A passport security verification method and system

By generating negotiation state nodes and directed graph data structures, the radio frequency link status during the passport verification process is dynamically evaluated, which solves the problem of insufficient protection in passport verification in the existing technology and realizes dynamic protection and tamper identification of passport data.

CN122020736BActive Publication Date: 2026-06-16SHENZHEN DECARD SMART CARD TECH
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHENZHEN DECARD SMART CARD TECH
Filing Date
2026-04-10
Publication Date
2026-06-16

AI Technical Summary

Technical Problem

Existing passport verification technologies are unable to identify communication anomalies when faced with complex electromagnetic interference and malicious message retransmissions, and cannot effectively prevent the tampering and forgery of data blocks inside the passport, resulting in insufficient security.

Method used

By collecting the handshake negotiation messages between the passport control machine and the electronic passport, negotiation state nodes are generated. Combined with the cumulative results of communication path penalty and the directed graph data structure, the radio frequency link status is dynamically evaluated to identify and prevent data tampering.

Benefits of technology

It effectively resists environmental interference and abnormal message retransmission, detects structural tampering of specific data blocks, and enhances the protection of passport verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122020736B_ABST
    Figure CN122020736B_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of identity authentication, in particular to a passport security verification method and system, handshake message is collected and spliced to generate negotiation state node, transfer frequency is counted and decay penalty is introduced to accumulate path cost; according to this, global directory is parsed to extract data group length and hash dependence mapping, topological out-of-queue is used to calculate group summary difference, whether tampering is determined and verification result is output. In the present application, negotiation state node is constructed by extracting message exception flag and baud rate, and path accumulation is carried out in combination with penalty coefficient, the passport function can dynamically evaluate the state of the radio frequency link in the early stage of interaction, effectively resist environmental interference and abnormal message retransmission, at the same time, directed graph data structure is constructed based on the byte length and hash dependence identification of global file, topological logic is used to derive the out-of-queue sequence without predecessor node, the passport verification is driven to read according to the internal correlation, in combination with the summary comparison mechanism, the structural tampering and forgery of specific data block are cracked.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of identity authentication technology, and in particular to a passport security verification method and system. Background Technology

[0002] The field of identity authentication technology involves the collection, comparison, and authenticity verification of individual identity information. It covers biometric collection such as fingerprint image acquisition and feature point matching, facial image acquisition and key point comparison, iris texture acquisition and encoding comparison, as well as digital certificate verification and key negotiation processes based on document information. It also includes the encryption and encapsulation of identity data during transmission, random number generation, message digest calculation, and integrity verification.

[0003] The passport security verification method refers to a process in which the basic information data file of the passport holder and the security object document in the passport chip are read during the entry and exit inspection. The data signature value is verified according to the public key of the issuing authority. A random number is generated and sent to the passport chip. The chip uses its internal private key to calculate the response value and returns it to the verification terminal. Then, the facial image collected on site is compared point by point with the facial image feature point data stored in the chip to complete the consistency verification of the passport holder and the document.

[0004] Existing passport verification technologies mainly rely on fixed signature verification and image comparison. This static operating mode lacks a dynamic monitoring mechanism for channel fluctuations and handshake message status during the underlying radio frequency communication establishment phase. It is difficult to identify complex electromagnetic interference and malicious message retransmission, which can easily lead to false rejection and interruption risks when communication is abnormal. At the same time, facing numerous independent data groups within the passport, traditional reading methods ignore the hash dependency relationship of the data structure within the file stream, making it difficult to prevent tampering and forgery of specific structured data blocks, resulting in potential vulnerabilities in the overall security. Summary of the Invention

[0005] The purpose of this invention is to address the shortcomings of existing technologies by proposing a passport security verification method and system.

[0006] To achieve the above objectives, the present invention adopts the following technical solution: a passport security verification method, comprising the following steps:

[0007] S1: Collect the handshake negotiation messages between the passport machine and the electronic passport, and perform position concatenation operation between the error flag of the handshake message check bit and the passport communication baud rate to generate a negotiation state node;

[0008] S2: Collect the negotiation state reference transition frequency of the continuously generated negotiation state nodes, preset the attenuation penalty coefficient, calculate the product of the two and perform path accumulation to obtain the cumulative communication path penalty result;

[0009] S3: Based on the cumulative result of the communication path penalty, read the passport global directory file data, extract the byte length and hash dependency identifier of the independent data group of the passport data group, and generate the passport data group structure parameters;

[0010] S4: Construct a directed graph data structure based on the passport data group structure parameters, use the passport data group byte length as weight and hash dependency identifier as directed edge, perform a no-predecessor node removal calculation on the directed graph data structure, and generate a no-predecessor node dequeue sequence for the passport data group.

[0011] S5: Based on the passport data group without a predecessor node dequeue sequence, read the independent data groups in sequence, calculate the difference between the passport data group summary and the passport document comparison item to obtain the passport data matching deviation, determine whether the passport data has been tampered with, and generate the passport verification result.

[0012] As a further embodiment of the present invention, the negotiation state node includes a handshake message check bit error flag and a passport communication baud rate. The cumulative result of the communication path penalty is obtained by calculating the negotiation state reference transition frequency and the attenuation penalty coefficient. The passport data group structure parameters include the passport data group byte length and hash dependency identifier. The passport data group dequeue sequence without a predecessor node includes independent data groups and no predecessor node. The passport verification result is obtained by judging the passport data matching deviation.

[0013] As a further aspect of the present invention, the step of obtaining the negotiation state node specifically includes:

[0014] S111: Collect interactive data generated when the user places the electronic passport into the sensing area of ​​the passport machine, obtain the handshake negotiation message received and transmitted between the passport machine and the electronic passport by the underlying radio frequency communication probe in the sensing area, parse the communication protocol data frame inside the handshake negotiation message, extract the bit status information inside the communication protocol data frame and separate the error flag of the handshake message check bit.

