Gene sample dynamic key derivation and two-way encryption authentication method and related device

CN122802166APending Publication Date: 2026-09-22欧科华创自动化(深圳)有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611203790.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-08-10
Publication Date
2026-09-22

AI Technical Summary

Technical Problem

然而,现有基于射频识别的基因样本认证方案存在三方面根本性安全隐患:

Benefits of technology

[0034]本发明通过获取待认证标签的唯一标识信息,在标签与读写器之间建立了一一对应的身份映射关系,解决了现有技术中标签身份信息不完整导致认证精确度不足的技术问题。标签唯一标识信息与物理不可克隆函数响应值的结合使用,使得每个标签的身份认证具有了硬件级的不可伪造特性,为后续动态密钥派生和双向认证提供了可信的身份基础。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122802166A_ABST
    Figure CN122802166A_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of biological sample security identification, in particular to a gene sample dynamic key derivation and bidirectional encryption authentication method and related device. According to one aspect of the present application, a gene sample dynamic key derivation and bidirectional encryption authentication method is provided, comprising: obtaining unique identification information of a label to be authenticated; based on a preset key derivation algorithm, combining a master key, label unique identification information and a current time stamp to derive a dynamic key, and generating a current session key. The present application solves the technical problem of insufficient authentication accuracy caused by incomplete label identity information in the prior art by obtaining the unique identification information of the label to be authenticated. The combination of label unique identification information and physically unclonable function response values makes the identity authentication of each label have a hardware-level unforgeable feature, providing a trusted identity basis for subsequent dynamic key derivation and bidirectional authentication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of biosample security identification technology, specifically to a method and device for dynamic key derivation and two-way encryption authentication of gene samples. Background Technology

[0002] Gene samples are the most important fundamental resources in biomedical research and precision medicine. Their accurate identification and secure storage are directly related to the reliability of clinical diagnosis and the safety of biological resources. Radio frequency identification (RFID) technology, with its advantage of non-contact batch identification, has become the main technical means for biobank management. However, existing RFID-based gene sample authentication schemes have three fundamental security risks:

[0003] First, existing authentication mechanisms generally adopt a one-way authentication mode, where only the reader verifies the legitimacy of the tag, but the tag cannot verify the authenticity of the reader. Malicious readers can impersonate legitimate devices to carry out man-in-the-middle attacks. Second, existing key management uses a static key mechanism, where keys are pre-set at the factory and remain unchanged throughout their lifecycle. This makes them vulnerable to physical attacks or theft through side-channel analysis, leading to the risk of mass cloning. Third, existing dynamic key schemes are only bound to the tag identifier and not to the gene sample data itself, so the keys cannot prevent the lateral misuse of the sample data. Therefore, the problem proposed in this invention is: how to simultaneously achieve two-way authentication, dynamic one-time key authentication, and deep binding of keys to sample identity for secure gene sample authentication. Summary of the Invention

[0004] This disclosure proposes a method and related apparatus for dynamic key derivation and two-way encryption authentication of gene samples, aiming to overcome at least one defect in the prior art.

[0005] To achieve the above objectives, the technical solution disclosed in this invention is as follows:

[0006] According to one aspect of this disclosure, a method for dynamic key derivation and two-way encryption authentication of gene samples is provided, comprising:

[0007] Step 1: Obtain the unique identifier information of the tag to be certified;

[0008] Step 2: Based on the preset key derivation algorithm, combine the master key, the unique identifier of the tag, and the current timestamp to perform dynamic key derivation and generate the current session key;

[0009] Step 3: Send a challenge code containing a random number to the tag, receive the response code generated by the tag based on the session key and the preset encryption algorithm, and at the same time send a verification request for the legitimacy of the reader / writer to the tag, and receive the device response code generated by the reader / writer based on the device certificate and the preset verification algorithm;

[0010] Step 4: If the response code matches the expected response code generated by the tag and the device response code passes verification, then the authentication is successful; otherwise, the authentication fails.

[0011] Furthermore, the tag is an RFID tag chip embedded in the gene sample storage container. The RFID tag chip integrates a miniature sensor module, which includes a biological sample characteristic acquisition sensor for real-time acquisition of physical characteristic parameters of the gene sample and at least one environmental parameter sensor for acquisition of temperature, humidity and air pressure parameters of the sample storage environment. The RFID tag chip has a built-in non-volatile memory for storing the unique identification information of the RFID tag chip, the sequence number of the gene sample, and the current status information of the dynamically derived session key.

[0012] Furthermore, the dynamic key derivation algorithm includes at least one of the following methods: a hash chain-based key derivation method, wherein the current session key is generated iteratively from the previous session key through a one-way hash function; a key negotiation method based on the elliptic curve Diffie-Hellman protocol, wherein the reader and the tag calculate a shared secret based on their respective elliptic curve private keys and the other party's public key, and then generate a session key by combining the timestamp and the tag's unique identification information through a key derivation function; and a key derivation method based on a hierarchical key structure, wherein the master key is derived from the first-level key to generate an intermediate key, and the intermediate key is then derived from the second-level key and combined with the tag's dynamic information to generate a session key.

