A lightweight dynamic traceability system and method based on stream cipher and time synchronization

By introducing a lightweight dynamic traceability system that synchronizes stream ciphers with time into bottled consumer products, and dynamically generating QR codes combined with anonymous identity tokens, the system solves the problems of dynamism, scenario adaptability, and privacy protection in the anti-counterfeiting traceability of bottled consumer products, and achieves efficient and secure anti-counterfeiting functions.

CN121547279BActive Publication Date: 2026-03-27GUIZHOU UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-01-09
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Existing anti-counterfeiting and traceability technologies for bottled consumer goods suffer from insufficient dynamism, poor scenario adaptability, imbalance between privacy and statistics, and incomplete verification chains, making it difficult to meet the requirements of low power consumption, small size, and offline operation.

Method used

A lightweight dynamic traceability system based on stream cipher and time synchronization is adopted. By writing a unique identifier, manufacturer signature and device key on the product, and combining it with a real-time clock to generate a dynamic QR code, and introducing anonymous identity tokens for user access, triple verification and data updates are achieved.

Benefits of technology

It effectively resists replay attacks, achieves unforgeable product identity and anonymous user behavior statistics, is suitable for resource-constrained embedded scenarios, and provides efficient and secure anti-counterfeiting functions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121547279B_ABST
    Figure CN121547279B_ABST
Patent Text Reader

Abstract

The present application relates to the field of Internet of Things, embedded system and information security, in particular to a lightweight dynamic traceability system and method based on stream cipher and time synchronization, aiming at the problems of easy copying of existing static two-dimensional code, high risk of replay attack, poor adaptation to resource limited scene, etc., the method comprises: writing identity information and activating real-time clock at product end; calculating time slice after triggering, generating check code by stream cipher encryption to construct dynamic two-dimensional code; uploading information anonymously by user; recording traceability information after three signatures of manufacturer identity, replay attack and device identity by platform. The system comprises read-write storage area, encryption module, real-time clock register, power module, and electronic paper or ink screen capable of displaying two-dimensional code. The present application can resist copying and replay attack, adapt to scenarios such as bottle cap chip, and balance privacy and statistics, ensuring safe and effective traceability.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of Internet of Things, embedded systems and information security, more particularly to a lightweight dynamic traceability system and method based on stream cipher and time synchronization. BACKGROUND

[0002] Currently, in the field of bottled consumer goods such as food, medicine and liquor, in order to prevent counterfeiting, replacing packaging and illegal filling, the industry generally uses two-dimensional codes or NFC / RFID tags to realize product traceability and anti-counterfeiting verification. The more common methods are: 1. Using static two-dimensional code to identify product identity, users access the background platform by scanning the code to verify the authenticity of the product and record the access information. Some systems introduce cloud platforms and centralized databases to realize code scanning tracking, or use electronic tags embedded with chips to enhance security. 2. Multi-authentication code logistics tracking scheme, some existing technologies design a multi-group static authentication code system to realize full-link traceability, including logistics management authentication code for logistics link tracking, retail management authentication code for retail stage management, product anti-counterfeiting authentication code for consumer anti-counterfeiting, and final consumer anti-counterfeiting authentication code. This kind of scheme generates authentication codes through a specific algorithm, and hides them by using coating, one-time packaging, etc., while using Hash chain technology to ensure that logistics information cannot be tampered with, and can realize functions such as dealer in-out record, consumer authentication frequency statistics, etc. 3. Electronic tag anti-counterfeiting scheme, to improve security, some schemes use NFC (Near Field Communication) or RFID (Radio Frequency Identification) electronic tags to realize anti-counterfeiting through chip-embedded encryption information.

[0003] However, the above-mentioned three schemes have certain defects, such as the static two-dimensional code anti-counterfeiting scheme, although it is simple to operate, the two-dimensional code content is fixed and cannot be changed, which is easy to be maliciously copied and transferred to counterfeit products, and it cannot identify the replay attack of "copy code reuse"; at the same time, the verification process completely depends on the networking environment, which cannot be used in storage and transportation scenarios without network coverage, and the operation and maintenance cost of the cloud platform is high, which is difficult to adapt to the low-power application demand. The authentication code of the multi-authentication code logistics tracking scheme is static and fixed after generation, and cannot be dynamically updated. Once the hidden layer is damaged, the authentication code is easy to be copied and abused, and the verification process depends on the centralized system to solve complex equations (such as authentication code verification based on matrix operation), which has large operation overhead and needs to interact with the system frequently, and cannot be deployed in micro-embedded devices with small size, weak computing power and low power consumption. The hardware cost of the electronic tag anti-counterfeiting scheme is high, and the tag size is large, which is difficult to integrate into bottle caps, micro-packaging and other narrow spaces; at the same time, the reading of the electronic tag needs special equipment, the user operation threshold is high, and it still needs to rely on the background system for verification, which cannot realize fast anti-counterfeiting query in offline scenarios, and is not suitable for large-scale application of mass consumer goods.