[0015] S112: Read the RF communication band configuration parameters generated when the passport machine's underlying RF communication probe receives the handshake negotiation message, parse the RF communication band configuration parameters and obtain the passport communication baud rate of the electronic passport in the current interaction process, and perform numerical conversion on the passport communication baud rate to obtain the passport communication baud rate value.

[0016] S113: The handshake message check bit error flag and the passport communication baud rate value are concatenated to form a binary data segment sequence, which is then merged with the RF communication probe hardware identifier encoding to generate a negotiation state node.

[0017] As a further aspect of the present invention, the step of obtaining the cumulative result of the communication path penalty specifically includes:

[0018] S211: Obtain the negotiation state nodes at the current time and the previous time, determine the state transition characteristics between the nodes based on the two negotiation state nodes, analyze the negotiation state reference transition frequency in the passport machine that matches the state transition characteristics, synchronously obtain the preset attenuation penalty coefficient, determine whether the handshake message check bit error flag is in an active state, and extract the error activation state quantity corresponding to the check bit error flag in an active state.

[0019] S212: Based on the error activation state quantity, for the case where the error flag of the handshake message check bit is active, calculate the state correction transfer frequency value based on the negotiation state reference transfer frequency and the attenuation penalty coefficient.

[0020] S213: Obtain a parameter set consisting of multiple state correction transition frequency values ​​generated during the continuous interaction between the passport machine and the electronic passport, calculate the cumulative sum of all state correction transition frequency values ​​in the parameter set, and generate a cumulative communication path penalty result.

[0021] As a further aspect of the present invention, the step of obtaining the passport data group structure parameters specifically includes:

[0022] S311: Compare the cumulative result of the communication path penalty with the preset degradation alarm threshold. When the cumulative result of the communication path penalty is greater than the degradation alarm threshold, send a disconnection control level signal to the radio frequency communication probe through the passport device and terminate the verification process. When the cumulative result of the communication path penalty is less than the degradation alarm threshold, generate a communication connection maintenance identifier.

[0023] S312: Based on the communication connection to maintain the identifier, the passport machine sends a read command to the electronic passport to obtain the passport global directory file data, extracts the configuration information content of each independent data group in the passport from the passport global directory file data, parses the configuration information content and counts the byte length value of the passport data group in the independent data group.

[0024] S313: Use the byte length value of the passport data group as the address offset to divide the data boundary of each independent data group within the passport global directory file data. Extract the hash dependency relationship identifier of each independent data group in the passport according to the data boundary. Combine the hash dependency relationship identifier and the byte length value to generate the passport data group structure parameters.

[0025] As a further aspect of the present invention, the step of obtaining the passport data set dequeue sequence without a predecessor node specifically comprises:

[0026] S411: Referring to the passport data group structure parameters, construct a directed graph data structure in the passport machine memory, convert each independent data group in the passport data group structure parameters into a corresponding element and map it as a graph structure node inside the directed graph data structure, and statistically analyze the spatial distribution status of all graph structure node objects in the directed graph data structure to obtain the graph structure node mapping distribution value.

[0027] S412: For the graph structure node mapping distribution value, set the passport data group byte length value as the graph node weight of the corresponding graph structure node, set the directed edge connecting each graph structure node to the graph structure according to the passport data group hash dependency relationship identifier, and establish directed graph structure association parameters.

[0028] S413: Input the directed graph structure association parameters into the topology sorting logic to perform cyclic screening and removal calculations for nodes without predecessors, locate the graph structure nodes in the directed graph data structure with an in-degree value of zero, and perform removal and stripping operations to generate a passport data group dequeue sequence without predecessors.

[0029] As a further aspect of the present invention, the step of obtaining the passport verification result specifically includes:

[0030] S511: The passport data group dequeue sequence without predecessor nodes is converted into a probe order execution instruction table matched by the bottom probe of the passport machine. The passport machine obtains all independent data groups in sequence according to the probe order execution instruction table and extracts the passport data group summary value of all independent data groups.

[0031] S512: Collect passport document comparison items from passport security object documents synchronously captured by the preset passport machine, extract the passport document comparison items and compare them with the passport data group summary value, and calculate the proportion of multiple character elements in the character sequence according to the degree of difference between the two to obtain the passport data matching deviation rate.

[0032] S513: Compare the passport data matching deviation rate with a preset deviation tolerance threshold. If the passport data matching deviation rate is greater than the deviation tolerance threshold, it is confirmed that the passport data has been tampered with. If the passport data matching deviation rate is less than the deviation tolerance threshold, it is confirmed that the passport data is consistent, and a passport verification result is generated.

[0033] A passport security verification system, the system comprising:

[0034] The negotiation state generation module collects the handshake negotiation messages between the passport machine and the electronic passport, and performs position concatenation operation between the error flag of the handshake message check bit and the passport communication baud rate to generate a negotiation state node.

[0035] The communication path penalty accumulation module collects the negotiation state reference transition frequency of the continuously generated negotiation state nodes, presets the attenuation penalty coefficient, calculates the product of the two and performs path accumulation to obtain the communication path penalty accumulation result.

[0036] The passport data group structure parsing module reads the passport global directory file data based on the cumulative result of the communication path penalty, extracts the byte length and hash dependency identifier of the independent data group of the passport data group, and generates passport data group structure parameters.

[0037] The data group topology construction module constructs a directed graph data structure based on the passport data group structure parameters. Using the passport data group byte length as the weight and the hash dependency identifier as the directed edge, it performs a predecessorless node removal calculation on the directed graph data structure to generate a passport data group predecessorless node dequeue sequence.

[0038] The passport data integrity verification module reads independent data groups sequentially according to the passport data group dequeue sequence without a predecessor node, calculates the difference between the passport data group summary and the passport document comparison items to obtain the passport data matching deviation, determines whether the passport data has been tampered with, and generates a passport verification result.

