Information security traceability method of electronic authentication system using commercial cryptographic algorithm
By using commercial cryptographic algorithms for encryption and electronic authentication systems, the problems of inaccurate information and security in product traceability have been solved, enabling secure and reliable traceability and supervision of product information, and ensuring the integrity and reliability of the information.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-30
- Publication Date
- 2026-03-10
AI Technical Summary
Existing product traceability methods suffer from problems such as untimely information updates, inaccurate data, incomplete traceability chains, and information that is easily damaged or forged, making it impossible to fully and effectively achieve end-to-end product traceability and precise supervision.
Commercial cryptographic algorithms are used to encrypt key data. Electronic certification marks are generated and stored on the product manufacturer's side through an electronic certification system. Combined with QR codes and a traceability management platform, secure and reliable traceability of product information is achieved.
Ensuring the security, integrity, and reliability of information enables precise traceability and monitoring of product information, prevents information tampering and leakage, and improves the credibility and efficiency of the traceability process.
Smart Images

Figure CN121644099A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the fields of computer technology, information security, and information traceability, and particularly to an information security traceability method for an electronic authentication system utilizing commercial cryptographic algorithms. Background Technology
[0002] Product traceability certification aims to enable regulatory bodies and consumers to effectively monitor product quality, requiring products to have traceable information. When product quality issues arise, the traceability identifier and related traceability records of the problematic product can be used to locate relevant process information during the production and processing of the product and its components, as well as product testing information, thereby helping to analyze the causes of the quality problems.
[0003] The traceability information for certified products must be accurate, complete, and timely. Companies need to clearly record key data at each stage, such as raw material supplier information, production time, and inspection results. Simultaneously, they must ensure the secure and reliable storage and management of this information, making it readily available for inquiry by relevant regulatory authorities and consumers.
[0004] Currently, certified products are traceable primarily using the following methods: 1) Manual record traceability. Manual record traceability is a traditional method where companies manually record a series of product information. This information includes raw material procurement information, product quality inspection results, etc. While simple and easy to implement, manual record traceability is prone to errors and omissions. In large-scale production, the efficiency and accuracy of manual record traceability are limited. 2) Barcode traceability. Barcode traceability is a common traceability method where each product is associated with a unique barcode. By scanning the barcode, companies can obtain detailed product information. Barcode traceability is efficient and accurate, meeting traceability needs in large-scale production environments. Consumers can also obtain product information by scanning the barcode. However, barcodes have limited information capacity and are easily damaged or counterfeited. 3) RFID traceability. RFID (Radio Frequency Identification) traceability is a method of product traceability using radio frequency technology. Each product carries an RFID chip, and product information can be read using an RFID reader. RFID traceability is highly automated and real-time, effectively improving the accuracy and efficiency of traceability. However, it is relatively expensive.
[0005] The above methods may also have problems such as untimely information updates, inaccurate data, incomplete traceability chains, and information damage and forgery, which may prevent the full traceability and precise supervision of products from being achieved in practical applications.
[0006] Therefore, there is an urgent need for an effective information security traceability method to effectively avoid security problems such as unreliable traceability information, leakage of sensitive information during the reporting process, and illegal retention and tampering of information by application parties, and to effectively enhance the authenticity, integrity and security of information in the process of real-name information traceability. Summary of the Invention
[0007] Based on the above analysis, this invention aims to disclose an information security traceability method for an electronic authentication system utilizing commercial cryptographic algorithms. By employing commercial cryptographic algorithms to encrypt key data, the confidentiality and integrity of the original information are effectively ensured, enabling secure and accurate traceability of relevant information and ensuring the reliability of information security and the traceability process.
[0008] This invention discloses an information security traceability method for an electronic authentication system utilizing commercial cryptographic algorithms, comprising:
[0009] On the certification body side, the mark generation equipment creates and issues electronic certification marks encrypted with commercial cryptographic algorithms upon application by the product manufacturer; at the same time, it binds the business information related to the electronic certification mark and sends it to the traceability management platform.