[0004] In summary, the current anti-counterfeiting traceability technology of bottled consumer goods generally has the following common problems:

[0005] 1. Lack of dynamics: authentication information (two-dimensional code, multiple sets of authentication code) is static and fixed, easy to copy and vulnerable to replay attacks, and cannot guarantee timeliness through time dimension.

[0006] 2. Poor scene adaptability: existing solutions rely on cloud platform networking or have high operation / hardware costs, and cannot adapt to resource-limited micro-embedded scenarios such as bottle cap chips, making it difficult to meet the needs of low power consumption, small size, and offline operation.

[0007] 3. Privacy and statistics imbalance: either lack of user behavior statistics capability or need to collect real identity information, making it difficult to achieve traceability of anonymous access behavior while protecting privacy.

[0008] 4. Incomplete verification chain: unable to integrate manufacturer digital signature (product source), time synchronization (verification timeliness), and user behavior (access record) into a unified tamper-proof verification system, resulting in fragmented traceability information and insufficient security and traceability. SUMMARY

[0009] Therefore, the present application provides a lightweight dynamic traceability system and method based on stream cipher and time synchronization, which effectively solves the problems of existing anti-counterfeiting systems such as static two-dimensional code being easily copied and counterfeited, lack of product identity authentication mechanism, and inability to realize user access tracking and privacy protection.

[0010] To achieve the above purpose, the present application adopts the following technical solutions:

[0011] A lightweight dynamic traceability method based on stream cipher and time synchronization, specifically comprising the following steps:

[0012] S1, product end identity information writing, the product end writes product unique identification, manufacturer signature, device key and initial time into the chip secure storage area, and activates the chip real-time clock;

[0013] S2, signature verification information encryption, the chip is triggered to calculate the time slice number, the product unique identification and the time slice number are spliced into the payload, the device verification code is generated by stream cipher encryption, and the two-dimensional code containing the product unique identification, the manufacturer signature, the time slice number and the device verification code is constructed;

[0014] S3, user anonymous access, the user terminal generates a user anonymous identification, scans the two-dimensional code, and uploads the product unique identification, manufacturer signature, time slice number, device verification code, and user anonymous identification to the verification platform;

[0015] S4, platform signature verification, verify the platform to complete the manufacturer identity verification, replay attack verification, device identity verification, three verification, record traceability information, and update statistical data.

[0016] Further, the product end writes the product unique identification, manufacturer signature, device key and initial time into the chip secure storage area, and activates the chip real-time clock, specifically including:

[0017] The manufacturer generates a unique product identification code for each product chip, generates a signature for the unique product identification code using the elliptic curve digital signature algorithm, generates a device key through a key derivation function, activates the chip real-time clock register and records the initial time, and writes the final signature verification identity information into the chip secure storage area.

[0018] Further, the product unique identification is generated by performing a hash operation on the chip serial number, product factory time and product model through a hash function, and the first 8 bytes are intercepted.

[0019] Further, the manufacturer signature is generated by the elliptic curve digital signature algorithm through the manufacturer private key for the hash value of the product unique identification.

[0020] Further, the device key is derived by a key derivation algorithm in combination with the product unique identification and a secure random number, and 16 bytes are intercepted as a 128-bit key.

[0021] Further, after the chip is triggered, the time slice number is calculated, the product unique identification and the time slice number are spliced into the payload, the device verification code is generated by stream cipher encryption, and the two-dimensional code containing the product unique identification, manufacturer signature, time slice number and device verification code is constructed, specifically including:

[0022] After the user triggers the chip button, the chip reads the time value of the current timestamp and the initial time, and calculates the time slice number , ΔT is the update period of the two-dimensional code, RTC now represents the current timestamp, T0 represents the initial time, and t is the time slice number,

[0023] The product unique identification and the time slice are spliced to form the authentication data, the product unique identification is encrypted using the preset key and the stream cipher encryption algorithm, and the first 8 bytes are intercepted as the device verification code, the two-dimensional code data containing the product unique identification, manufacturer signature, time slice number and device verification code is constructed and displayed on the chip electronic paper or ink screen.

