Port group electronic tag with security protection mechanism and security authentication method

Electronic tags for fiber optic port groups, which use biometric authentication features, solve the security protection problem of fiber optic interfaces and connectors in optical networks, achieve efficient security management and resource utilization, and improve the overall security of optical networks.

CN121486091APending Publication Date: 2026-02-06NANJING HUAMAI TECH +1
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202610013496.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-01-07
Publication Date
2026-02-06

AI Technical Summary

Technical Problem

The fiber optic interfaces and connectors in existing optical networks lack security protection mechanisms, making them vulnerable to being counterfeited with fake tags to gain access, leading to signal eavesdropping, data tampering, and network outages. Furthermore, the physical access process lacks security control.

Method used

The fiber optic port group electronic tag, which adopts biometric authentication feature recognition, combines fingerprint, iris and facial recognition devices with a hierarchical protection mode through group tag and sub-tag design to ensure biometric authentication before operation and prevent unauthorized operation.

Benefits of technology

It enhances the security protection capabilities of the physical layer of optical networks, prevents unauthorized access, improves resource utilization and management efficiency, achieves differentiated security protection, and isolates potential intrusion behaviors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121486091A_ABST
    Figure CN121486091A_ABST
Patent Text Reader

Abstract

The invention discloses a port group electronic tag with a security protection mechanism and a security authentication method, and belongs to the technical field of methods or devices for marking recording carriers in a digital mode. According to the electronic tag, a biometric authentication feature device is integrated at a group tag end, and biometric authentication feature authentication needs to be completed before the electronic tag, an optical fiber interface and a connector are operated, so that the problems that an existing electronic tag is easy to counterfeit and is difficult to manage and control due to illegal access are solved; on-demand protection is carried out on optical fiber ports through a hierarchical security protection scheme, accurate protection of high-risk ports is realized on the premise of not influencing normal operation and maintenance of low-risk ports, and potential intrusion behaviors are effectively isolated; through hierarchical design of the group labels and the sub-labels, the port security levels are accurately distinguished, the overall link risk caused by single sub-label vulnerabilities is avoided, and the resource utilization rate and the management efficiency of the optical network are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention discloses a port group electronic tag with a security protection mechanism and a security authentication method, which relates to optical fiber communication digital management technology and belongs to the technical field of methods or devices for digitally marking recording carriers. Background Technology

[0002] With the rapid development of artificial intelligence, industrial internet, big data centers, and other fields, optical networks, with their core advantages such as ultra-high bandwidth, low transmission loss, and strong resistance to electromagnetic interference, have become the core transmission carrier supporting data interaction in the intelligent field. As the scale and scope of optical network applications continue to expand, their security has become a major concern, especially physical layer security, which, as the foundation of optical network security, determines the reliability and confidentiality of the entire network transmission. Currently, the number of optical communication equipment in optical networks, such as optical transmission equipment, optical distribution boxes, and optical distribution nodes, is growing exponentially. These devices rely on fiber optic interfaces and connectors for signal interconnection, and these interfaces and connectors, as the physical entry and exit points for optical signal transmission, have become key points for physical layer security protection.

[0003] To achieve standardized management of fiber optic interfaces and connectors, existing technologies mostly use electronic tags, such as RFID tags and near-field communication tags, for identification. Tag reading enables digital management of information such as interface model, home link, and maintenance records, improving maintenance efficiency to some extent. However, in practice, it has been found that existing electronic tag management systems only focus on identification and recording, completely neglecting the security protection needs of interfaces and connectors. On the one hand, electronic tags themselves lack security verification capabilities. Unauthorized personnel can forge legitimate interface identities to access the optical network by counterfeiting tags or tampering with tag information, leading to eavesdropping, tampering, or injection of false data into optical signals. On the other hand, the physical access process of interfaces and connectors lacks security control mechanisms. Unauthorized plugging and unplugging operations, such as maliciously disconnecting critical links or connecting illegal optical equipment, can easily cause network interruptions, service paralysis, and even pose a serious threat to the stable operation of critical infrastructure such as power and communications.