[0039] Compared with the prior art, the advantages and positive effects of the present invention are as follows:

[0040] In this invention, by extracting message anomaly flags and baud rates to construct negotiation state nodes and combining them with penalty coefficients for path accumulation, the passport function can dynamically assess the radio frequency link status in the early stages of interaction, effectively resisting environmental interference and abnormal message retransmission. At the same time, a directed graph data structure is constructed based on the byte length and hash dependency identifier of the global file, and the dequeue sequence without predecessor nodes is derived using topological logic. This drives passport verification to schedule and read according to the inherent correlation. Combined with the digest comparison mechanism, it can detect structural tampering and forgery targeting specific data blocks, comprehensively filling communication blind spots and improving the protection tightness. Attached Figure Description

[0041] Figure 1 This is a schematic diagram of the workflow of the present invention;

[0042] Figure 2 This is a flowchart illustrating the process of generating negotiation state nodes in this invention.

[0043] Figure 3 This is a flowchart of the process for obtaining the cumulative result of communication path penalty in this invention;

[0044] Figure 4 This is a flowchart of the passport data group structure parameter acquisition process of the present invention;

[0045] Figure 5 This is a flowchart of the process for obtaining the dequeue sequence of passport data groups without predecessor nodes according to the present invention;

[0046] Figure 6 This is a flowchart of the passport verification result acquisition process of the present invention. Detailed Implementation

[0047] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.

[0048] Please see Figure 1 This invention provides a technical solution, a passport security verification method, comprising the following steps:

[0049] S1: Collect the handshake negotiation messages between the passport machine and the electronic passport, and perform position concatenation operation between the error flag of the handshake message check bit and the passport communication baud rate to generate a negotiation state node;

[0050] S2: Collect the reference transition frequency of the negotiation state of the continuously generated negotiation state nodes, preset the attenuation penalty coefficient, calculate the product of the two and perform path accumulation to obtain the cumulative result of communication path penalty;

[0051] S3: Based on the cumulative result of communication path penalty, read the passport global directory file data, extract the byte length and hash dependency identifier of the independent data group of the passport data group, and generate the passport data group structure parameters;

[0052] S4: Construct a directed graph data structure based on the passport data group structure parameters. Using the passport data group byte length as the weight and the hash dependency identifier as the directed edge, perform a no-predecessor node removal calculation on the directed graph data structure to generate a no-predecessor node dequeue sequence for the passport data group.

[0053] S5: Based on the out-of-queue sequence of the passport data group without a predecessor node, read the independent data groups in order, calculate the difference between the passport data group summary and the passport document comparison items to obtain the passport data matching deviation, determine whether the passport data has been tampered with, and generate the passport verification result.

[0054] The negotiation state node includes the handshake message check bit error flag and the passport communication baud rate. The cumulative communication path penalty result is obtained by calculating the negotiation state reference transfer frequency and the attenuation penalty coefficient. The passport data group structure parameters include the passport data group byte length and hash dependency identifier. The passport data group dequeue sequence without a predecessor node includes independent data groups and no predecessor node. The passport verification result is obtained by judging the passport data matching deviation.

[0055] Please see Figure 2 The specific steps for obtaining the negotiation state node are as follows:

[0056] S111: Collect interactive data generated when the user places the electronic passport into the sensing area of ​​the passport machine, obtain the handshake negotiation message received and transmitted between the passport machine and the electronic passport by the underlying radio frequency communication probe in the sensing area, parse the communication protocol data frame inside the handshake negotiation message, extract the bit status information inside the communication protocol data frame and separate the error flag of the handshake message check bit.

[0057] Electromagnetic band data monitored by the underlying RF communication probe at a frequency of 13.56 MHz was retrieved to obtain the raw analog RF signal generated when the electronic passport was placed in the sensing area. Gaussian filtering was performed on the raw analog RF signal to remove environmental electromagnetic background noise data with frequencies exceeding 0.5 MHz above and below 13.56 MHz. Z-score normalization was then applied to normalize the denoised RF signal. The mean and standard deviation of the denoised RF signal dataset were calculated. The difference between each RF signal value and the mean was calculated, and the quotient of the result was then calculated with the standard deviation to obtain a standard digital signal sequence. From this standard digital signal sequence, the handshake negotiation message received by the underlying RF communication probe and transmitted between the passport control and the electronic passport within the sensing area was extracted. Bit-by-bit reading of the communication protocol data frames within the handshake negotiation message was performed, reading the frame header synchronization byte data and the frame tail end flag data, and extracting the load data segment between these two data points. For the load data segment, a bit status information extraction operation is performed. Each data bit within the load data segment is scanned sequentially, and its corresponding high / low level state is determined. The level state is divided into two possibilities: logic high and logic low. When the data bit level value is greater than 2.5 volts, it belongs to the high-level range, and the bit status information is determined as logic high (1). When the data bit level value is less than 1.2 volts, it belongs to the low-level range, and the bit status information is determined as logic low (0). To extract the bit status information more accurately, an adaptive judgment threshold algorithm is introduced in this process. The calculation formula is as follows: ,in This represents the adaptive judgment threshold, measured in volts, which serves as the dynamic reference for ultimately distinguishing between high and low levels. The average voltage representing the ambient noise level, measured in volts, is calculated by continuously sampling the background electromagnetic environment of the sensing area and averaging the values. Indicates the first The voltage amplitude at each sampling point, measured in volts, is directly obtained through transient readings from the bottom-layer probe. This represents the total number of sampling points, with a value range of positive integers. It is obtained by accumulating and counting the discrete sampling points within a single analysis window. This represents the confidence coefficient, which ranges from 1.0 to 5.0. It is set according to the tolerance for fluctuations in the environmental electromagnetic noise floor. The more severe the noise floor fluctuations and the lower the tolerance for noise, the larger this coefficient should be. This represents the offset parameter, measured in volts. It is set based on the inherent voltage drop characteristics of the passport control's internal circuitry and is used to maintain the baseline threshold when the ambient voltage fluctuation is 0.