[0024] Further, the encryption algorithm specific steps are: the initial vector IV=SHA256(t)[0:10] of the lightweight stream cipher algorithm is calculated by a hash function on the time slice number, the final key stream is calculated, and the device verification code is obtained by XOR operation with the authentication data.

[0025] Further, the specific construction method of the user anonymous identifier is that the user anonymous identifier is generated by the HMAC-SHA256 hash algorithm, the user device unique identifier, the application program installation one-time identifier, and the identifier validity period are operated, and then the data is converted into a binary data security coding format.

[0026] Further, the verification platform sequentially completes manufacturer identity verification, replay attack verification, and device identity verification, records traceability information after the three verifications are passed, and updates statistical data, specifically including:

[0027] The verification platform first performs manufacturer identity verification, verifies the matching of the manufacturer signature public key and the product unique identifier, then performs replay attack verification, compares whether the initial time at the time of uploading and the current time are in the tolerance interval, and finally performs device identity verification, derives the device key by the key derivation algorithm combined with the product unique identifier and the platform private key, re-constructs the device verification code and compares it with the device verification code at the time of uploading; after the three verifications are passed, the verification data is recorded and the statistical product access times and user code scanning times are updated.

[0028] Another technical solution with singularity is:

[0029] A lightweight dynamic traceability system based on stream cipher and time synchronization, which completes the lightweight dynamic traceability method described above, the system includes a chip, a readable and writable storage area, an encryption module, a real-time clock register, a power module, and an electronic paper or ink screen capable of displaying a two-dimensional code are provided in the chip,

[0030] The readable and writable storage area is used to store the product unique identifier, the manufacturer signature, the device key, the initial time, and the configuration parameters of the stream cipher algorithm, the hash algorithm, and the key derivation algorithm, and also stores the time slice number and the load data generated during the calculation process,

[0031] The encryption module is used to execute the elliptic curve digital signature algorithm to generate the manufacturer signature, derive the device key by the key derivation algorithm, encrypt the load data by the stream cipher algorithm to generate the message authentication code, and complete the encryption operation related to the hash operation and the device verification code verification,

[0032] The real-time clock register is used to store the initial time, continuously record the current running time of the chip, provide a time reference for calculating the time slice number, and maintain the accuracy of the time data to ensure the time synchronization verification function,

[0033] The power module is used to provide power support for the operation of the readable and writable storage area, the encryption module, and the real-time clock register, and to provide power for the display operation of the electronic paper or ink screen, and supports a low-power working mode to prolong the battery life of the chip.

[0034] Compared with the prior art, the present application has the following beneficial effects: 1. Through the lightweight dynamic traceability system based on stream cipher and time synchronization, the problems of easy copying and counterfeiting of static two-dimensional codes, lack of product identity authentication mechanism, and inability to realize user access tracking and privacy protection in the existing anti-counterfeiting system are effectively solved.

[0035] 2. By embedding a unique product identification code and a manufacturer digital signature in the product end, the unforgeability of product identity and the verifiability of source are realized; by introducing a stream cipher algorithm combined with a time slice mechanism, the two-dimensional code content is dynamically generated, and the replay attack is effectively resisted.

[0036] 3. At the same time, combined with the anonymous identity token mechanism, the anonymous upload and statistical analysis of user scanning behavior are supported, and the privacy protection and behavior traceability requirements are taken into account.

[0037] 4. The system realizes the unforgeability of product identity using a digital signature algorithm, realizes the encryption and authentication of two-dimensional code information using a lightweight stream cipher, and realizes user privacy protection and access behavior statistics through an anonymous user identity token, and is suitable for resource-constrained embedded scenarios such as bottle cap chips, realizes efficient, secure and traceable anti-counterfeiting function, and can be widely used in anti-counterfeiting authentication and scanning registration in scenarios such as fast-moving consumer goods and medicines. BRIEF DESCRIPTION OF DRAWINGS

[0038] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings needed to be used in the embodiments or the prior art description will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor on the basis of the provided drawings.

[0039] Fig. 1 It is a general architecture diagram of the lightweight dynamic traceability system.

[0040] Fig. 2 It is a dynamic authentication flowchart of the lightweight dynamic traceability method.