[0004] Therefore, it is necessary to design an electronic tag for fiber optic port groups with a security protection mechanism to compensate for the lack of security protection mechanisms in the fiber optic interfaces and connectors of the physical layer of optical networks, and to ensure the safe and reliable operation of optical networks in key applications in the field of intelligence. Summary of the Invention

[0005] The purpose of this invention is to address the shortcomings of the aforementioned background technology by providing a fiber optic port group electronic tag solution for security protection through biometric authentication. Before operating the electronic tag of the fiber optic port group with security protection mechanism and the fiber optic interface and connector it identifies, biometric authentication is required. Only after successful authentication can the next step be performed, thereby achieving the purpose of protecting the fiber optic interface, connector, and fiber optic port group electronic tag, and solving the technical problem of the lack of security protection mechanisms for optical network physical layer devices, inter-device connections, and data transmission.

[0006] To achieve the above-mentioned objectives, the present invention employs the following technical solution:

[0007] A port group electronic tag with a security protection mechanism includes a group tag and at least one sub-tag. The group tag is equipped with a feature authentication device controlled by operation commands. The feature authentication device integrates at least one biometric authentication feature acquisition device and a processor. The processor generates operation commands based on the authentication results of at least one biometric authentication feature under different protection mode levels. The feature authentication device operates under the action of the operation commands to cover or expose the group tag.

[0008] As a further optimization scheme for port group electronic tags with security protection mechanisms, the protection mode levels include: basic level, linkage level, and full-dimensional level.

[0009] As a further optimization of port group electronic tags with security protection mechanisms, at least one biometric authentication feature acquisition device includes a fingerprint acquisition device, an iris acquisition device, and a facial recognition device.

[0010] As a further optimization of port group electronic tags with security protection mechanisms, the operation instructions are generated based on the authentication result of one of the biometric authentication features, namely fingerprint, iris, or facial recognition, under the basic protection mode level.

[0011] As a further optimization of port group electronic tags with security protection mechanisms, the operation instructions are generated based on the authentication results of two biometric authentication features: fingerprint, iris, and facial recognition, under the linkage-level protection mode.

[0012] As a further optimization of port group electronic tags with security protection mechanisms, the operation instructions are generated based on the authentication results of fingerprint, iris, and face under the full-dimensional protection mode.

[0013] As a further optimization of the port group electronic tag with a security protection mechanism, the feature authentication device also includes an electromagnetic control component or motor controlled by an operation command, which controls the operation of the feature authentication device under the action of the operation command.

[0014] As a further optimization of port group electronic tags with security protection mechanisms, the feature authentication device also includes a display and a graphical user interface. The protection mode selection interface provided by the graphical user interface is transmitted to the display, which is used to input the request instructions of the technician and receive the protection mode selection instructions of the technician.

[0015] A method for secure authentication of port group electronic tags, wherein the aforementioned port group electronic tags are implemented, and the feature authentication device performs the following steps:

[0016] S1, Receive request signaling for operation of electronic tags in the fiber optic port group;

[0017] S2 prompts you to select a protection mode level. After selecting the protection mode level, you receive an authentication request signaling and receive an instruction to allow the submission of biometric authentication features. You then obtain the biometric authentication features collected by the electronic tags of the port group to be authenticated.

[0018] S3 compares the biometric authentication features obtained in S2 with the stored biometric features. If the authentication comparison is successful, an operation command is sent to the electronic tags in the port group to be authenticated, and an operation command is sent to the technicians. If the authentication comparison fails, a lock command is sent to the electronic tags in the port group to be authenticated.

[0019] As a further optimization of the port group electronic tag security authentication method, in S3, if the authentication comparison fails no more than a times, it returns to S2 and receives the authentication request signaling again under the selected protection mode level; if the authentication comparison fails more than a times, a lockout command is sent to the electronic tag of the port group to be authenticated, where a is an integer greater than or equal to 1.

[0020] The present invention, by adopting the above technical solution, has the following beneficial effects:

[0021] (1) This invention proposes an electronic tag scheme for fiber optic port groups with a security protection mechanism. It clarifies that before operating the electronic tag, fiber optic interface and connector under this scheme, biometric authentication such as fingerprint, iris and face must be completed. This design can solve the pain points of existing electronic tags being easy to forge and difficult to control illegal access, and effectively improve the security protection capability of the physical layer of optical network.