[0010] On the product manufacturer's side, the product manufacturing equipment that meets the conditions for receiving electronic certification marks receives the electronic certification marks and applies them to the internal secure storage of the certified products it produces; and the filing information generated by the certification product filing is sent to the traceability management platform on the one hand, and a traceability QR code is generated and engraved or pasted on the product surface on the other hand.
[0011] On the product user side, product traceability can be achieved by scanning the traceability QR code on the product surface with a terminal, or by logging into the traceability management platform to trace business information and filing information.
[0012] Furthermore, the process by which the mark generation device, upon application by the product manufacturer, creates an electronic authentication mark encrypted with commercial cryptographic algorithms includes:
[0013] 1) The product manufacturer sends product information, including product ID, batch number, production date, the product manufacturer's unique manufacturer code, and the location where the product manufacturer uses the electronic certification mark to the mark generation device;
[0014] 2) The mark generation device uses commercial cryptographic algorithms to encrypt product information and uses set encoding rules or algorithms to convert the encrypted product information into a specific form of electronic certification mark, including strings or QR codes.
[0015] 3) Bind the business information related to the creation of electronic certification marks, including product type, manufacturer name, certificate number, and number of electronic certification marks applied for by the manufacturer, and send it to the traceability management platform for product traceability.
[0016] Furthermore, a mark carrier tool is used as the storage carrier for the electronic certification mark; the mark generation device sends the information, including the electronic certification mark, in encrypted form to the authorized mark carrier tool for secure storage; the mark carrier tool is transported to the product manufacturer's side, where the product manufacturing equipment retrieves the electronic certification mark and applies it to the product.
[0017] Furthermore, information, including electronic certification marks, is transmitted in encrypted form to authorized mark carrier tools for secure storage; including:
[0018] 1) Authorization of logo carrier tools;
[0019] After the logo generation device connects with the authorized logo carrier tool, two-way authentication is performed; the logo generation device authorizes the logo carrier tool that has successfully completed two-way authentication.
[0020] The two-way authentication utilizes the first key issued to the token carrier tool by the cryptographic device when the token carrier tool leaves the factory, and negotiates the key with the token generation device to achieve two-way authentication between the token generation device and the token carrier tool, and then authorizes the token carrier tool.
[0021] 2) Encrypted message distribution;
[0022] After two-way identity authentication, the mark generation device will generate an electronic certification mark for the manufacturer, which will be used as a second key for verifying the consistency of the manufacturer code and key negotiation between the mark carrier tool and the product manufacturing equipment. Information such as the unique manufacturer code of the product manufacturer and the location where the product manufacturer uses the electronic certification mark will be sent to the mark carrier tool in encrypted form.
[0023] 3) Secure storage;
[0024] The flag carrier tool decrypts the received ciphertext and then stores it securely.
[0025] Furthermore, on the product manufacturer's side, after the mark carrier tool is delivered to the manufacturer and connected to the product manufacturing equipment, the mark carrier tool determines whether the product manufacturing equipment meets the conditions for receiving electronic certification marks. If the conditions are met, the mark carrier tool is activated, allowing the electronic certification mark to be securely accessed; otherwise, the access to the electronic certification mark is rejected.
[0026] Furthermore, the process of initiating the electronic certification mark carrier tool to determine if it meets the acceptance criteria includes:
[0027] 1) Geographical location verification;
[0028] The location of the marker carrier tool after connecting to the product manufacturing equipment is compared with the location of the electronic certification mark issued by the product manufacturer by the stored marker generation equipment to determine whether it is within the set distance range. If yes, the current location is within the set activation geographical location; geographical location verification is successful.
[0029] 2) Consistency verification;
[0030] After the tag carrier tool is connected to the product manufacturing equipment, the product manufacturing equipment sends the unique manufacturer code of the product manufacturer, which is encrypted with a second key, to the tag carrier tool. After the tag carrier tool decrypts the code, it performs a consistency verification with the stored unique manufacturer code information of the product manufacturer. If the consistency verification is successful, the currently connected product manufacturing equipment is the designated user.