[0013] Furthermore, the expression for dynamic key derivation is:

[0014] K_current = HKDF(Secret, TagID||Timestamp||Nonce, kdf_info), where K_current is the currently derived session key, HKDF (HMAC-based Key Derivation Function) is the HMAC-based key derivation function, Secret is the key seed obtained by XORing the master key and the tag's physical non-cloning function response value, TagID is the tag's unique identifier, Timestamp is the current timestamp, Nonce is the random number generated in this key derivation session, and kdf_info is an optional parameter string containing key derivation context information; the master key is the root key preset in the reader, and the tag's physical non-cloning function response value is the bit string generated after extracting the physical characteristic fingerprint formed during the tag chip manufacturing process through stimulus-response extraction.

[0015] Furthermore, the specific implementation of the two-way challenge-response mechanism includes the following stages: The first stage is that the reader initiates authentication to the tag. The reader generates a first random number as a challenge code and attaches the current session sequence number and timestamp. After encapsulation, it is encrypted using the current session key and sent to the tag. The tag decrypts the challenge code, extracts it, calculates the expected response code in combination with its own stored copy of the session key, and sends it back. The second stage is that the tag initiates authentication to the reader. The tag generates a second random number as a reverse challenge code and encapsulates the reader's device certificate information. After encryption using the tag's side session key, it is sent to the reader. The reader decrypts the code, verifies the legality of the device certificate, calculates the device response code, and sends it back to the tag. The tag verifies the device response code to confirm the authenticity of the reader.

[0016] Furthermore, the expression for generating the response code is:

[0017] R_tag = AES_ENC(K_session, Challenge||TagID||Timestamp_R1), where R_tag is the response code generated by the tag, AES_ENC (Advanced Encryption Standard) is the encryption function based on the AES algorithm, K_session is the current session key, Challenge is the plaintext challenge code containing a random number sent by the reader, TagID is the tag's unique identifier, and Timestamp_R1 is the local timestamp when the tag receives the challenge code; further, the expression for generating the device response code is:

[0018] R_device = RSA_SIGN(PrivateKey_device, Cert_device||Challenge||Timestamp_R2), where R_device is the device response code generated by the reader, RSA_SIGN (a digital signature function based on the RSA algorithm, RSA being an asymmetric encryption algorithm named after its inventors Rivest, Shamir, and Adleman) is the digital signature function based on the RSA algorithm, PrivateKey_device is the reader's private key, Cert_device is the reader's device certificate, Challenge is the plaintext of the reverse challenge code sent by the tag, and Timestamp_R2 is the local timestamp when the reader receives the reverse challenge code.

[0019] Furthermore, the specific implementation of device certificate verification is based on the Public Key Infrastructure (PKI) system. The PKI system includes a hierarchical certificate trust chain consisting of Certificate Authorities (CAs), root Certificate Authorities (CAPs), and intermediate Certificate Authorities (CATs). During the authentication process, the reader sends its device certificate and the complete certificate chain to the tag. The tag first verifies whether the root certificate of the CAP exists in its trust list, and then verifies the signature validity and validity period of each certificate in the certificate chain in turn, and checks the certificate revocation list to confirm that no certificate has been revoked. If the complete certificate chain of the device certificate is verified and the certificate has not been revoked, the device response code is verified.

[0020] Furthermore, it also includes a timestamp synchronization mechanism, the steps of which include:

[0021] Step 1: During the initialization phase, the reader and the tag establish a clock synchronization connection based on the network time protocol. The reader periodically sends clock synchronization frames to the tag to calibrate the tag's local clock.

[0022] Step 2: Before each authentication session begins, the reader compares its current timestamp with the tag's local clock. If the difference between the two exceeds a preset threshold, a clock calibration process is executed.

[0023] Step 3: Both the challenge code and the response code contain a timestamp field. After receiving the message, the receiver first parses the timestamp field. If the timestamp exceeds the preset time window range, the message is determined to be a replay attack and is rejected.

[0024] Step 4: The time window range is dynamically adjusted according to the clock drift rate of the tag chip and the security level requirements. In high-security scenarios, the time window range is set to one-quarter of the default time window range, and the shortest time window is no less than 30 seconds, in order to enhance the ability to prevent replay attacks.

[0025] According to another aspect of this disclosure, a dynamic key derivation and two-way encryption authentication system for gene samples is provided to implement the above-mentioned dynamic key derivation and two-way encryption authentication method for gene samples, including:

[0026] The unique identifier information acquisition module is used to obtain the unique identifier information of the label to be certified;

[0027] The dynamic key derivation module, connected to the tag unique identifier information acquisition module, is used to dynamically derive the current session key based on a preset key derivation algorithm, combined with the master key, tag unique identifier information and the current timestamp.

[0028] The two-way authentication communication module, connected to the dynamic key derivation module, is used to send a challenge code containing a random number to the tag to receive a response code generated by the tag based on the session key, and at the same time send a verification request for the legitimacy of the reader / writer to the tag to receive a device response code generated by the reader / writer based on the device certificate.

[0029] The authentication decision module, connected to the two-way authentication communication module, is used to output an authentication pass signal when the response code matches the expected response code and the device response code passes verification, and to output an authentication failure signal when the conditions of the response code matching the expected response code and / or the device response code passing verification are not met.

[0030] The physically unclonable function module is used to form a unique physical fingerprint during the tag chip manufacturing process, serving as the tag's hardware-level identity credential.

[0031] The key and sample identity binding module is used to hash and bind the gene sample sequence number stored in the tag with the dynamically derived session key so that the key and sample data correspond one-to-one.

[0032] According to another aspect of this disclosure, a computer-readable storage medium is provided, which stores a computer program that, when executed by a processor, implements the above-described gene sample dynamic key derivation and two-way encryption authentication method.