[0022] (2) The fiber optic port group electronic tag scheme proposed in this invention uses a hierarchical design of group tags and sub-tags. The group tags manage the overall port access, and the sub-tags are adapted according to the requirements. This not only accurately distinguishes the port security level and avoids the risk of the overall link caused by the vulnerability of a single sub-tag, but also saves fiber optic port electronic tag resources and improves the resource utilization and management efficiency of the optical network.

[0023] (3) This invention proposes a graded security protection scheme for electronic tags of fiber optic port groups, with three levels of protection: basic, linkage, and full-dimensional. The fiber optic ports are protected as needed, and uncertified personnel cannot operate them. This scheme achieves precise protection of high-risk ports without affecting the normal operation and maintenance of low-risk ports, effectively isolates potential intrusion behaviors, and further improves the overall security of optical networks.

[0024] (4) The present invention can realize differentiated security protection for electronic tags of optical fiber interfaces, connectors and optical fiber port groups in optical networks, and provide a security protection mechanism for users' batch operations. Attached Figure Description

[0025] Figure 1 This is a schematic diagram of an electronic tag for a fiber optic port group with a security protection mechanism.

[0026] Figure 2 This is a flowchart of the control signaling transmission between the electronic tag and the authentication device.

[0027] Figure 3 This is a schematic diagram of a 6-fiber optic port group electronic tag fingerprint recognition system with security protection mechanisms.

[0028] Figure 4 This is a schematic diagram of a 6-fiber optic port group electronic tag fingerprint recognition system with security protection mechanisms.

[0029] The labels in the diagram are as follows: 11, 12, ..., 1n are sub-labels of the first group of port group electronic tags, 2, ..., 2n are sub-labels of the second group of port group electronic tags, m1, m2, ..., mn are sub-labels of the mth group of port group electronic tags, 1, 2, ..., m are group labels of the 1st to mth group of port group electronic tags, and 101, 201, ..., m01 are feature authentication devices of the 1st to mth group of port group electronic tags. Detailed Implementation

[0030] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only some, not all, of the embodiments of this invention.

[0031] like Figure 1As shown, in m groups of fiber optic port group electronic tags, the i-th group of fiber optic port group electronic tags consists of the i-th group tag and the i1-in-th sub-tags, where i=1,2,...,m, m is an integer greater than or equal to 1, and n is an integer greater than or equal to 1. The group tag is a hierarchical identification module set on the fiber optic distribution frame to identify a group of fiber optic ports with the same affiliation or service attributes. It contains core data such as the group's unique ID and affiliation information, enabling overall identification and batch maintenance of the port group, and forming a hierarchical association with the sub-tags. The sub-tag is an end-point identification module belonging to the group tag, corresponding one-to-one with a single fiber optic port on the fiber optic distribution frame. It binds fine-grained data such as the port's unique address and connection information, enabling precise single-port positioning and link traceability, supporting independent updates while maintaining its association with the group tag.

[0032] To provide security protection for the electronic tags in the fiber optic port group, a feature authentication device 101, 201, ..., m01, controlled by operation commands, is configured for each group of electronic tags in the first to m-th port groups. The feature authentication device integrates at least one biometric authentication feature acquisition device (fingerprint acquisition, iris acquisition, facial recognition, or other methods) and a processor. After acquiring the biometric authentication features of a technician, the at least one biometric authentication feature is submitted to the processor. The processor generates an operation command after successfully authenticating the submitted biometric feature under different protection mode levels. Under the action of the operation command, the feature authentication device closes to cover the group tags; under the action of the operation command, the feature authentication device opens to expose the group tags. The feature authentication device also includes an electromagnetic control component or motor controlled by the operation command, which controls the closing or opening of the feature authentication device. Depending on the different security protection requirements of the fiber optic port group electronic tags, the connection methods between these group tags and sub-tags and the feature authentication device are also different. The feature authentication device also includes a display and a graphical user interface. The protection mode selection interface provided by the graphical user interface is transmitted to the display, which is used to input the technician's request command and receive the technician's protection mode selection command.

[0033] The security protection mechanism for electronic tags in fiber optic port groups can be divided into three types: basic level, linkage level, and full-dimensional level.