[0058] The parameter calculation process is as follows: extract the average voltage of the ambient noise floor, the voltage amplitude of each sampling point, the total number of sampling points, the confidence coefficient, and the specific values ​​of the offset parameter, and substitute them into the formula for calculation. The specific calculation formula is as follows: The adaptive judgment threshold is derived to be 2.1 volts. Next, the error flag of the handshake message check bit is separated, and the 8-bit parity check code data at the end of the communication protocol data frame is extracted. The number of all bits in the load data segment that are judged to be logic high level 1 is summed to obtain the total number of high-level bits. After extracting the specific total number of high-level bits, the modulo operation is performed on the total value divided by the value 2 to obtain the locally calculated check value. The check state has two possibilities: active and inactive. The locally calculated check value is compared with the corresponding bit value inside the parity check code data. If the two are not equal, the state belongs to the error triggering interval, the handshake message check bit error flag is determined to be active and assigned a value of 1; if the two are equal, the state belongs to the normal communication interval, the handshake message check bit error flag is determined to be inactive and assigned a value of 0.

[0059] S112: Read the RF communication band configuration parameters generated when the passport machine's underlying RF communication probe receives the handshake negotiation message, parse the RF communication band configuration parameters and obtain the passport communication baud rate of the electronic passport in the current interaction process, and perform numerical conversion on the passport communication baud rate to obtain the passport communication baud rate value.

[0060] The system sends a status query control command to the underlying RF communication probe and receives the configuration attribute set data, including the operating frequency parameters, transmit power parameters, and modulation depth parameters, to obtain the RF communication band configuration parameters generated during the handshake negotiation message. It then performs a parsing operation on the RF communication band configuration parameters, locates the modulation rate configuration segment in the configuration attribute set data, and extracts the raw string of the passport communication baud rate in the current interaction process. After obtaining the specific raw string of the passport communication baud rate, it removes non-numeric character suffixes to obtain a pure numeric character sequence. It then extracts each numeric character from this sequence, performs a product operation on each numeric character and its corresponding decimal weight, and finally sums all the generated product values. The resulting sum is the passport communication baud rate value.

[0061] S113: The handshake message check bit error flag and the passport communication baud rate value are concatenated to form a binary data segment sequence, which is then merged with the RF communication probe hardware identifier encoding to generate a negotiation state node.

[0062] After obtaining the specific handshake message checksum error flag and passport communication baud rate value, the error flag is expanded into a binary sequence of the corresponding length and then shifted left by a specified number of bits to obtain the shifted error flag sequence. Simultaneously, the passport communication baud rate value is converted into a baud rate binary sequence. A bitwise OR operation is performed on the shifted error flag sequence and the baud rate binary sequence to obtain a binary data segment sequence. The factory hardware serial number data of the underlying RF communication probe is extracted and converted into a probe hardware identification code. The odd-numbered bits of the binary data segment sequence and the even-numbered bits of the probe hardware identification code are extracted and subjected to an alternating interleaving combination operation to finally generate a complete negotiation state node.

[0063] Please see Figure 3 The specific steps for obtaining the cumulative result of communication path penalty are as follows:

[0064] S211: Obtain the negotiation state nodes at the current time and the previous time, determine the state transition characteristics between the nodes based on the two negotiation state nodes, analyze the negotiation state reference transition frequency in the passport machine that matches the state transition characteristics, synchronously obtain the preset attenuation penalty coefficient, determine whether the error flag of the handshake message check bit is in the active state, and extract the error activation state quantity corresponding to the check bit error flag in the active state.

[0065] After extracting the current negotiation state node generated at the current moment and the historical negotiation state node generated at the previous moment, a bitwise XOR operation is performed on the two, and the total number of bits with a value of 1 in the result is used as the inter-node state transition characteristic value. Based on this inter-node state transition characteristic value, the corresponding negotiation state reference transition frequency is retrieved from the preset state transition mapping data table. Simultaneously, the number of retries before the communication interruption is extracted from the historical failed communication interaction record set, and the preset attenuation penalty coefficient is calculated based on the reciprocal of the arithmetic mean of this data. The preset state transition mapping data table is set based on the statistical analysis of the state transition characteristic data set during historical normal interactions, determined by calculating the arithmetic mean of the frequency record data with the same transition characteristic value. Error flag states are divided into two possibilities: active and inactive. It is determined whether the value of the error flag in the handshake message checksum is strictly equal to 1. When the value is equal to 1, the state belongs to the active interval, and the preset penalty weight constant is extracted as the error active state quantity; when the value is equal to 0, the state belongs to the inactive interval. The penalty weight constant is set based on the statistics of multiple historical tampered data packets. The calculation is determined by calculating the standard deviation of the erroneous bits in the data packet from the normal baseline value. The higher the degree of deviation, the larger the weight constant is set. The value range is from 1.0 to 5.0.

[0066] S212: Based on the error activation state quantity, for the case where the error flag of the handshake message check bit is active, calculate the state correction transfer frequency value based on the negotiation state reference transfer frequency and the attenuation penalty coefficient.

[0067] When the error flag in the handshake message checksum is active, frequency smoothing correction is performed based on the acquired error activation state quantity. To improve the accuracy of frequency correction, a smoothing correction algorithm based on Bayesian posterior estimation is introduced into the product correction calculation. The error activation state quantity is incorporated as an anomaly observation scaling factor into the calculation, and its calculation formula is as follows: ,in This represents the state correction transition frequency value, measured in Hertz, which is used as the final control frequency parameter for the output. The reference transition frequency of the negotiation state is represented by Hertz, which is obtained by retrieving the mapping data table through feature matching and is used to set the prior frequency expectation. This represents the prior confidence level of the observation, with a value ranging from 0.1 to 10.0. It is calculated based on the signal-to-noise ratio attenuation data obtained in real time by the underlying RF communication probe. The more severe the signal-to-noise ratio fluctuation and the greater the attenuation in the real-time communication link, the higher this confidence level parameter should be set. This represents the historical prior confidence level, ranging from 0.1 to 10.0. It is set based on the evaluation of packet loss rate data of historical long-term communication connections. The lower the background noise of historical communication and the more stable the long-term connection, the higher the confidence level should be. This represents the preset attenuation penalty coefficient, which ranges from 0.1 to 1.0 and is calculated based on the reciprocal of the average of the set of retries before the communication interruption. This represents the error activation state quantity, with a value ranging from 1.0 to 5.0. It is calculated based on the standard deviation of the error bits in historical data packets from the baseline value and represents the penalty scaling range for anomaly verification. This represents the environmental dynamic adjustment factor, ranging from 0.5 to 2.0. Its setting is based on operating temperature data collected by the internal motherboard temperature sensor. Higher operating temperatures increase the likelihood of crystal oscillator frequency deviation, thus requiring a larger factor setting. The parameter calculation process involves extracting the specific values ​​of the negotiated state reference transition frequency, observed prior confidence, historical prior confidence, preset attenuation penalty coefficient, erroneous activation state quantity, and the environmental dynamic adjustment factor, and substituting them into the smoothing correction algorithm formula. The specific calculation formula is as follows: The final state correction transition frequency value was derived to be 60 Hz. This product operation logic, by introducing the erroneous activation state quantity and Bayesian posterior estimation processing, expands the frequency correction value corresponding to the abnormal handshake state in the calculation result and takes into account the hardware device's anti-jitter mechanism.