[0033] The beneficial effects of this invention are:

[0034] This invention establishes a one-to-one identity mapping between tags and readers by acquiring the unique identification information of the tags to be authenticated, thus solving the technical problem of insufficient authentication accuracy caused by incomplete tag identity information in existing technologies. The combined use of the tag's unique identification information and the response value of the physically unclonable function gives each tag's identity authentication hardware-level unforgeability, providing a reliable identity foundation for subsequent dynamic key derivation and two-way authentication.

[0035] This invention addresses the technical challenges of static keys being easily extracted and the risk of side-channel attacks due to the long-term immutability of session keys through a dynamic one-time pad mechanism. The key derivation module combines three independent entropy sources—the master key, the tag's unique identifier, and the current timestamp—to generate the current session key using the HKDF function. The introduction of the timestamp ensures that even for two consecutive authentication sessions with the same tag, the derived session keys will be completely different due to the different timestamps. Furthermore, the key seed is the result of an XOR operation between the master key and the response value of a physically cloning-unique function. Even if an attacker obtains the master key, they cannot deduce the correct session key solely from the tag identifier; they must simultaneously obtain the physical fingerprint of the tag chip, making mass cloning attacks computationally infeasible.

[0036] This invention solves the technical problems of unverified reader legitimacy and incomplete tag identity authentication through a two-way authentication mechanism. Step three includes two parallel authentication branches: the first branch involves the reader sending a challenge code containing a random number to the tag, the tag generating a response code based on the session key, and the reader verifying the tag's identity; the second branch involves the tag receiving a device certificate verification request from the reader, the reader generating a device response code based on the device certificate, and the tag verifying the device response code to confirm that the reader holds a legitimate certificate. This two-way authentication mechanism enables the tag to identify forged or tampered malicious readers through the PKI system, completely eliminating the security blind spot of malicious readers impersonating legitimate devices to launch man-in-the-middle attacks, which is present in one-way authentication systems.

[0037] This invention ensures the integrity and reliability of the authentication results through a comprehensive decision-making mechanism. The system outputs an authentication pass signal only when the response code matches the expected response code and the device response code passes verification. The decision logic in step four is directly related to the bidirectional authentication result in step three; failure in any authentication branch will lead to overall authentication failure.

[0038] The above description is merely an overview of the technical solution of the present invention. In order to better understand the technical means of the present invention and to implement it in accordance with the contents of the specification, the preferred embodiments of the present invention are described in detail below with reference to the accompanying drawings. Attached Figure Description

[0039] Figure 1 This is a flowchart of the gene sample dynamic key derivation and two-way encryption authentication method of the present invention.

[0040] Figure 2 This is a top-view view of the 3D topographic map and contour lines of the node locations for the signal coverage of the two-way authentication system of the present invention.

[0041] Figure 3 This is an eye diagram of the radio frequency interaction authentication signal between the tag and the reader in this invention;

[0042] Figure 4 This is the envelope diagram of the ASK modulation signal from the reader to the tag according to the present invention;

[0043] Figure 5 This is a spectrum analysis diagram of the tag-to-reader backscattered signal of the present invention;

[0044] Figure 6 This is a timing waveform diagram of the multi-frame authentication signal of the present invention;

[0045] Figure 7 This is a schematic diagram of the hardware layout of the tag chip of the present invention;

[0046] Figure 8 This is a timing diagram of the signal integrity of the chip encryption engine of the present invention;

[0047] Figure 9 This is a heat map showing the power consumption distribution of each module in the chip of this invention;

[0048] Figure 10 Electron micrograph of a physically non-clonable function cell array according to the present invention;

[0049] Figure 11 This is a 3D distribution diagram of the stability of the 256-bit physically unclonable function response of the present invention;

[0050] Figure 12 This is a diagram showing the distribution of inter-chip Hamming distances for the physically unclonable function of the present invention.

[0051] Figure 13 This is a 3D surface plot showing the reliability of the physically unclonable function of the present invention as a function of temperature and voltage.

[0052] Figure 14 This is a Hamming distance distribution diagram of the on-chip response uniformity of the physically unclonable function of the present invention;

[0053] Figure 15 This is a heatmap showing the correlation between adjacent positions of the physically unclonable function of the present invention.

[0054] Figure 16 This is a heatmap of the security strength at each stage of the dynamic key derivation algorithm of the present invention;

[0055] Figure 17 This is a diagram illustrating the session key lifecycle state migration and survival analysis of the present invention. Detailed Implementation

[0056] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0057] In embodiments of the present invention, the terms "exemplary" or "for example" are used to indicate that something is an example, illustration, or description. Any embodiment or design described as "exemplary" or "for example" in embodiments of the present invention should not be construed as being more preferred or advantageous than other embodiments or designs. Rather, the use of the terms "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0058] The present invention provides the following preferred embodiments:

[0059] In one embodiment, refer to Figure 1This embodiment discloses the process steps of a method for dynamic key derivation and two-way encryption authentication of gene samples. (Refer to...) Figure 1 The flowchart shown illustrates that the entire authentication process consists of four sequentially executed steps. Step one is the tag identification acquisition stage. The reader sends an initialization query command conforming to the ISO / IEC 18000-3 standard (Radio Frequency Identification Air Interface Protocol) via the radio frequency interface to wake up the tag to be authenticated and read its unique identification information. This unique identification information includes the tag's fixed code and the gene sample's sequence number. Step two is the dynamic key derivation stage. The reader calls the key derivation module, combining the master key stored in the local hardware security module, the received tag unique identification information, and the current system timestamp, to generate a temporary session key for this session using the cryptographically secure HKDF function. This session key is distributed to the tag's storage via an encrypted channel. Step three is the two-way authentication stage. The reader and tag conduct two independent authentication interactions according to a preset two-way challenge-response protocol, respectively completing the reader's authentication of the tag's identity and the tag's authentication of the reader's legitimacy. Step four is the authentication decision stage. The system determines whether the authentication is successful based on the comprehensive results of the two-way authentication. Only when the authentication in both directions is successful will the system output an authentication pass signal and allow subsequent data read and write operations. Otherwise, a security alarm mechanism will be triggered.

[0060] Reference Figure 2 As shown, the system presents the signal coverage terrain between the tag chip and multiple readers in three-dimensional space. Readers A to D are deployed at different locations in the biobank. The radio frequency signal strength between each reader and the central tag chip decreases non-linearly with increasing distance, forming a concentric circular signal radiation terrain with the tag chip as the peak. The contour lines change color from red to blue to represent the signal strength decreasing from strong to weak. The top-down contour map further illustrates the signal quality differences between each reader node and the tag. The tag chip is located at the center of the coverage area, and each reader node is distributed within different signal strength contour ranges. Reader A is the closest and has the strongest signal, while reader D is the farthest and its signal attenuates significantly at the edge. The signal coverage terrain map provides a clear view of the signal quality distribution between each reader and the tag, providing a basis for selecting the reader combination with the optimal signal quality for authentication during actual system deployment.

[0061] The tag chip is the core security element directly attached to the gene sample storage container in this invention system. Each tag chip has a globally unique identification code, which is written into an immutable read-only memory area by the manufacturer during the chip manufacturing stage. The tag chip integrates five functional units: a radio frequency transceiver module, a digital processing module, a secure storage module, a sensor module, and a physically unclonable function module. The radio frequency transceiver module operates in the UHF or HF radio frequency band, conforming to international standard protocols such as ISO / IEC 18000-3 and EPC Global C1G2, supporting wireless data interaction between the reader and the tag. The digital processing module incorporates a dedicated low-power encryption coprocessor, with instruction set optimizations for cryptographic operations such as HKDF key derivation, AES encryption / decryption, and RSA signature verification. The secure storage module employs a physically tamper-proof design to store the gene sample sequence number, session key status, and dynamic parameters. The sensor module integrates biological sample characteristic acquisition sensors and environmental parameter sensors, used to collect physicochemical characteristic parameters of the gene sample and temperature, humidity, and air pressure data of the storage environment, respectively. The physically unclonable function module utilizes process variations during chip manufacturing to generate unique physical fingerprints, providing a foundation for hardware-level identity authentication.

[0062] The tag chip is the core security element directly attached to the gene sample storage container in this invention system. Each tag chip has a globally unique identification code, which is written into an immutable read-only memory area by the manufacturer during the chip manufacturing stage. The tag chip integrates five functional units: a radio frequency transceiver module, a digital processing module, a secure storage module, a sensor module, and a physically unclonable function module. The radio frequency transceiver module operates in the ultra-high frequency or high frequency radio frequency band, conforming to international standard protocols such as ISO / IEC 18000-3 and EPC Global C1G2 (the second generation of the global standard for electronic product codes), supporting wireless data interaction between the reader and the tag. The digital processing module incorporates a dedicated low-power encryption coprocessor, with instruction set optimizations for cryptographic operations such as HKDF (HMAC-based Key Derivation Function) key derivation, AES (Advanced Encryption Standard) encryption and decryption, and RSA (RSA encryption algorithm, an asymmetric encryption algorithm named after its inventors Rivest, Shamir, and Adleman) signature verification. The secure storage module employs a physically-level tamper-proof design to store gene sample sequence numbers, session key status, and dynamic parameters. The sensor module integrates biological sample characteristic acquisition sensors and environmental parameter sensors, used to collect physicochemical characteristic parameters of the gene samples and temperature, humidity, and air pressure data of the storage environment, respectively. The physically unclonable function module utilizes process variations during chip manufacturing to generate unique physical fingerprints, providing a foundation for hardware-level identity authentication.

[0063] The reader incorporates a high-security-level security processor and a hardware security module. The security processor performs complex key derivation operations and digital signature verification, while the hardware security module provides a secure storage environment for the master key and an isolated execution environment for cryptographic operations. The reader stores its own device certificate and corresponding private key. The device certificate, issued by a Certificate Authority (CA), contains information such as the reader's public key, serial number, and validity period. The reader establishes an encrypted connection with the backend management server via a two-way authenticated transport layer security protocol, periodically uploading authentication logs and receiving key update commands. The backend management server manages the entire system's key hierarchy, equipped with a hardware security module for secure master key storage and an integrated machine learning engine to analyze authentication history data and dynamically adjust key derivation parameters. The Certificate Authority is a trusted third party responsible for issuing and managing device certificates within the system; its root certificate is pre-installed in the trusted storage area of ​​all tag chips and readers.