[0031] When a product manufacturer applies for an electronic certification mark from a certification body, the certification body issues a second key to the product manufacturer via a cryptographic device for key negotiation with the mark carrier tool.
[0032] 3) Once both the geographic location verification and the consistency verification are passed, the mark carrier tool is activated, allowing the use of the electronic certification mark; otherwise, the mark carrier tool is not activated, and the use of the electronic certification mark is rejected.
[0033] Furthermore, after the marker carrier tool is activated, it needs to perform two-way authentication with the product manufacturing equipment again; only after successful two-way authentication is the product manufacturing equipment allowed to securely access the electronic authentication marker stored therein.
[0034] Furthermore, the two-way authentication process includes:
[0035] 1) The tag carrier tool generates a random number 1 and sends the random number 1 and the product ID to the product manufacturing equipment;
[0036] 2) The product manufacturing equipment generates random number 2, and encrypts random number 2, the received random number 1, and the product ID together using the second key, and then sends the ciphertext to the carrier tool.
[0037] 3) The carrier tool decrypts the received ciphertext and compares the decrypted random number 1 and product ID with the random number 1 and ID it sent; if they match, proceed to the next step.
[0038] 3) The carrier tool encrypts the random number 2 and the product ID using its own stored second key, and then sends the ciphertext to the product manufacturing equipment. The manufacturing system decrypts the ciphertext and compares whether the decrypted random number 2 and the product ID are consistent. If they are consistent, two-way authentication is completed.
[0039] Furthermore, after two-way authentication between the mark carrier tool and the product manufacturing equipment, the product manufacturing equipment loads the electronic certification mark, distributes the electronic certification mark to the product and stores it securely. At the same time, the production information, including product ID, production batch, production date, and generating equipment number, is bound to the generated filing record information. On the one hand, it is sent to the traceability management platform, and on the other hand, a traceability QR code is generated and engraved or pasted on the product surface.
[0040] Furthermore, the registration process for certified products involving product manufacturing equipment includes:
[0041] 1) Production information binding;
[0042] The electronic certification mark retrieved from the mark carrier tool will be bound to the production information of the manufactured product, including product ID, production batch, production date, and generating device number.
[0043] 2) Generate filing information;
[0044] After binding, the information is digitally signed using commercial cryptographic algorithms, and a filing information with an electronic certification mark is generated.
[0045] Digital signatures ensure the integrity and immutability of data during transmission and storage, and bind electronic certification marks to production information and generate filing data information under encrypted conditions.
[0046] 3) Generate traceability QR codes and report filing information;
[0047] Generate a QR code based on the registration information, and then engrave or paste the QR code onto the product surface;
[0048] The system submits registration information to the traceability management platform via the internet; the traceability management platform associates and stores the received registration information with business information related to the electronic certification mark.
[0049] This invention can achieve one of the following beneficial effects:
[0050] Safe and reliable; This method is based on commercial cryptographic algorithms and proposes a highly secure information authentication scheme. Through two-way entity authentication and data integrity verification, it achieves smooth data migration throughout the system and ensures the safety and reliability of information.
[0051] It effectively ensures the secure operation of the electronic authentication system, protecting the security of the entire process of data source, transmission and storage through commercial cryptographic algorithms, making the electronic authentication mark system more secure;
[0052] This method effectively ensures information traceability by binding the electronic certification mark (i.e., the unique code) with product production information, thereby enabling the secure storage and traceability of information registered in the electronic certification mark system. Attached Figure Description
[0053] The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. Throughout the drawings, the same reference numerals denote the same parts.
[0054] Figure 1 This is a flowchart illustrating the information security traceability method of an electronic authentication system utilizing commercial cryptographic algorithms in an embodiment of the present invention. Detailed Implementation
[0055] Preferred embodiments of the present invention will now be described in detail with reference to the accompanying drawings, which form part of this application and, together with the embodiments of the present invention, serve to illustrate the principles of the present invention.