[0068] S213: Obtain a parameter set consisting of multiple state correction transition frequency values ​​generated during the continuous interaction between the passport machine and the electronic passport, calculate the cumulative sum of all state correction transition frequency values ​​in the parameter set, and generate a cumulative communication path penalty result.

[0069] After obtaining the state frequency parameter set, which consists of multiple state correction transition frequency values ​​generated during continuous interactions between the passport control machine and the electronic passport, the cumulative register is initialized to 0. Each state correction transition frequency value in the state frequency parameter set is read sequentially according to time. The read state correction transition frequency value is then added to the current value stored in the cumulative register, and the result is reassigned to the cumulative register. This process continues until all state correction transition frequency values ​​in the state frequency parameter set have been traversed. The final sum value stored in the cumulative register is then extracted and output as the cumulative result of the communication path penalty.

[0070] Please see Figure 4 The specific steps for obtaining the passport data group structure parameters are as follows:

[0071] S311: Compare the cumulative result of communication path penalty with the preset degradation alarm threshold. When the cumulative result of communication path penalty is greater than the degradation alarm threshold, send a disconnect RF connection control level signal to the RF communication probe through the passport device and terminate the verification process. When the cumulative result of communication path penalty is less than the degradation alarm threshold, generate a communication connection maintenance identifier.

[0072] After obtaining the specific cumulative communication path penalty result and the preset degradation alarm threshold, the cumulative communication path penalty result is compared with the preset degradation alarm threshold. The comparison result is divided into two possibilities: exceeding the blocking range and maintaining security. The preset degradation alarm threshold is set based on the statistical extraction of a set of normal fluctuation data of path penalties under historical secure communication environments. The arithmetic mean of the data set and three times the standard deviation of the data are calculated to determine the final value, which is a positive real number. When it is determined that the cumulative communication path penalty result is significantly greater than the preset degradation alarm threshold, this state belongs to the exceeding the blocking range. A disconnect RF connection control level signal is generated, forcibly pulling the power supply pin level of the underlying RF communication probe down to 0 volts, cutting off the RF antenna power source and terminating all subsequent data request processes. When it is determined that the cumulative communication path penalty result is significantly less than the preset degradation alarm threshold, this state belongs to the security maintenance range. It is confirmed that the current communication path security status meets the evaluation requirements, and a communication connection maintenance flag is generated. A logic high level 1 is written to a specific flag bit in the internal communication status register.

[0073] S312: Based on the communication connection, maintain the identification quantity, send a read command to the electronic passport through the passport machine to obtain the passport global directory file data, extract the configuration information content of each independent data group in the passport from the passport global directory file data, parse the configuration information content and count the byte length value of the passport data group in the independent data group.

[0074] The separate data sets include the passport holder text data set, the passport holder facial feature data set, and the passport security object data set;

[0075] Parse the configuration information content and count the byte length value of the passport data group in the independent data group. Specifically, extract the starting address and ending address of the passport holder text data group, the passport holder facial feature data group, and the passport security object data group.

[0076] Calculate the address offset span between the end address and the start address;

[0077] The address offset span value is determined as the passport data group byte length value;

[0078] Based on the communication connection maintenance identifier, a hexadecimal format read instruction code is sent to the electronic passport, and the returned passport global directory file data stream is received. A parsing process is performed on the passport global directory file data stream to locate the configuration information content area of ​​the independent data group within the data stream. After location, the start and end address addresses of each independent data group in the passport are read. After extracting the specific start and end address addresses of each data group, the end address value and start address value of each independent data group are extracted and the difference is calculated to obtain the corresponding address offset span value. This calculated address offset span value is then directly determined as the passport data group byte length value for the corresponding passport data group.

[0079] S313: Use the byte length value of the passport data group as the address offset to divide the data boundary of each independent data group inside the global directory file data of the passport. Extract the hash dependency relationship identifier of each independent data group in the passport according to the data boundary. Combine the hash dependency relationship identifier and the byte length value to generate the passport data group structure parameters.

[0080] The byte length value of each passport data group is extracted as the address offset. Data segments are sequentially extracted from the passport global directory file data to define the start and end boundaries of each independent data group. The header label information of each independent data group within the data boundaries is read, and the passport data group hash dependency identifier recorded in the header label information is extracted. After obtaining the specific hash dependency identifier and passport data group byte length value of each passport data group, both are converted into corresponding binary sequences. The converted hash dependency identifier binary sequence is placed in the high-order data segment, and the passport data group byte length value binary sequence is placed in the low-order data segment. A bitwise concatenation operation is performed to generate a merged overall binary sequence. This overall binary sequence is then converted back to a decimal value, and the generated decimal value is used as the passport data group structure parameter for the corresponding passport data group.