[0041] Fig. 3 It is a schematic diagram of the key security mechanism of the lightweight dynamic traceability system. DETAILED DESCRIPTION

[0042] The technical solutions in the embodiments of the present application will be described clearly and completely below. Obviously, the described embodiments are only some of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the present application.

[0043] As Figs. 1-3As shown, this implementation example is a lightweight dynamic tracing method based on stream ciphers and time synchronization, specifically including the following steps:

[0044] Step 1: Write identity information to the product side

[0045] ① Calculate the product identifier. The manufacturer generates a unique product identifier (ProductID) code for each product chip. The format is 8 bytes. It can be generated by a hash function using information such as the product manufacturing timestamp, chip serial number SN and product model. For example, hash=SHA256(SN||timestamp||model). Then, the first 8 bytes are extracted to obtain ProductID = hash[0:8].

[0046] ② Calculate the manufacturer's signature. After obtaining the unique product identifier (ProductID), the manufacturer needs to use a signature algorithm to sign it to achieve non-repudiation of the information. Specifically, the manufacturer needs to first calculate the public key and private key for signing, and then use the private key (PrivManufacturer) to digitally sign the ProductID.

[0047] Taking the ECDSA signature algorithm and the secp256r1 curve as an example, the manufacturer first generates random numbers. Furthermore, each signature must be unique, and curve points are calculated based on k and the base point G. And then calculate Finally, I got a signature. If either r or s has a value of 0, then a new device key (k) is selected.

[0048] Wherein, G is the base point of the elliptic curve (predefined), n is the order of G, a 256-bit prime number; PrivManufacturer is the private key d, d∈[1, n-1]; PubManufacturer is the public key Q=d×G, k is a one-time secret integer k∈[1, n-1] selected by the signer in each signing process, used to calculate the signature components r and s; x1 and y1 are the horizontal and vertical coordinates (x1, y1) of the curve point calculated by the random number k and the base point G, where x1 is used to generate the signature component r, and y1 is used to verify the legality of the selected curve point; r is the value obtained by taking the modulo of the horizontal coordinate x1 of the coordinate point by n, which is the public verification certificate of the signature legality; z is the hash value z=SHA256(ProductID) after hashing the unique identifier (ProductID); s is the multiplicative inverse k of the private key d, the message hash value z, and the random number k. -1 The calculated core verification parameters are used to ensure that the signature cannot be tampered with, and together with r, they form a signature pair (r, s).

[0049] ③Calculate the device key (K) that the manufacturer generates the unique symmetric key K (128 bits) of the chip through the key derivation algorithm of the platform for generating the device check code (MAC) value in the subsequent two-dimensional code verification. The key derivation algorithm can select the HKDF algorithm to dynamically derive the device key from the platform master key to avoid storing each key and reduce storage pressure. The specific steps of selecting the HKDF-Expand mode in RFC5869 standard to calculate the device key (K) are as follows: first, initialize the counter ctr = 0x01, then construct the expansion data block input = ProductID || ctr to form a 9-byte input, use the pseudo-random key (PRK) as the key of HMAC to perform the HMAC-SHA256 operation on the above 9-byte input, and obtain the complete key expansion value K_full = HMAC-SHA256 (PRK, ProductID || ctr). Then, the final device symmetric key K = K_full[0:16] is extracted from the first 16 bytes of K_full.

[0050] Among them, the specific definitions of part of the parameters in the above process are as follows:

[0051] PRK: Secret, 32-byte secure random number;

[0052] Info: ProductID;

[0053] Input: Input message body in HKDF-Expand;

[0054] L: 16 bytes (output length, i.e. 128-bit symmetric key);

[0055] ctr: Initialize the counter;

[0056] K_full: The original output result of HMAC, with a length of 32 bytes.

[0057] ④The manufacturer activates the real-time clock register (RTC) in the chip to obtain the initial timestamp T0 (RTC starting point (external crystal oscillator + initial setting)), and finally writes the obtained signature information (ProductID, Signature, K, T0) to the readable and writable area (OTP or FLASH storage area) of the chip.