[0034] The basic security level protection for fiber optic port group electronic tags refers to a system where only group tags are connected to the feature authentication device. Before scanning, replacing, or performing operations on group tags 1-m, technicians must first authenticate using one of three biometric authentication features: fingerprint, iris, or facial recognition. For example, technicians who fail fingerprint authentication cannot operate on group tags 1-m; otherwise, the feature authentication device will trigger an alarm and lock all connectors and interfaces. In the basic security level protection mode for fiber optic port group electronic tags, feature authentication is not required before operating on any of the sub-tags 11-mn.

[0035] The fiber optic port group electronic tag security linkage level protection refers to the connection of group tags and some sub-tags to a feature authentication device. Before scanning, replacing, or performing operations such as scanning or replacing group tags 1-m and some sub-tags requiring security protection, technicians must first authenticate using two biometric authentication features: fingerprint, iris, or facial recognition. Technicians who fail authentication cannot operate group tags 1-m or some sub-tags; otherwise, the feature authentication device will trigger an alarm and lock all connectors and interfaces. In the fiber optic port group electronic tag security linkage level protection mode, feature authentication is not required before operating any electronic tag among the sub-tags that do not require security protection.

[0036] The full-dimensional security protection of the fiber optic port group electronic tags means that group tags 1-m and sub-tags 11-mn are all connected to the feature authentication device. Before scanning or replacing any of the group tags 1-m or sub-tags 11-mn that are under security protection, technicians must first authenticate through three biometric authentication features: fingerprint, iris, and facial recognition. Technicians who fail to authenticate cannot perform the operation; otherwise, the feature authentication device will trigger an alarm and lock all connectors and interfaces.

[0037] Based on the above-mentioned electronic tag security protection mechanism, the control signaling transmission process between the electronic tag and the feature authentication device is as follows: Figure 2 As shown, the steps include the following.

[0038] S1, when the control signaling transmission process between the electronic tag and the feature authentication device begins, the technician first issues an operation request signaling to the electronic tag in the fiber optic port group to officially start the subsequent operation.

[0039] S2. Next, proceed to the protection mode level selection step. Depending on the electronic tags of the fiber optic port group to be protected, select one of three different security protection modes: Basic, Linked, and Full-Dimensional. If an incorrect selection is made, return to the "Protection Mode Level Selection" step to select again. After selecting a protection mode, the technician sends an authentication request signal to the feature authentication device to initiate the identity authentication process. When the feature authentication device returns an instruction allowing the submission of biometric authentication features, the technician submits biometric authentication features such as fingerprints, iris scans, or facial recognition, followed by identity verification.

[0040] S3. Then, the processor determines whether the biometric authentication comparison is successful. If the comparison is successful, the feature authentication device sends an operation permission command to the electronic tag in the fiber optic port group and simultaneously sends an operation permission command to the technician, thus ending the operation process. If the initial biometric authentication comparison fails, the technician can submit the biometric authentication feature for multiple comparisons. If the biometric authentication comparison fails no more than 'a' times, the feature authentication device returns to the "send authentication request signaling" step to re-authenticate; if the number of authentication failures exceeds 'a' times, the feature authentication device will send a tag lock command to terminate the technician's subsequent operations.

[0041] like Figure 3 As shown, in the basic protection level, and using only fingerprint authentication, the fiber optic port group electronic tag with 6 ports includes one group tag (group tag 1) and 6 sub-tags (sub-tags 11-16), and a feature authentication device integrated with a fingerprint acquisition device.

[0042] like Figure 4 As shown, the feature authentication device, which integrates a fingerprint acquisition unit, is installed on the cabinet of the electronic tag group that needs to be protected. The feature authentication device is installed on the outside of the group tag 1. The feature authentication device will only open after the fingerprint authentication is successful, and the group tag 1 can be operated; if the authentication is unsuccessful or fails, the group tag 1 cannot be operated.

[0043] Specifically, under normal circumstances, the signature authentication device is in the off state. The display screen of the signature authentication device is in the off state when no technician is performing authentication operations, in order to save power.

[0044] When a technician needs to operate on group tag 1, the technician first activates the feature authentication device via its graphical user interface to issue a request signal. Next, the technician selects the protection mode level; since only group tags need protection, the basic level is selected. After selection, the technician sends an authentication request command to the feature authentication device and, upon receiving a permission command, submits their biometric authentication signature via the fingerprint scanner. The feature authentication device then compares the collected biometric signature with those in the system to determine if the technician is authorized to proceed.