[0064] The system architecture of this invention fully considers the practical needs of biosample management scenarios. The tag chip adopts a low-power design, allowing it to be continuously attached to the surface of the sample storage container without external power supply, and supports an intermittent wake-up working mode to reduce average power consumption. The reader / writer uses a standardized interface design, which can be easily integrated into existing biobank management systems, supporting batch authentication operations and enabling rapid authentication, inventory, and data updates for multiple tags at once. The system supports flexible security level configuration; in high-security scenarios, the time window range can be narrowed, the random number length increased, and the key refresh frequency improved to meet the differentiated security requirements of different scenarios.

[0065] In one embodiment, refer to Figures 7 to 15 This embodiment details the hardware security architecture of the tag chip. As the largest deployed front-end security element in the system of this invention, directly bound to the gene sample storage container, the design of the tag chip's hardware security architecture directly relates to the security baseline of the entire system.

[0066] Reference Figure 7The chip layout shown employs a chip photomask design. The diagram labels the layout and metallic fill textures of core functional modules, including the PUF (Physically Unclonable Function) engine, AES (Advanced Encryption Standard) engine, SHA (Secure Hash Algorithm) engine, cryptographic control unit, RF analog IP, sensor array, and non-volatile memory control. The PUF engine, located in the upper left corner of the chip, occupies approximately one-eighth of the total area. It consists of an array of 32 by 32 PUF units, each with a physical size on the order of micrometers. The AES engine, located slightly to the left of the center, is the largest functional module on the chip, equipped with dedicated data paths and key scheduling hardware, supporting full-process encryption and decryption operations using AES-256 (Advanced Encryption Standard 256-bit key version). The SHA (Secure Hash Algorithm) engine, located to the right of the PUF (Physically Unclonable Function) engine, performs SHA-256 (Secure Hash Algorithm 256-bit) hash operations, providing hash computation capabilities for the extraction phase of the HKDF key derivation function. The cryptographic control unit, located in the center of the chip, handles data routing and timing coordination between the various cryptographic modules. The RF analog IP, located on the right edge of the chip, integrates a modem, power amplifier, and low-noise amplifier, responsible for wireless signal transmission and reception with the reader / writer. The sensor array, located in the lower right corner of the chip, includes sensing units for collecting the physicochemical properties of gene samples and sensing units for monitoring environmental parameters such as temperature, humidity, and air pressure. The non-volatile memory control module, located at the bottom center of the chip, manages read / write operations and data retention for the on-chip memory area. The modules are interconnected via multi-layered metal interconnects, with four rows of dozens of pin pads distributed along the edge of the layout, presenting a true layout of a highly integrated system-on-a-chip.

[0067] Reference Figure 8The timing diagram of the encryption engine, presented in an oscilloscope style, illustrates the timing relationship between the clock signal CLK, the data signal AES_DATA, and the enable signal ENABLE. The clock signal CLK is a continuous standard square wave with the operating frequency of the tag chip, remaining stable during the encryption operation. The data signal AES_DATA is high during encryption, indicating that the data path is active, and remains low when idle. The enable signal ENABLE transitions from low to high at the start of the encryption operation and remains high throughout the entire operation, returning to low after completion. The timing diagram shows that the data signal is established near the rising edge of the clock and held near the falling edge, establishing timing constraints for setup time and hold time. The orderly transitions of the signals indicate that the timing design of the encryption engine meets the timing convergence requirements of sub-nanometer process technology.

[0068] Reference Figure 9 The power consumption heatmap displays the power consumption distribution of each functional module of the tag chip in different operating modes in matrix form. The rows correspond to nine operating states: idle, initialization, authentication initiation, tag authentication, reader authentication, encryption operation, decryption operation, sensor acquisition, and deep sleep. The columns correspond to nine functional modules: PUF (Physically Unclonable Function) engine, AES (Advanced Encryption Standard) engine, SHA (Secure Hash Algorithm) engine, cryptographic CPU, RF simulation, sensor array, NVM (Non-Volatile Memory) control, GPIO (General Purpose Input / Output) ports, and PMU (Power Management Unit). The heatmap color changes from yellow to red, indicating a change in power consumption from low to high. The yellow area has a power consumption of approximately a few tenths of a milliwatt, while the orange-red area can reach over ten milliwatts. The heatmap clearly shows that the AES (Advanced Encryption Standard) engine consumes the most power during encryption and decryption operations, reaching over 15 milliwatts, which is the main source of power consumption for the tag chip; the PMU power management unit consumes the least power in deep sleep mode, at about 0.1 milliwatts; the PUF (Physically Unclonable Function) engine consumes very little power in idle mode but its power consumption increases significantly in working mode, reflecting its on-demand operation characteristics.

[0069] The tag chip employs a highly integrated system-on-a-chip design, with an overall area controlled within a few square millimeters, allowing it to be packaged within the outer wall of a standard gene sample storage tube or the label of a cryopreservation box. The core processing unit of the chip is a dedicated low-power encryption coprocessor. It has undergone instruction set-level optimization for the HKDF key derivation algorithm, AES-256 (Advanced Encryption Standard 256-bit) encryption / decryption algorithm, and RSA (RSA encryption algorithm, an asymmetric encryption algorithm named after its inventors Rivest, Shamir, and Adleman) signature verification algorithm used in this invention. This allows it to perform tens of thousands of hash and encryption / decryption operations per second with extremely low power consumption. The coprocessor integrates a true random number generator module, which generates cryptographically secure random numbers based on physical random sources such as thermal noise or oscillator jitter. The quality of these random numbers is certified by the NIST SP 800-90B standard, ensuring the freshness of the challenge code and session key in each authentication session.

