to generate a completion value of the gap data, and the gap data is interpolated and completed according to the completion value to obtain complete authentication data, comprising: Obtain the gap data generated by the interrupt node during link interruption; the gap data includes numerical fields and type fields; For the numerical fields, obtain the values at the previous and subsequent time points, and calculate the first field interpolation of the intermediate missing point according to the time interval ratio; For the type fields, count the occurrence times of each type, and generate a second initial field interpolation containing the completion values of all missing fields according to the type value with the most occurrences; Match the second initial field interpolation with the format requirements of the interrupt node to obtain the second field interpolation; According to the first field interpolation and the second field interpolation, the gap data is interpolated and completed to obtain complete authentication data.

8. The RFID tag security protection method integrating encryption and identity authentication as described in claim 1, characterized in that, According to the complete authentication data, identify the authentication failure node, pause the authentication operation of the authentication failure node, perform data verification on the authentication failure node until the data verification passes the preset verification times threshold continuously, and restart the authentication operation of the authentication failure node, comprising: According to the complete authentication data, extract the node with the authentication failure times greater than the preset failure times threshold as the to-be-verified node; Compare and verify the data content of the to-be-verified node with the original storage data, count the number of failed items of the verification, and identify the to-be-verified node with the number of failed items greater than the preset failure number threshold as the authentication failure node; Pause the authentication operation of the authentication failure node; Obtain the authentication data of the authentication failure node from the original storage data, continuously send the authentication data to the authentication failure node to obtain the authentication result; If the authentication result is passed in the continuous preset verification times threshold, restart the authentication operation of the authentication failure node.

9. A security protection system of RFID tags fusing encryption and identity authentication, characterized in that, Comprising: A third-party authentication module is configured to, when a third-party node requests to perform an RFID read-write operation through an authentication node, acquire behavior data of the authentication node and an interaction log between the third-party node and the authentication node, and generate a temporary trust token with a dynamic validity period for the third-party node according to the behavior data and the interaction log; A node unification module is configured to compare real-time state information between authentication nodes and third-party nodes, filter unsynchronized nodes, obtain a node consistency score according to the real-time state information, and perform state synchronization through multicasting if the node consistency score is less than a preset consistency score threshold; A data synchronization module is configured to, when an unsynchronized node is identified, detect the communication state of each node and its neighbor nodes, identify an interrupt node, generate a repair link bypassing the interrupt node in combination with a link topology and a historical transmission path, and perform data transmission using the repair link; A data completion module is configured to acquire gap data of the interrupt node, generate a completion value of the gap data using a data completion algorithm, and interpolate and complete the gap data according to the completion value to obtain complete authentication data. An abnormal node checking module is configured to identify an authentication failure node according to the complete authentication data, suspend the authentication operation of the authentication failure node, perform data checking on the authentication failure node until the data checking is continuously passed for a preset threshold of checking times, and restart the authentication operation of the authentication failure node; The third-party authentication module comprises: A data acquisition unit is configured to acquire behavior data of the authentication node and an interaction log between the third-party node and the authentication node when the third-party node requests to perform an RFID read-write operation through the authentication node; A first feature extraction unit is configured to extract a trust credential established between authentication nodes according to the behavior data to obtain a trust credential feature; A second feature extraction unit is configured to obtain a behavior feature vector of the third-party node according to the interaction log; A trust score calculation unit is configured to calculate a cosine similarity of the trust credential feature and the behavior feature vector to obtain a similarity value as a trust score; A temporary trust token generation unit is configured to generate a temporary trust token with a dynamic validity period for the third-party node according to the trust score and the trust credential.

Citation Information

Patent Citations

  • Information security prevention and control management system based on edge cloud cooperation

    CN118590320A

  • Secure communication verification method and system for Internet of Things

    CN118748619A

  • Node fault intelligent diagnosis method and system of intelligent space sensor network

    CN120416078A