[0045] If the technician fails to pass the biometric authentication of the feature authentication device, the above steps can be repeated for a second attempt. When the number of authentication failures exceeds a=3, the feature authentication device sends a group tag 1 lock command to the fiber optic port group tag to prevent the technician from taking further action.

[0046] If a technician authenticates their identity using the biometric authentication device, the device sends an operation permission command to group tag 1 and simultaneously sends an operation permission command to the technician, allowing the technician to operate group tag 1. Once the authentication device is activated, group tag 1 and its sub-tags are placed on the same horizontal plane, allowing the technician to operate group tag 1.

[0047] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the specific embodiments described above. The specific embodiments and descriptions in the specification are merely for further illustrating the principles and preparation effects of the present invention. Various changes and modifications can be made to the present invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of protection claimed by the present invention. The scope of protection of the present invention is defined by the claims and their equivalents.

Claims

1. A port group electronic tag with a security protection mechanism, characterized in that, It includes a group tag and at least one sub-tag. The group tag is configured with a feature authentication device controlled by an operation command. The feature authentication device integrates at least one biometric authentication feature acquisition device and a processor. The processor generates operation commands based on the authentication results of at least one biometric authentication feature under different protection mode levels. The feature authentication device acts under the action of the operation command to cover or expose the group tag.

2. The port group electronic tag with a security protection mechanism according to claim 1, characterized in that, The protection mode levels include: basic level, linkage level, and full-dimensional level.

3. The port group electronic tag with a security protection mechanism according to claim 2, characterized in that, The at least one biometric authentication feature acquisition device includes a fingerprint acquisition device, an iris acquisition device, and a facial recognition device.

4. The port group electronic tag with a security protection mechanism according to claim 3, characterized in that, The operation command is generated under the basic protection mode level based on the authentication result of one of the biometric authentication features, namely fingerprint, iris, or facial recognition.

5. The port group electronic tag with a security protection mechanism according to claim 3, characterized in that, The operation command is generated based on the authentication results of two biometric authentication features: fingerprint, iris, and facial recognition, under the linkage-level protection mode.

6. The port group electronic tag with a security protection mechanism according to claim 3, characterized in that, The operation instructions are generated based on the authentication results of fingerprint, iris, and face under the full-dimensional protection mode.

7. The port group electronic tag with a security protection mechanism according to claim 1, characterized in that, The feature authentication device also includes an electromagnetic control component or motor controlled by an operation command, which controls the feature authentication device to operate under the operation command.

8. The port group electronic tag with a security protection mechanism according to claim 1, characterized in that, The feature authentication device also includes a display and a graphical user interface. The protection mode selection interface provided by the graphical user interface is transmitted to the display. The display is used to input the technician's request instructions and receive the technician's protection mode selection instructions.

9. A method for secure authentication of port group electronic tags, characterized in that, The feature authentication device, implemented using the port group electronic tag as described in claim 1, performs the following steps: S1, Receive request signaling for operation of electronic tags in the fiber optic port group; S2 prompts you to select a protection mode level. After selecting the protection mode level, you receive an authentication request signaling and receive an instruction to allow the submission of biometric authentication features. You then obtain the biometric authentication features collected by the electronic tags of the port group to be authenticated. S3 compares the biometric authentication features obtained in S2 with the stored biometric features. If the authentication comparison is successful, an operation command is sent to the electronic tags in the port group to be authenticated, and an operation command is sent to the technicians. If the authentication comparison fails, a lock command is sent to the electronic tags in the port group to be authenticated.

10. The port group electronic tag security authentication method according to claim 9, characterized in that, In step S3, if the authentication comparison fails no more than a times, the process returns to step S2 and receives the authentication request signaling again under the selected protection mode level; if the authentication comparison fails more than a times, a lockout command is sent to the electronic tag of the port group to be authenticated, where a is an integer greater than or equal to 1.

Citation Information

Patent Citations

  • Anti-identity theft and information security system process

    CN103443719A

  • Intelligent optical fiber wiring device and method and management system

    CN103454736A

  • Two-dimensional code anti-counterfeit label

    CN212411231U

  • Novel anti-counterfeit label

    CN219609893U

  • Patch type RFID electronic tag

    CN221726562U