[0056] This invention discloses an information security traceability method for an electronic authentication system utilizing commercial cryptographic algorithms, such as... Figure 1 As shown, it includes:
[0057] Step S1: On the certification authority side, the mark generation device creates and issues electronic certification marks encrypted with commercial cryptographic algorithms upon application by the product manufacturer; at the same time, it binds the business information related to the electronic certification mark and sends it to the traceability management platform.
[0058] Step S2: On the product manufacturer's side, the product manufacturing equipment that meets the conditions for receiving electronic certification marks receives the electronic certification marks and applies them to the internal secure storage of the certified products it produces; and the filing information generated by the certification product filing is sent to the traceability management platform on the one hand, and a traceability QR code is generated and engraved or pasted on the product surface on the other hand.
[0059] Step S3: On the product user side, product traceability is performed by scanning the traceability QR code on the product surface using a terminal, or by logging into the traceability management platform to trace business information and filing information.
[0060] Specifically, in this embodiment, the electronic mark (electronic certification mark) is an electronic certification mark, including mandatory certification marks and voluntary certification marks. Voluntary certification marks include nationally unified voluntary certification marks and certification marks developed by certification bodies themselves. Mandatory certification marks and nationally unified voluntary certification marks are nationally proprietary certification marks. This certification mark is used to confirm the authenticity, legality, and reliability of products, services, or information. Each compliant product corresponds to a unique certification mark. Through the certification mark, users can quickly identify certified products, enhancing trust and ensuring transaction security.
[0061] Specifically, in step S1, the process of the mark generation device creating an electronic authentication mark encrypted with commercial cryptographic algorithms for the product manufacturer upon application includes:
[0062] 1) The product manufacturer sends product information, including product ID, batch number, production date, the product manufacturer's unique manufacturer code, and the location where the product manufacturer uses the electronic certification mark to the mark generation device;
[0063] The mark generation equipment is a system used by certification authorities to issue electronic certification marks. The system produces electronic certification marks according to the application requirements of certified product manufacturers and the type of product applied for.
[0064] 2) The mark generation device uses commercial cryptographic algorithms to encrypt product information and uses set encoding rules or algorithms to convert the encrypted product information into a specific form of electronic certification mark, including strings or QR codes.
[0065] The commercial cryptographic algorithms include cryptographic algorithms such as SM2, SM3 and SM4; the encoding rules or algorithms may also adopt existing rules or algorithms according to user needs.
[0066] 3) Bind the business information related to the creation of electronic certification marks, including product type, manufacturer name, certificate number, and number of electronic certification marks applied for by the manufacturer, and send it to the traceability management platform for product traceability.
[0067] In this embodiment, a mark carrier tool is used as the storage carrier for the electronic certification mark; the mark generation device sends the information, including the electronic certification mark, in encrypted form to the authorized mark carrier tool; the mark carrier tool is transported to the product manufacturer's side, where the product manufacturing equipment calls up the electronic certification mark and applies it to the product.
[0068] Specifically, information, including electronic certification marks, will be transmitted in encrypted form to authorized mark carrier tools; including:
[0069] 1) Authorization of logo carrier tools;
[0070] After the logo generation device connects with the authorized logo carrier tool, two-way authentication is performed; the logo generation device authorizes the logo carrier tool that has successfully completed two-way authentication.
[0071] The two-way authentication utilizes the first key issued to the token carrier tool by the cryptographic device when the token carrier tool leaves the factory, and negotiates the key with the token generation device to achieve two-way authentication between the token generation device and the token carrier tool, and then authorizes the token carrier tool.
[0072] 2) Encrypted message distribution;
[0073] After two-way identity authentication, the mark generation device will generate an electronic certification mark for the manufacturer, which will be used as a second key for verifying the consistency of the manufacturer code and key negotiation between the mark carrier tool and the product manufacturing equipment. Information such as the unique manufacturer code of the product manufacturer and the location where the product manufacturer uses the electronic certification mark will be sent to the mark carrier tool in encrypted form.
[0074] 3) Secure storage procedures;
[0075] The flag carrier tool decrypts the received ciphertext and then stores it securely.