[0070] The tag chip's secure storage module employs a layered encryption protection design. The bottom layer is a physical-level read-only memory area, storing the chip's fixed identification information and the initial key seed written by the manufacturer; this area is physically immutable. The middle layer is a protected non-volatile memory area, using advanced charge trapping or ferroelectric storage technology, with an erase / write life of no less than 100,000 cycles and a data retention time of no less than ten years. This area can only be read and written after verification by the coprocessor and is used to store gene sample sequence numbers, session key states, and dynamic parameters. The top layer is a memory encryption area. All keys and sensitive data temporarily stored during computation are stored in encrypted form in on-chip SRAM (Static Random Access Memory). Even if an attacker directly reads the chip's internal dynamic random access memory using a focused ion beam or microprobe, they cannot obtain sensitive information in plaintext.

[0071] The sensor module is a key innovative feature that distinguishes the tag chip from traditional RFID tags. The biological sample characteristic acquisition sensor can be implemented using various technologies such as near-infrared spectroscopy sensors, miniature impedance measurement sensing circuits, or electrochemical sensing arrays. It is used to collect the physicochemical characteristic parameters of gene samples in real time. These parameters can serve as an additional entropy source in the key derivation process to enhance the randomness of the session key. Environmental parameter sensors, including miniature temperature, humidity, and pressure sensors, are used to monitor the temperature, humidity, and pressure conditions of the gene sample storage environment. When environmental parameters exceed preset safety thresholds, the tag chip can proactively send alarm information to the reader, achieving real-time monitoring of the sample storage environment.

[0072] Furthermore, the optical structure design of the near-infrared spectral sensor specifically includes the following scheme: the miniature spectral sensor chip is manufactured using silicon-based CMOS compatible technology, with the overall package size controlled within 2mm×2mm×0.5mm, enabling integration within the limited layout area of ​​the RFID tag chip; the optical incident window adopts a microlens array structure, with microlens unit diameters ranging from 50μm to 100μm and focal lengths from 100μm to 200μm, using graded refractive index materials to achieve wide-spectrum focusing; the light source uses a miniature near-infrared light-emitting diode with a center wavelength of 850nm to 950nm, a bandwidth of 30nm to 50nm, and a luminous power of 1mW to 5mW, operating in pulsed mode to reduce average power consumption; the optical path design adopts a total internal reflection structure, with incident light passing through a microlens array. After collimation, the light penetrates the sample tube wall and illuminates the surface of the gene sample. The reflected light from the sample is collected by the same microlens and transmitted to the spectral detector. The spectral detector uses a short-wave infrared detection unit based on amorphous silicon or gallium arsenide, with a spectral response range of 800nm ​​to 1100nm, and integrates a 256-pixel or 512-pixel linear sensor array. The optical path and the RFID radio frequency path are physically isolated from each other, using independent antenna structures and optical windows to avoid interference between radio frequency signals and optical signals. When penetrating the sample tube wall for detection, both the incident light and the reflected light pass through the sample tube wall (made of transparent polypropylene or polycarbonate) at approximately a perpendicular angle. The optical path design takes into account the spherical aberration and light intensity attenuation caused by the tube wall thickness (1mm to 2mm), and compensates for tube wall reflection loss through optical cancellation design.

[0073] The physically unclonable function module is a key module for implementing hardware-level authentication in this invention. (See reference...) Figure 10 Electron micrographs show the microstructure of the PUF unit array in an actual chip. The grayscale value of each pixel in the image represents the steady-state resistance distribution of that PUF unit. Bright areas correspond to high-resistance units, and dark areas correspond to low-resistance units. The discrete distribution of resistance values ​​of each unit caused by random process fluctuations introduced during chip manufacturing can be clearly observed. (Refer to...) Figure 11 The 3D stability waterfall plot displays the reliability distribution of each bit in the 256-bit PUF response in a three-dimensional bar chart. The X-axis represents bit indices 0 to 31, the Y-axis represents the number of measurements, and the Z-axis represents instability. The color of the bars changes from green to red, indicating that the instability increases from low to high. This allows for the visual identification of a few high-risk unstable bits, which require special error correction mechanisms for protection in subsequent processing. (Refer to...) Figure 12 The 3D histogram shows the statistical distribution of the inter-chip Hamming distance. Ideally, the inter-chip Hamming distance should be concentrated around 128 bits, indicating that the PUF response between different tag chips has sufficient differentiation. (Refer to...) Figure 13The 3D reliability surface illustrates the trend of PUF response reliability as a function of ambient temperature and operating voltage. The X-axis represents temperature (20 to 80 degrees Celsius), the Y-axis represents voltage (0.8 to 1.4 volts), and the Z-axis represents the reliability percentage. The surface color changes from blue to red to indicate decreasing reliability. (Refer to...) Figure 14 The on-chip Hamming distance distribution verifies the response stability of the same chip under repeated measurements; the concentration of the distribution near zero indicates good on-chip repeatability. (Refer to...) Figure 15 The correlation heatmap analysis revealed the correlation structure between each bit of the PUF response. The weak correlation between adjacent bits reflects the local independence of process fluctuations.