[0058] Step two, signature information encryption

[0059] The chip needs to pass through the encryption module to encrypt the written verification information combined with the time stamp fed back by the clock register. Whenever the user presses the refresh button on the chip, the chip will intercept the current time stamp (RTC_now) and calculate the current time slice t = floor((RTC_now - T0) / ΔT) with the initial time T0, where ΔT is the update period of the two-dimensional code, RTC_now represents the current time stamp, T0 represents the initial time, t is the time slice number, that is, the two-dimensional code is updated every ΔT seconds, and t (4-byte time slice integer) is combined with ProductID in the verification information to construct authentication data payload = ProductID ||t, and then the encryption module is used to encrypt the constructed authentication data (payload) combined with the device key (K) to obtain the device check code (MAC). The encryption module can select the lightweight encryption algorithm Trivium (a lightweight stream cipher algorithm, which needs to provide a key and an initial vector (IV) during initialization, and IV is a 96-bit initial vector (12 bytes)) in the stream cipher.

[0060] The specific encryption steps are: first, calculate the initial vector IV = SHA256(t)[0:10] of Trivium through the hash function for the time slice t, and finally calculate the keystream keystream = Trivium_Encrypt(K, IV, length = 12) (equal in length to the constructed authentication data payload), and perform XOR operation with payload to obtain MAC = keystream XOR payload, where XOR represents XOR operation.

[0061] Finally, the calculated verification information {product unique identifier, manufacturer signature, time slice number, device check code} is displayed in the form of a two-dimensional code on the electronic paper or ink screen on the chip. Since the intercepted RTC_now is different each time the button is pressed, the calculated time slice t is also different, which drives the change of t and MAC values in the verification information, so that the two-dimensional code constructed in this way will change every time the chip button is pressed, thereby realizing the unforgeable strategy of dynamic two-dimensional code.

[0062] Step three, user anonymous access

[0063] The user scans the two-dimensional code using the verification device to read the information ProductID, Signature, t, and MAC. The verification device generates an anonymous identity UserToken (which can be one-time or long-term persistent) and uploads the information to the verification platform. The five-tuple of the uploaded content is: {ProductID, Signature, t, MAC, UserToken}. The verification device does not transmit any content related to the real identity of the user, and the verification platform can only establish an anonymous portrait based on the anonymous identity (UserToken).

[0064] The specific construction method of the anonymous identity (UserToken) is as follows: first, use the HMAC signature algorithm to construct the anonymous signature of the user Sig=HMAC_SHA256(PlatformSecret, DeviceID || AppInstallID || ExpiryTime), UserToken=Base64URL(Sig). Since the anonymous signature of the user is included in UserToken, the non-repudiation of the user's access operation is achieved.

[0065] Among them, the specific definitions of some parameters in the above process are as follows:

[0066] Sig: anonymous signature of the user;

[0067] Base64URL: a secure encoding format for converting data to binary data;

[0068] PlatformSecret: platform private key for generating signature (random number);

[0069] DeviceID: unique identifier of the user device (such as encrypted Android ID or account);

[0070] AppInstallID: one-time identity generated when the App is installed (16-byte random number, persistent storage in local);

[0071] ExpiryTime: signature validity period (such as timestamp, expiration time point), used to prevent the signature from being reused for a long time.

[0072] Step four, the verification process is divided into three stages of platform verification

[0073] ① The platform extracts the five-tuple {ProductID, Signature, t, MAC, UserToken} from the information uploaded by the user, and first verifies the legality of the manufacturer's signature on (r, s) in Signature, that is, whether both are not in , if yes, the signature verification fails; then calculate the message hash value z = SHA256(ProductID), and calculate the inverse of s , and then calculate , and finally obtain the elliptic curve point If v = r, the signature verification passes to the next stage.

[0074] The specific definitions of some parameters in the above process are as follows: Q is the manufacturer's signature public key PubManufacturer; (r, s) is the signature pair Signature; N is the order of the elliptic curve; V is the value used to compare the signature; w is the modular inverse of the signature component s, which is used as the subsequent signature verification scalar coefficient; u1 and u2 are two scalar coefficients in the verification stage calculated by w, which are used to calculate the elliptic curve point (x1, y1); r is the value obtained by taking the modulus of the coordinate point horizontal coordinate x1 with respect to n, which is a public verification voucher for the legality of the signature and is also one of the signature components; x1 and y1 are the horizontal and vertical coordinates (x1, y1) of the curve point calculated by the random number k and the base point G, wherein x1 is used to generate the signature component r, and y1 is used to verify the legality of the curve point taken; v is the quadratic calculation of the public verification voucher r of the signature by the parameter accepted in the verification stage, and the calculation process is the same as r v = x1 mod n; v = r is the verification of the correctness of the signature in the verification stage, and the calculation processes of the two parameters are consistent, and only the comparison of the results can determine whether the parameters are changed in the transmission process.