[0076] In this step, the mark carrier tool uses the first key issued when the mark carrier tool leaves the factory to negotiate a key with the mark generation device to achieve two-way identity authentication; information including the electronic certification mark is obtained and stored securely using encryption, ensuring that the carrier for obtaining the electronic certification mark is an authorized carrier, and is transmitted in encrypted form to ensure the confidentiality of information transmission.
[0077] To achieve the above functions, the token carrier tool includes a key management module, an algorithm module, and a storage module; among them...
[0078] The key management module is used to manage keys, including the first key and the second key.
[0079] The first key is used for key negotiation between the token carrier tool and the token generation device, and is distributed to the token carrier tool through the cryptographic device when the token carrier tool leaves the factory;
[0080] The second key is used for vendor code consistency verification and key negotiation between the token carrier tool and the product manufacturing equipment. When the certification authority authorizes the token carrier tool, it is issued to the token carrier tool through a cryptographic device.
[0081] The algorithm module uses cryptographic algorithms including SM2, SM3 and SM4. When connected to a mark generation device or product manufacturing device, it uses the obtained first key or second key to perform key negotiation and complete two-way identity authentication.
[0082] The storage module is used to securely store the electronic certification mark produced by the manufacturer after decrypting the encrypted text sent by the mark generation device, the second key used for verifying the consistency of the manufacturer code and key negotiation between the mark carrier tool and the product manufacturing equipment, the unique manufacturer code of the product manufacturer, and the location information of the product manufacturer using the electronic certification mark.
[0083] Specifically, in step S2, on the product manufacturer's side, after the mark carrier tool is delivered to the manufacturer and connected to the product manufacturing equipment, the mark carrier tool determines whether the product manufacturing equipment meets the electronic certification mark reception conditions; if the conditions are met, the mark carrier tool starts and allows the electronic certification mark to be securely accessed; otherwise, it rejects the access of the electronic certification mark.
[0084] The process of determining whether the electronic certification mark acceptance criteria are met and the activation of the mark carrier tool includes:
[0085] 1) Geographical location verification;
[0086] The location of the marker carrier tool after connecting to the product manufacturing equipment is compared with the location of the electronic certification mark issued by the product manufacturer by the stored marker generation equipment to determine whether it is within the set distance range. If yes, the current location is within the set activation geographical location; geographical location verification is successful.
[0087] 2) Consistency verification;
[0088] After the tag carrier tool is connected to the product manufacturing equipment, the product manufacturing equipment sends the unique manufacturer code of the product manufacturer, which is encrypted with a second key, to the tag carrier tool. After the tag carrier tool decrypts the code, it performs a consistency verification with the stored unique manufacturer code information of the product manufacturer. If the consistency verification is successful, the currently connected product manufacturing equipment is the designated user.
[0089] When a product manufacturer applies for an electronic certification mark from a certification body, the certification body issues a second key to the product manufacturer via a cryptographic device for key negotiation with the mark carrier tool.
[0090] 3) Once both the geographic location verification and the consistency verification are passed, the mark carrier tool is activated, allowing the use of the electronic certification mark; otherwise, the mark carrier tool is not activated, and the use of the electronic certification mark is rejected.
[0091] To achieve the above functions, the sign carrier tool is also equipped with a start control module and a positioning module;
[0092] Startup control module; used to determine the startup status after the marker carrier tool is connected to the product manufacturing equipment;
[0093] The positioning module is used for positioning the marker carrier tool; the positioning module includes modules with positioning functions, such as a 4G module.
[0094] Specifically, in step S2, after the marker carrier tool is started, it needs to perform two-way authentication with the product manufacturing equipment again; only after the two-way authentication is successful can the product manufacturing equipment securely access the electronic authentication marker stored therein.
[0095] Specifically, the two-way authentication process for the identification carrier tool and the product manufacturing equipment includes:
[0096] 1) The tag carrier tool generates a random number 1 and sends the random number 1 and the product ID to the product manufacturing equipment;
[0097] 2) The product manufacturing equipment generates random number 2, and encrypts random number 2, the received random number 1, and the product ID together using the second key, and then sends the ciphertext to the carrier tool.