[0081] Please see Figure 5 The specific steps for obtaining the dequeue sequence of a passport data set without a predecessor node are as follows:

[0082] S411: Referring to the passport data group structure parameters, construct a directed graph data structure in the passport machine memory, convert each independent data group within the passport data group structure parameters into a corresponding element and map it to a graph structure node inside the directed graph data structure, and statistically analyze the spatial distribution status of all graph structure node objects within the directed graph data structure to obtain the graph structure node mapping distribution value.

[0083] In the computational space, contiguous storage addresses are allocated to construct an empty directed graph data structure. The generated passport data group structure parameters are read, and each independent data group corresponding to the passport data group structure parameters is transformed into a graph structure node within the directed graph data structure. For each independent data group, a corresponding node object instance is created, and the passport data group structure parameter values ​​are written into the storage attribute fields of the corresponding node object instance. The starting address values ​​of all node object instances are obtained, and the arithmetic mean of all starting address values ​​is calculated. The difference between each starting address value and the average is calculated, and the square of the difference is calculated. All the squared values ​​are accumulated, and finally, the quotient of the accumulated sum and the total number of node object instances is calculated to derive the variance value of the dispersion. This variance value is used as the graph structure node mapping distribution value.

[0084] S412: For the distribution value of the graph structure node mapping, set the byte length value of the passport data group to the graph node weight of the corresponding graph structure node, set the directed edge connecting each graph structure node to the graph structure according to the hash dependency identifier of the passport data group, and establish the directed graph structure association parameters.

[0085] For the calculated distribution values ​​of the graph structure nodes, the byte length value of the passport data group corresponding to each independent data group is extracted and assigned to the graph node weight attribute field of the corresponding graph structure node. Simultaneously, the hash dependency identifier of the passport data group is read. Dependencies are categorized into two possibilities: pointing to any node and not pointing to any node. The hash dependency identifier of each graph structure node is checked sequentially. If the hash dependency identifier indicates that it does not point to any node, this state belongs to the "no pointing" interval, and no in-degree directed edge is created. If the hash dependency identifier indicates that it points to other specific graph structure nodes, this state belongs to the "pointing" interval, and a directed graph structure edge is created in the graph region, starting from the pointed-to node and pointing to the current node. All node object instances are traversed and processed to complete the creation and mounting of all directed graph structure edges, establishing a complete set of directed graph structure association parameters.

[0086] S413: Input the directed graph structure association parameters into the topology sorting logic to perform cyclic screening and removal calculations for nodes without predecessors, locate the graph structure nodes in the directed graph data structure with an in-degree value of zero, and perform removal and stripping operations to generate a passport data group dequeue sequence without predecessors.

[0087] After inputting the established directed graph structure association parameters into the topological sorting operation logic, the total number of directed edges pointing to each node in the directed graph is accumulated to obtain the in-degree value. Nodes with an in-degree value strictly equal to 0 are selected and removed from the current directed graph. Simultaneously, the directed edge records from that node to all other nodes are erased, and the node's unique identifier is pushed into the output queue buffer. After this round of removal, the in-degree values ​​of all remaining nodes are updated. Nodes with an in-degree value equal to 0 are re-selected, and the removal operation is repeated. This process is repeated until the set of nodes in the directed graph is completely cleared. The set of node identifiers arranged in order in the output queue buffer then generates the passport data group's dequeue sequence without predecessor nodes.

[0088] Please see Figure 6 The specific steps to obtain the passport verification result are as follows:

[0089] S511: Convert the passport data set dequeue sequence without a predecessor node into a probe order execution instruction table that matches the bottom probe of the passport machine. The passport machine then obtains all independent data sets in sequence according to the probe order execution instruction table and extracts the passport data set summary value of all independent data sets.

[0090] The system reads the passport data group dequeue sequence without a predecessor node, converts the identifiers of each independent data group in the sequence into specific application protocol data unit read instruction codes for the underlying RF communication probe, and writes the instruction codes into the execution buffer according to the dequeue order to generate a probe execution order instruction table. Control signals are sent to the electronic passport according to this instruction table to obtain the original data blocks corresponding to all independent data groups. The original data block corresponding to each obtained independent data group is extracted and truncated into multiple sub-operation blocks of 512 bits in length. For the tail sub-operation blocks that are less than 512 bits, bit-filling operations (padding with 1s and 0s) are performed to force alignment to the 512-bit boundary. Sixty-four pre-set hexadecimal logical constants and eight initial hash vectors are invoked to perform multi-round iterative bitwise AND, bitwise XOR, and logical right shift operations with each sub-operation block. After completing 64 rounds of iterative processing, a final hash result data string of 256 bits is extracted and used as the passport data group digest value for the corresponding independent data group.

[0091] S512: Collect passport document comparison items from passport security object documents synchronously captured by the preset passport machine, extract passport document comparison items and compare them with passport data group summary values, and calculate the proportion of multiple character elements in the character sequence based on the degree of difference between the two to obtain the passport data matching deviation rate.

[0092] The process involves retrieving the pre-downloaded passport security object document file and deserializing its structure to extract the statically recorded character sequences of passport document comparison items for each independent data group. The character sequences and summary values ​​of the passport data groups are then extracted, and a difference accumulation count variable is initialized to 0. Following a left-to-right arrangement, characters at the same offset positions in the passport document comparison item data and the passport data group summary value are sequentially compared, with their ASCII codes matched one by one. Character comparisons are categorized into two possibilities: identical or different. If the ASCII codes are determined to be unequal, this state falls within the difference range, and the difference accumulation count variable is incremented by 1. If the characters are determined to be equal, this state falls within the identical range, and the difference accumulation count variable remains unchanged. After traversing and comparing all corresponding characters, the final statistical value of the difference accumulation count variable is obtained. This statistical value is then divided by the total character length of the passport data group summary value to obtain a decimal quotient, which is determined as the passport data matching deviation rate.

[0093] S513: Compare the passport data matching deviation rate with the preset deviation tolerance threshold. If the passport data matching deviation rate is greater than the deviation tolerance threshold, it is confirmed that the passport data has been tampered with. If the passport data matching deviation rate is less than the deviation tolerance threshold, it is confirmed that the passport data is consistent, and a passport verification result is generated.