[0075] ②According to the initial timestamp T0 recorded in the background corresponding to ProductID and the current time t now , calculate t now current = floor((t now - T0) / ΔT), and then compare the difference between t now and T0, if the difference is too large, it is determined as a replay attack and the verification is rejected, otherwise the third stage verification is performed.

[0076] After the current two-stage verification passes, the platform will calculate the device key K1 = HKDF(ProductID, PlatformSecret) of the chip according to the internal stored key distribution private key (PlatformSecret) through the key derivation algorithm combined with the product identifier ProductID, calculate payload1 = ProductID || t through the uploaded t and ProductID, and then calculate the initial vector IV1 = SHA256(t) [0:10] through the same encryption module in the platform as the chip, the keystream keystream1 = Trivium_Encrypt(K1, IV1, length = 12) (the same length as payload1), and finally XOR the keystream1 with payload1 to obtain MAC' = keystream1 XOR payload1. Then, whether the third-stage verification passes is determined by comparing whether the information of MAC' and MAC matches.

[0077] When the three verifications all pass, the signing platform needs to adjust the code as follows: product_access_count[ProductID]++ represents that the successful access number of the product is increased, and user_scan_count[ProductID][UserToken]++ represents that the number of times that the user UserToken accesses the product is increased.

[0078] A lightweight dynamic tracing system based on stream cipher and time synchronization, which completes the lightweight dynamic tracing method described above, the system includes a chip, a readable and writable storage area, an encryption module, a real-time clock register, a power module, and an electronic paper or ink screen capable of displaying a two-dimensional code are arranged in the chip.

[0079] The readable and writable storage area is used to store the product unique identifier, the manufacturer signature, the device key, the initial time, and the configuration parameters of the stream cipher algorithm, the hash algorithm, and the key derivation algorithm, and to store the time slice number and the payload data generated in the calculation process.

[0080] The encryption module is used to perform the elliptic curve digital signature algorithm to generate the manufacturer signature, derive the device key through the key derivation algorithm, encrypt the payload data through the stream cipher algorithm to generate the message authentication code, and complete the encryption operation related to the hash operation and the device check code verification.

[0081] The real-time clock register is used to store the initial time, continuously record the current running time of the chip, provide a time reference for calculating the time slice number, and maintain the accuracy of the time data to ensure the time synchronization verification function.

[0082] A power module is used to provide power support for the operation of the read-write memory area, the encryption module, the real-time clock register, to provide power for the display operation of the electronic paper or ink screen, and to support a low-power working mode to prolong the endurance time of the chip.

[0083] The various embodiments described in this specification are presented by way of example, and each embodiment describes a specific feature of the application that is independently useful. Each embodiment can be combined with any other embodiment, and the various features of the embodiments can be combined in any combination. The various embodiments described in this specification can be implemented in hardware, software, or a combination of hardware and software. Any feature described in this specification can be implemented in hardware, software, or a combination of hardware and software. The various embodiments described in this specification can be combined in any combination. The various embodiments described in this specification can be implemented in hardware, software, or a combination of hardware and software. Any feature described in this specification can be implemented in hardware, software, or a combination of hardware and software. The various embodiments described in this specification can be combined in any combination.