[0074] During the operation of the physically unclonable function module, the reader first sends a preset excitation sequence to the tag chip. As this excitation sequence passes through the module's internal resistor network or capacitor array, slight differences in the physical characteristics of each node result in a characteristic voltage or current distribution in the output response. The analog-to-digital converter then converts this analog response into a digital bit string. The response value is immediately used in key derivation operations after generation, and no plaintext copy is retained in memory after the operation, achieving immediate use and destruction of the response value. Even if an attacker performs physical-level analysis of the chip using sophisticated instruments, they can only obtain the chip's static circuit structure information and cannot obtain the physical fingerprints that only manifest in dynamic operating states.

[0075] Furthermore, the secure registration and synchronization mechanism for the Physically Unclonable Function Response (PUF_response) specifically includes the following process: During the tag chip manufacturing stage, the manufacturer performs a PUF stimulus-response extraction operation on each chip to generate the chip's raw PUF response value (PUF_raw). This raw response value, after noise reduction and stability screening, is securely transmitted to the backend management server for secure registration via an encrypted channel. The backend management server establishes a secure association between the PUF_response and the corresponding tag unique identifier (TagID), storing it in a high-security hardware security module protected by AES-256 encryption. Before the tag chip leaves the factory, the PUF_response is pre-written in encrypted form into the secure storage area of ​​the tag chip, protected by the manufacturer's identification key during storage. At the start of each authentication session, the reader sends an authentication request to the backend management server. The request includes the TagID of the tag to be authenticated. The backend management server retrieves the corresponding PUF_response based on the TagID, encrypts the PUF_response using the session key between the reader and the backend server, and returns it to the reader. After receiving the encrypted PUF_response, the reader decrypts it using the decryption key in the hardware security module to obtain the plaintext PUF_response, and then performs key derivation operations to generate the session key. This mechanism ensures that the PUF_response is transmitted and stored only in encrypted form throughout its entire lifecycle. Even if the communication between the reader and the backend server is eavesdropped on, attackers cannot obtain the plaintext PUF_response that can be used to clone tags.

[0076] In one embodiment, refer to Figure 16 and Figure 17 This embodiment details the specific implementation of the dynamic key derivation algorithm. The dynamic key derivation algorithm used in this invention employs the master key as the root key and gradually generates the final session key used for authentication through multiple rounds of key derivation processes, which is a core technology for ensuring system security.

[0077] The master key is stored in the reader's hardware security module and injected by the administrator through a secure initialization process. The master key itself remains fixed throughout the system's lifecycle, and its storage and computation are performed within the trusted execution environment of the hardware security module. Even if the reader's host operating system is completely compromised by an attacker, the master key will not be leaked. (See reference...) Figure 16The security strength heatmap shown uses the X-axis to represent the four key steps of key derivation: key seed generation, HKDF extraction, HKDF expansion, and session key output. The Y-axis represents four security parameters: entropy, randomness, correlation, and computational complexity. The heatmap color changes from blue to red to indicate a change in security strength from low to high. The heatmap reveals that the entropy and randomness in the key seed generation stage are at a moderate level because this stage introduces two entropy sources: the master key and the PUF response value. After HMAC compression in the extraction stage, the entropy and randomness significantly increase to a high level, while the correlation decreases to a low level. The expansion stage further enhances the security strength by reducing computational complexity. Finally, the session key output stage reaches high security strength, with all four dimensions exhibiting a state conducive to security.

[0078] At the start of each authentication session, the key derivation module first obtains the current Physically Unclonable Function (PUF) response value of the tag from the Physically Unclonable Function (PUF) module, which is denoted as Secret_1. The key derivation module performs an XOR operation on the master key MasterKey and PUF_response to generate the key seed Secret. This operation can be represented as Secret equals MasterKey XORed with PUF_response. This XOR operation design ensures that the final session key depends on both the master key on the reader side and the physical characteristics on the tag side. The absence of either side will prevent the generation of a valid session key. Even if an attacker obtains the master key, they cannot deduce the correct session key based solely on the tag identification information. The key seed generation process also introduces a timestamp and a nonce as additional entropy sources. The timestamp is obtained by the reader from the system clock, representing the precise time when the authentication session was initiated. The nonce is generated by a true random number generator and is a cryptographic random number for this key derivation session. The combined use of these two ensures that even if multiple authentication requests are initiated for the same tag within a very short period of time, the derived session key will be completely different each time.

[0079] The complete key derivation calculation uses the HMAC-based key derivation function HKDF. Specifically, the calculation formula is that K_current equals the HKDF-SHA256 function performing key derivation operations on the key seed (Secret), tag ID (TagID), timestamp (Timestamp), and nonce (Nonce), outputting the current session key K_current. The HKDF function comprises two stages: the extraction stage uses the HMAC-SHA256 function to compress the variable-length key seed and salt value into a fixed-length pseudo-random key. This stage compresses multiple optional entropy sources into a single uniformly distributed pseudo-random key. The expansion stage uses this pseudo-random key to generate the required output keystream through a series of HMAC iterative operations. The input for each iteration includes the output of the previous iteration, an optional information parameter, and an iteration counter. This invention sets the output key length of HKDF to 256 bits to meet the key length requirements of the AES-256 encryption algorithm.