[0098] 3) The carrier tool decrypts the received ciphertext and compares the decrypted random number 1 and product ID with the random number 1 and ID it sent; if they match, proceed to the next step.
[0099] 4) The carrier tool encrypts the random number 2 and the product ID using its own stored second key, and then sends the ciphertext to the product manufacturing equipment. The manufacturing system decrypts the ciphertext and compares whether the decrypted random number 2 and the product ID are consistent. If they are consistent, two-way authentication is completed.
[0100] In this step, the electronic certification mark acceptance conditions are first determined. Only when these conditions are met can the mark carrier tool be activated. These conditions include both user consistency verification and activation geographical location determination. The mark carrier tool can only be activated by a designated user within the specified activation geographical location. After activation, two-way identity authentication is performed again before the product manufacturing equipment is allowed to securely access the electronic certification mark. This effectively prevents unauthorized areas or unauthorized users from fraudulently applying the mark, ensuring the authenticity and reliability of the certification process and truly achieving information-based and digital certification of products. It meets the regulatory requirements of relevant departments for certified products while ensuring that products with applied electronic certification marks are controllable and trustworthy.
[0101] After two-way authentication between the marking carrier tool and the product manufacturing equipment, the product manufacturing equipment loads the electronic certification mark, which is then distributed to the product and stored securely. At the same time, production information, including product ID, production batch, production date, and generating equipment number, is bound to the generated filing record information. This information is sent to the traceability management platform on one hand, and a traceability QR code is generated and engraved or pasted onto the product surface on the other.
[0102] Specifically, the registration process for product manufacturing equipment for certified products includes:
[0103] 1) Production information binding;
[0104] The electronic certification mark retrieved from the mark carrier tool will be bound to the production information of the manufactured product, including product ID, production batch, production date, and generating device number.
[0105] 2) Generate filing information;
[0106] After binding, the information is digitally signed using commercial cryptographic algorithms, and a filing information with an electronic certification mark is generated.
[0107] Digital signatures ensure the integrity and immutability of data during transmission and storage, and bind electronic certification marks to production information and generate filing data information under encrypted conditions.
[0108] 3) Generate traceability QR codes and report filing information;
[0109] Generate a QR code based on the registration information, and then engrave or paste the QR code onto the product surface;
[0110] The system submits registration information to the traceability management platform via the internet; the traceability management platform associates and stores the received registration information with business information related to the electronic certification mark.
[0111] Before the initial submission, product manufacturers apply for a login account on the traceability management platform through a certification body. After obtaining the account, manufacturers can submit the filing information documents themselves. After submission, the filing information is recorded on the product at the URL address of the traceability management platform.
[0112] Manufacturers may submit filing information documents in batches or at fixed times. However, in order to facilitate public access to the filing information, the filing information should be submitted no later than before the product is sold.
[0113] The method in this embodiment encrypts critical data at the data generation source using commercial cryptographic algorithms to ensure the confidentiality of the original information. Furthermore, an encrypted communication mechanism is used during the data reporting to the management system to guarantee the security of data transmission and prevent data theft or tampering. In the data storage stage, commercial cryptographic algorithms are used to encrypt and protect the stored data, and a strict data access control policy is established, ensuring that only authorized personnel can access the encrypted data.
[0114] Furthermore, the registration information is secure and traceable. During network transmission, sensitive information such as key information and identification information is encrypted using commercial cryptographic algorithms to ensure the confidentiality of information transmitted over the network. To achieve product traceability, every data operation and transfer is recorded in a dedicated registration information log, which is also encrypted using commercial cryptographic algorithms. End users can view the traceability information of relevant products by scanning the product's QR code or visiting the UR website.