[0094] The system retrieves the passport data matching deviation rate and compares it with an internally preset deviation tolerance threshold. The preset deviation tolerance threshold is set based on a statistical analysis of a set of log data showing reasonable error rates caused by channel physical layer attenuation during historical compliant electronic passport verification processes. This threshold is derived by calculating the sum of the arithmetic mean of this reasonable error rate data set and one standard deviation of the data, ultimately setting the preset deviation tolerance threshold to a fixed number of 0.05. After obtaining the passport data matching deviation rate and the preset deviation tolerance threshold, the system determines whether the passport data matching deviation rate is strictly greater than the preset deviation tolerance threshold. The deviation rate determination has two possibilities: legitimate release and abnormal blocking. If the deviation rate is greater than the threshold, the state belongs to the abnormal blocking range, an abnormal alarm event is triggered, a blocking code is sent to the communication control bus, and the local verification status flag variable is set to 0. If the deviation rate is less than or equal to the threshold, the state belongs to the legitimate release range, the internal data of the electronic passport is confirmed to be consistent with the document baseline data, a release code is sent to the communication control bus, and the local verification status flag variable is set to 1. The system integrates the status values ​​of local verification status flag variables with the code data from the comparison process log, and encapsulates this data to generate the final passport verification result. Experimental results show that, when dealing with a test sample library of forged passport attacks, the introduction of Bayesian posterior estimation smoothing correction and dynamic graph anti-tampering mechanisms effectively reduces the error response rate and environmental fluctuation interference in the parameter verification stages of the entire process. The overall tamper detection accuracy reaches 100%, and the false rejection rate of normal passports under complex electromagnetic environments is reduced.

[0095] A passport security verification system, the system comprising:

[0096] The negotiation state generation module collects the handshake negotiation messages between the passport machine and the electronic passport, and performs position concatenation operation between the error flag of the handshake message check bit and the passport communication baud rate to generate a negotiation state node.

[0097] The communication path penalty accumulation module collects the negotiation state reference transition frequency of continuously generated negotiation state nodes, presets the attenuation penalty coefficient, calculates the product of the two and performs path accumulation to obtain the communication path penalty accumulation result.

[0098] The passport data group structure parsing module reads the passport global directory file data based on the cumulative result of communication path penalty, extracts the byte length and hash dependency identifier of the independent data group of the passport data group, and generates passport data group structure parameters.

[0099] The data group topology construction module constructs a directed graph data structure based on the passport data group structure parameters. It uses the passport data group byte length as the weight and the hash dependency identifier as the directed edge to perform a predecessorless node removal calculation on the directed graph data structure, generating a passport data group predecessorless node dequeue sequence.

[0100] The passport data integrity verification module reads independent data groups sequentially based on the out-of-queue sequence of passport data groups without predecessor nodes, calculates the difference between the passport data group summary and the passport document comparison items to obtain the passport data matching deviation, determines whether the passport data has been tampered with, and generates the passport verification result.

[0101] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention in any other way. Any person skilled in the art may make changes or modifications to the above-disclosed technical content to create equivalent embodiments that can be applied to other fields. However, any simple modifications, equivalent changes, and modifications made to the above embodiments based on the technical essence of the present invention without departing from the scope of the present invention shall still fall within the protection scope of the present invention.

Claims

1. A passport security verification method, characterized in that, Includes the following steps: S1: Collect the handshake negotiation messages between the passport machine and the electronic passport, and perform position concatenation operation between the error flag of the handshake message check bit and the passport communication baud rate to generate a negotiation state node; S2: Collect the negotiation state reference transition frequency of the continuously generated negotiation state nodes, preset the attenuation penalty coefficient, calculate the product of the two and perform path accumulation to obtain the cumulative communication path penalty result; S3: Based on the cumulative result of the communication path penalty, read the passport global directory file data, extract the byte length and hash dependency identifier of the independent data group of the passport data group, and generate the passport data group structure parameters; S4: Construct a directed graph data structure based on the passport data group structure parameters, use the passport data group byte length as weight and hash dependency identifier as directed edge, perform a no-predecessor node removal calculation on the directed graph data structure, and generate a no-predecessor node dequeue sequence for the passport data group. S5: Read the independent data groups in sequence according to the passport data group without a predecessor node dequeue sequence, calculate the difference between the passport data group summary and the passport document comparison item to obtain the passport data matching deviation, determine whether the passport data has been tampered with, and generate the passport verification result. The specific steps for obtaining the passport data set without a predecessor node dequeue sequence are as follows: S411: Referring to the passport data group structure parameters, construct a directed graph data structure in the passport machine memory, convert each independent data group in the passport data group structure parameters into a corresponding element and map it as a graph structure node inside the directed graph data structure, and statistically analyze the spatial distribution status of all graph structure node objects in the directed graph data structure to obtain the graph structure node mapping distribution value. S412: For the graph structure node mapping distribution value, set the passport data group byte length value as the graph node weight of the corresponding graph structure node, set the directed edge connecting each graph structure node to the graph structure according to the passport data group hash dependency relationship identifier, and establish directed graph structure association parameters. S413: Input the directed graph structure association parameters into the topology sorting logic to perform cyclic screening and removal calculations for nodes without predecessors, locate the graph structure nodes in the directed graph data structure with an in-degree value of zero, and perform removal and stripping operations to generate a passport data group dequeue sequence without predecessors. The specific steps for obtaining the passport verification result are as follows: S511: The passport data group dequeue sequence without predecessor nodes is converted into a probe order execution instruction table matched by the bottom probe of the passport machine. The passport machine obtains all independent data groups in sequence according to the probe order execution instruction table and extracts the passport data group summary value of all independent data groups. S512: Collect passport document comparison items from passport security object documents synchronously captured by the preset passport machine, extract the passport document comparison items and compare them with the passport data group summary value, and calculate the proportion of multiple character elements in the character sequence according to the degree of difference between the two to obtain the passport data matching deviation rate. S513: Compare the passport data matching deviation rate with a preset deviation tolerance threshold. If the passport data matching deviation rate is greater than the deviation tolerance threshold, it is confirmed that the passport data has been tampered with. If the passport data matching deviation rate is less than the deviation tolerance threshold, it is confirmed that the passport data is consistent, and a passport verification result is generated.