Claims

1. A lightweight dynamic tracing method based on stream ciphers and time synchronization, characterized in that, Includes the following steps: Product-side identity information is written. The product side writes the product's unique identifier, manufacturer's signature, device key, and initial time into the chip's secure storage area and activates the chip's real-time clock. The verification information is encrypted. After the chip is triggered, the time slice number is calculated. The product unique identifier and the time slice number are concatenated into a payload. The device verification code is generated by encrypting the payload with a stream cipher. A QR code containing the product unique identifier, manufacturer signature, time slice number and device verification code is constructed. For anonymous user access, the user terminal generates an anonymous user identifier. After scanning the QR code, the user uploads the product unique identifier, manufacturer signature, time slice number, device verification code, and anonymous user identifier to the verification platform. The platform verifies signatures by sequentially completing vendor identity verification, replay attack verification, and device identity verification. Once all three verifications are passed, the traceability information is recorded and the statistical data is updated. The product side writes the product's unique identifier, manufacturer's signature, device key, and initial time into the chip's secure storage area and activates the chip's real-time clock, specifically including: The manufacturer generates a unique product identification code for each product chip, uses the elliptic curve digital signature algorithm to generate a signature for the unique product identification code, generates a device key through a key derivation function, activates the chip's real-time clock register and records the initial time, and writes the final verified identity information into the chip's secure storage area. After the chip is triggered, the time slice number is calculated. The product unique identifier and the time slice number are concatenated into a payload, which is then encrypted using a stream cipher to generate a device verification code. A QR code containing the product unique identifier, manufacturer signature, time slice number, and device verification code is constructed, specifically including: After the user triggers the chip button, the chip reads the current timestamp and the initial time to calculate the time slice number. ΔT is the update period of the QR code, RTC_now represents the current timestamp, T0 represents the initial time, and t is the time slice number. The product's unique identifier is concatenated with the time slice to form authentication data. The product's unique identifier is encrypted using a pre-set key and stream cipher encryption algorithm, and the first 8 bytes are extracted as the device verification code. A QR code containing the product's unique identifier, manufacturer's signature, time slice number, and device verification code is constructed and displayed on the chip's electronic paper or e-ink screen. The specific steps of the encryption algorithm are as follows: The initial vector IV = SHA256(t)[0:10] of the lightweight stream cipher algorithm is obtained by calculating the time slice number using a hash function. Finally, the key stream is calculated and XORed with the constructed authentication data to obtain the device verification code. The specific method for constructing the user anonymity identifier is as follows: The anonymous user identifier is generated by using the HMAC-SHA256 hash algorithm to calculate the unique identifier of the user device, the one-time identifier for application installation, and the validity period of the identifier, and then converting the data into a secure encoding format of binary data. The verification platform sequentially completes vendor authentication, replay attack verification, and device authentication. Once all three verifications pass, it records the source information and updates statistical data, specifically including: The verification platform first performs vendor identity verification by verifying the match between the vendor's signature public key and the product's unique identifier; then it performs replay attack verification by comparing the initial upload time with the current time to see if they are within the tolerance range; finally, it performs device identity verification by deriving a device key using a key derivation algorithm combined with the product's unique identifier and the platform's private key, reconstructing the device verification code, and comparing it with the device verification code uploaded; after all three verifications pass, the verification data is recorded and the product access count and user scan count are updated and statistically analyzed.

2. The lightweight dynamic tracing method based on stream cipher and time synchronization according to claim 1, characterized in that, The unique product identifier is generated by hashing the chip serial number, product manufacturing date, and product model using a hash function, and then extracting the first 8 bytes.

3. The lightweight dynamic tracing method based on stream cipher and time synchronization according to claim 1, characterized in that, The manufacturer's signature uses an elliptic curve digital signature algorithm, which generates a hash value that uniquely identifies the product using the manufacturer's private key.

4. The lightweight dynamic tracing method based on stream cipher and time synchronization according to claim 1, characterized in that, The device key is generated by combining the product's unique identifier with a secure random number using a key derivation algorithm, and 16 bytes are extracted to form a 128-bit key.

5. A lightweight dynamic tracing system based on stream cipher and time synchronization, wherein the system implements the lightweight dynamic tracing method as described in any one of claims 1-4, characterized in that, The system includes a chip containing a read / write storage area, an encryption module, a real-time clock register, a power module, and an electronic paper or e-ink screen capable of displaying QR codes. The read / write storage area stores the product's unique identifier, manufacturer signature, device key, initial time, and configuration parameters for stream cipher algorithms, hash algorithms, and key derivation algorithms. It also stores the time slice number and payload data generated during the computation process. The encryption module is used to perform elliptic curve digital signature algorithm to generate a vendor signature, derive a device key through a key derivation algorithm, encrypt the payload data using a stream cipher algorithm to generate a message authentication code, and complete encryption operations related to hash operations and device verification code verification. The real-time clock register stores the initial time, continuously records the chip's current operating time, provides a time reference for calculating the time slice number, and maintains the accuracy of the time data to ensure the time synchronization verification function. The power module provides power to the read / write storage area, encryption module, and real-time clock register, powers the display operation of electronic paper or e-ink screen, and supports low-power operating mode to extend the chip's battery life.

Citation Information

Patent Citations

  • Security data isolation and information exchange method and system based on lightweight protocol

    CN121193526A

  • Block chain-based blood full-process traceability tracking and safety management system and method

    CN121306463A