[0115] In summary, the information security traceability method for the electronic authentication system utilizing commercial cryptographic algorithms in this embodiment is secure and reliable. Based on commercial cryptographic algorithms, it proposes a highly secure information authentication scheme. Through two-way entity authentication and data integrity verification, it achieves smooth data migration throughout the system, ensuring information security and reliability. It effectively guarantees the secure operation of the electronic authentication system by protecting the security of the data source, transmission, and storage process through commercial cryptographic algorithms, making the electronic authentication mark system more secure. It also effectively ensures information traceability by binding the electronic authentication mark (i.e., the unique code) to product production information, achieving secure storage and traceability of the registered information within the electronic authentication mark system.
[0116] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in the present invention should be included within the scope of protection of the present invention.
Claims
1. An information security traceability method of an electronic authentication system using a commercial cryptographic algorithm, characterized by, Comprise: On the side of the certification authority, the logo generation device makes and issues electronic authentication logo encrypted with commercial cryptographic algorithm for product manufacturers under their application; at the same time, the business information related to the electronic authentication logo is bound and sent to the traceability management platform; On the side of the product manufacturer, the product production equipment that meets the receiving conditions of the electronic authentication logo receives the electronic authentication logo and applies it to the internal secure storage of the certified product it produces; and the record information generated by the certified product is recorded, which is sent to the traceability management platform on the one hand, and the traceability two-dimensional code is engraved or pasted on the surface of the product on the other hand; On the side of the product user, the product traceability is carried out by scanning the traceability two-dimensional code on the surface of the product through the terminal, or logging in to the traceability management platform to trace the business information and record information.
2. The information security traceability method of the electronic authentication system using commercial cryptographic algorithm according to claim 1, characterized in that, The process of the logo generation device making the electronic authentication logo encrypted with commercial cryptographic algorithm for the product manufacturer under its application comprises: 1) The product manufacturer sends the product information including product ID, batch, production date, the unique manufacturer code of the product manufacturer, and the location of the product manufacturer using the electronic authentication logo to the logo generation device; 2) The logo generation device uses commercial cryptographic algorithm to encrypt the product information, and converts the encrypted product information into electronic authentication logo in a specific form including string or two-dimensional code by using a set of encoding rules or algorithms; 3) The business information related to the making of the electronic authentication logo, including product type, manufacturer name, certificate number, and the number of electronic authentication logos applied by the manufacturer, is bound and sent to the traceability management platform for product traceability.
3. The information security traceability method of the electronic authentication system using commercial cryptographic algorithm according to claim 1, characterized in that, The logo carrier tool is used as the storage carrier of the electronic authentication logo; the logo generation device sends the information including the electronic authentication logo to the authorized logo carrier tool in ciphertext for secure storage; the logo carrier tool is carried to the product manufacturer side, and the electronic authentication logo is called by the product production equipment and applied to the product.
4. The information security traceability method of the electronic authentication system using commercial cryptographic algorithm according to claim 3, characterized in that, The information including the electronic authentication logo is sent to the authorized logo carrier tool in ciphertext for secure storage; comprising: 1) Logo carrier tool authorization; After the logo generation device is connected with the authorized logo carrier tool, bidirectional identity authentication is performed; the logo generation device authorizes the logo carrier tool that passes the bidirectional identity authentication; The bidirectional identity authentication uses the first key issued to the logo carrier tool by the password machine device when the logo carrier tool is manufactured, and performs key negotiation with the logo generation device to authorize the logo carrier tool after the bidirectional identity authentication between the logo generation device and the logo carrier tool; 2) Ciphertext delivery; After the two-way identity authentication, the logo generation device will make electronic authentication logo for the manufacturer, which is used for the manufacturer code consistency verification and the second key negotiation between the logo carrier tool and the product production equipment. The unique manufacturer code of the product manufacturer and the location information of the product manufacturer using the electronic authentication logo are sent to the logo carrier tool by ciphertext; 3) secure storage; The logo carrier tool decrypts the received ciphertext and performs secure storage.