2. The passport security verification method according to claim 1, characterized in that, The negotiation state node includes a handshake message checksum error flag and a passport communication baud rate. The cumulative communication path penalty result is obtained by calculating the negotiation state reference transition frequency and the attenuation penalty coefficient. The passport data group structure parameters include the passport data group byte length and hash dependency identifier. The passport data group dequeue sequence without a predecessor node includes independent data groups and those without a predecessor node. The passport verification result is obtained by judging the passport data matching deviation.

3. The passport security verification method according to claim 1, characterized in that, The specific steps for obtaining the negotiation state node are as follows: S111: Collect interactive data generated when the user places the electronic passport into the sensing area of ​​the passport machine, obtain the handshake negotiation message received and transmitted between the passport machine and the electronic passport by the underlying radio frequency communication probe in the sensing area, parse the communication protocol data frame inside the handshake negotiation message, extract the bit status information inside the communication protocol data frame and separate the error flag of the handshake message check bit. S112: Read the RF communication band configuration parameters generated when the passport machine's underlying RF communication probe receives the handshake negotiation message, parse the RF communication band configuration parameters and obtain the passport communication baud rate of the electronic passport in the current interaction process, and perform numerical conversion on the passport communication baud rate to obtain the passport communication baud rate value. S113: The handshake message check bit error flag and the passport communication baud rate value are concatenated to form a binary data segment sequence, which is then merged with the RF communication probe hardware identifier encoding to generate a negotiation state node.

4. The passport security verification method according to claim 3, characterized in that, The specific steps for obtaining the cumulative result of the communication path penalty are as follows: S211: Obtain the negotiation state nodes at the current time and the previous time, determine the state transition characteristics between the nodes based on the two negotiation state nodes, analyze the negotiation state reference transition frequency in the passport machine that matches the state transition characteristics, synchronously obtain the preset attenuation penalty coefficient, determine whether the handshake message check bit error flag is in an active state, and extract the error activation state quantity corresponding to the check bit error flag in an active state. S212: Based on the error activation state quantity, for the case where the error flag of the handshake message check bit is active, calculate the state correction transfer frequency value based on the negotiation state reference transfer frequency and the attenuation penalty coefficient. S213: Obtain a parameter set consisting of multiple state correction transition frequency values ​​generated during the continuous interaction between the passport machine and the electronic passport, calculate the cumulative sum of all state correction transition frequency values ​​in the parameter set, and generate a cumulative communication path penalty result.

5. The passport security verification method according to claim 4, characterized in that, The specific steps for obtaining the passport data group structure parameters are as follows: S311: Compare the cumulative result of the communication path penalty with the preset degradation alarm threshold. When the cumulative result of the communication path penalty is greater than the degradation alarm threshold, send a disconnection control level signal to the radio frequency communication probe through the passport device and terminate the verification process. When the cumulative result of the communication path penalty is less than the degradation alarm threshold, generate a communication connection maintenance identifier. S312: Based on the communication connection to maintain the identifier, the passport machine sends a read command to the electronic passport to obtain the passport global directory file data, extracts the configuration information content of each independent data group in the passport from the passport global directory file data, parses the configuration information content and counts the byte length value of the passport data group in the independent data group. S313: Use the byte length value of the passport data group as the address offset to divide the data boundary of each independent data group within the passport global directory file data. Extract the hash dependency relationship identifier of each independent data group in the passport according to the data boundary. Combine the hash dependency relationship identifier and the byte length value to generate the passport data group structure parameters.

6. The passport security verification method according to claim 4, characterized in that, For the state correction transition frequency value, the formula is used: ; in, This indicates the state correction transition frequency value. Indicates the reference transition frequency of the negotiation state. This represents the prior confidence level of the observation. Indicates the historical prior confidence level. This indicates the preset attenuation penalty coefficient. Indicates the error activation state quantity. This represents the environmental dynamic adjustment factor.

7. The passport security verification method according to claim 5, characterized in that, The independent data sets include passport holder text data sets, passport holder facial feature data sets, and passport security object data sets. The process of parsing the configuration information and calculating the byte length of the passport data group in the independent data group specifically involves extracting the starting and ending addresses of the passport holder text data group, the passport holder facial feature data group, and the passport security object data group. Calculate the address offset span between the end address and the start address; The address offset span value is determined as the byte length value of the passport data group.

8. A passport security verification system, characterized in that, The passport security verification method according to any one of claims 1-7, wherein the system comprises: The negotiation state generation module collects the handshake negotiation messages between the passport machine and the electronic passport, and performs position concatenation operation between the error flag of the handshake message check bit and the passport communication baud rate to generate a negotiation state node. The communication path penalty accumulation module collects the negotiation state reference transition frequency of the continuously generated negotiation state nodes, presets the attenuation penalty coefficient, calculates the product of the two and performs path accumulation to obtain the communication path penalty accumulation result. The passport data group structure parsing module reads the passport global directory file data based on the cumulative result of the communication path penalty, extracts the byte length and hash dependency identifier of the independent data group of the passport data group, and generates passport data group structure parameters. The data group topology construction module constructs a directed graph data structure based on the passport data group structure parameters. Using the passport data group byte length as the weight and the hash dependency identifier as the directed edge, it performs a predecessorless node removal calculation on the directed graph data structure to generate a passport data group predecessorless node dequeue sequence. The passport data integrity verification module reads independent data groups sequentially according to the passport data group dequeue sequence without a predecessor node, calculates the difference between the passport data group summary and the passport document comparison items to obtain the passport data matching deviation, determines whether the passport data has been tampered with, and generates a passport verification result.

Citation Information

Patent Citations

  • Secure transmission system for passport data

    CN120474832A

  • Logistics traceability system and method based on block chain technology

    CN120525433A