5. The information security traceability method of the electronic authentication system using commercial cryptographic algorithms according to claim 3, characterized in that, On the product manufacturer side, after the logo carrier tool is carried to the manufacturer and connected with the product production equipment, the logo carrier tool judges whether the product production equipment meets the electronic authentication logo receiving conditions; If the conditions are met, the logo carrier tool is started and the electronic authentication logo is allowed to be safely called; Otherwise, the electronic authentication logo calling is rejected.
6. The information security traceability method of the electronic authentication system using commercial cryptographic algorithms according to claim 5, characterized in that, If the conditions are met, the logo carrier tool is started and the electronic authentication logo is allowed to be safely called; Otherwise, the electronic authentication logo calling is rejected.
6. The information security traceability method of the electronic authentication system using commercial cryptographic algorithms according to claim 5, characterized in that, 1) geographical location verification; The positioning location of the logo carrier tool after being connected with the product production equipment is compared with the stored location of the product manufacturer using the electronic authentication logo sent by the logo generation device to judge whether it is within the set distance range. If yes, the current location is within the set starting geographical location; the geographical location verification is passed; 2) consistency verification; After the logo carrier tool is connected with the product production equipment, the product production equipment sends the unique manufacturer code of the product manufacturer encrypted by the second key to the logo carrier tool. After decryption by the logo carrier tool, consistency verification is performed with the stored unique manufacturer code information of the product manufacturer. After the consistency verification is passed, the currently connected product production equipment is the set user; 3) After the geographical location verification and the consistency verification are both passed, the logo carrier tool is started and the electronic authentication logo is allowed to be called; otherwise, the logo carrier tool is not started and the electronic authentication logo calling is rejected.
8. The information security traceable method of an electronic authentication system using a commercial cryptographic algorithm according to claim 7, characterized in that, 7. The information security traceability method of the electronic authentication system using commercial cryptographic algorithms according to claim 5, characterized in that, After the logo carrier tool is started, it needs to be authenticated again with the product production equipment; after the two-way identity authentication is successful, the product production equipment is allowed to safely call the stored electronic authentication logo. The two-way identity authentication process includes: 1) the logo carrier tool generates random number 1 and sends the random number 1 and the product ID to the product production equipment; 2) the product production equipment generates random number 2 and encrypts the random number 2 together with the received random number 1 and product ID using the second key, and then sends the ciphertext to the carrier tool; 3) the carrier tool decrypts the received ciphertext and compares the decrypted random number 1 and product ID with the random number 1 and ID sent by itself; if they are consistent, the next step is entered; 3) The carrier tool encrypts the random number 2 and the product ID with the second key stored in itself, and sends the ciphertext to the product production equipment. The production system decrypts the ciphertext and compares the decrypted random number 2 and the product ID to determine whether they are consistent. If they are consistent, the two-way identity authentication is completed.
9. The information security traceability method of the electronic authentication system using a commercial cryptographic algorithm according to claim 8, characterized in that, After the two-way authentication of the sign carrier tool and the product production equipment, the product production equipment loads the electronic authentication sign, and sends the electronic authentication sign to the product and stores it securely. At the same time, the production information including the product ID, production batch, production date, and production equipment number is bound to generate the record information. The record information is sent to the traceability management platform on one hand, and the traceability QR code is generated and engraved or pasted on the surface of the product on the other hand.
10. The information security traceability method of the electronic authentication system using a commercial cryptographic algorithm according to claim 9, characterized in that, The record process of the product production equipment for the authentication product includes: 1) Production information binding; The electronic authentication sign called from the sign carrier tool and the production information including the product ID, production batch, production date, and production equipment number of the production product are bound. 2) Generating record information; The bound information is digitally signed using a commercial cryptographic algorithm, and the record information with the electronic authentication sign is generated after completion. The digital signature ensures the integrity and tamper resistance of the data during transmission and storage, and completes the binding of the electronic authentication sign and the production information and generates the record data information in the case of encryption. 3) Generating a traceability QR code and reporting record information; The QR code is generated according to the record information, and is engraved or pasted on the surface of the product. The record information is reported to the traceability management platform through the Internet, and the traceability management platform stores the received record information and the business information related to the electronic authentication sign in association.