[0080] Furthermore, the complete process for independently calculating the session key on the reader side and the tag side is as follows: The reader-side key calculation steps include: Step 1, the reader sends a PUF_response query request to the backend management server, carrying the unique identifier information TagID of the tag to be authenticated; Step 2, the backend management server retrieves the corresponding PUF_response based on the TagID, encrypts it using the transport layer security protocol session key between the reader and the backend server, and returns it; Step 3, the reader decrypts the plaintext PUF_response using the decryption key in the hardware security module; Step 4, the reader performs an XOR operation between the master key (MasterKey) and the PUF_response to generate the key seed (Secret); Step 5, combining the tag identifier (TagID), timestamp (Timestamp), and random number (Nonce), the current session key (K_current) is generated using the HKDF-SHA256 function. The tag-side key calculation steps include:

[0081] Step 1: The tag chip's built-in Physically Unclonable Function (PUF) module responds to the stimulus sequence sent by the reader, generating a PUF response. Step 2: The tag uses the same key derivation algorithm as the reader to XOR the MasterKey_copy stored in the secure storage area with the PUF response, generating the same key seed, Secret. Step 3: Combining the locally stored TagID, Timestamp_copy, and Nonce, the tag generates the same current session key, K_current, as the reader's, using the HKDF-SHA256 function. The tag's Timestamp_copy is synchronized with the reader's via a clock synchronization mechanism, and the Nonce is provided by the reader in the authentication request and transmitted to the tag via an encrypted channel. Through this symmetric key derivation mechanism, the reader and tag can independently calculate the same session key, achieving two-way authentication.

[0082] Session key lifecycle management is a crucial component of dynamic key derivation algorithms. (Refer to...) Figure 17 The session key lifecycle diagram shown on the left illustrates the transitions between six states: initialization, active, refresh, verification, expiration, and revocation. The initialization state is entered after a new key is generated by the key derivation module. The active state indicates the key can be used in the current authentication session. The refresh state indicates a key update operation is underway. The verification state indicates the key is being used for authentication verification. The expiration state indicates the key has exceeded its validity window. The revocation state indicates the key has been forcibly invalidated. The Kaplan-Meier survival curve on the right shows the decreasing survival probability of the session key over time. The shaded confidence interval represents the uncertainty range of the survival estimate. In high-security application scenarios, key survival decays faster, reflecting the security strategy of high-frequency key refresh.

[0083] This invention also supports a hash chain-based key derivation method as a supplement to the HKDF method. In the hash chain method, the current session key is generated iteratively from the previous session key through a one-way hash function. Specifically, K_current equals the result of the SHA256 function operating on the previous key K_previous, the tag ID TagID, and the timestamp. The one-way nature of the hash function ensures that even if an attacker obtains the current session key, they cannot deduce the historical session key through reverse calculation, thus effectively preventing lateral key leakage. The advantage of the hash chain method is that it does not require storing the derivation state of the master key; the evolution of the key is entirely driven by hash operations on the tag side, making it suitable for distributed application scenarios where the master key cannot be directly distributed to tags.

[0084] In one embodiment, refer to Figures 3 to 6 This embodiment details the complete workflow of the two-way authentication protocol. The two-way authentication protocol is the core innovation of this invention, comprising four main stages: initialization stage, tag authentication stage, reader authentication stage, and decision stage.

[0085] Reference Figure 3 The eye diagram illustrates the superimposed distribution of signal transition edges across multiple authentication cycles. The size of the eye diagram opening directly reflects the signal quality and the degree of inter-symbol interference. The central crosshair of the eye diagram marks the zero-time reference point, the horizontal solid line marks the signal decision threshold, and the vertical dashed line marks the optimal sampling time. The dense colored trajectory lines characterize the amplitude distribution of the signal within different time windows. A large opening in the eye diagram indicates that the signal has a good decision margin at the receiver and strong noise immunity. (Reference) Figure 4 The ASK modulation signal envelope diagram illustrates the envelope of the radio frequency signal sent by the reader to the tag. The fluctuations in the envelope characterize the modulation result of the baseband data. The carrier signal is superimposed on the envelope to form a complete ASK modulation waveform. The red envelope line clearly outlines the contour of the modulated signal, and the rising and falling edges of the envelope correspond to the transition times of the data bits. (Refer to...) Figure 5 The spectrum diagram, using short-time Fourier transform, shows the frequency distribution of the tag's backscattered signal within different time windows. The spectral color gradually changes from dark purple, representing low-energy regions, to yellow, representing high-energy regions. It can be observed that the center frequency of the backscattered signal is approximately the carrier frequency, and the spectrum exhibits a certain diffusion range, reflecting the spectral characteristics of the modulated signal. (Refer to...) Figure 6 The multi-frame timing waveform diagram shows the complete four-frame signal timing relationship from the initialization frame to the decision frame in a layered superposition. Frame-1 initialization frame is represented in blue, Frame-2 challenge frame is represented in red, Frame-3 response frame is represented in green, and Frame-4 decision frame is represented in purple. The signals of each frame are arranged sequentially on the time axis to form a complete authentication interaction sequence, and the duration and amplitude level of each frame are clearly distinguished.

[0086] During the initialization phase, a radio frequency communication connection is established between the reader and the tag. The reader sends an initialization command frame carrying the authentication protocol version number. After receiving and parsing the command frame, the tag enters the authentication preparation state. The reader then triggers the key derivation module to derive the current session key K_current according to the method described in Embodiment 3 above, and distributes the session key to the tag-side storage through a symmetric key negotiation mechanism based on physically non-cloning function responses.

[0087] During the tag authentication phase, the reader generates a first random number R1 and a first timestamp T1. These two values ​​are combined with the current session sequence number SN to form the plaintext challenge code, represented as Challenge_data, which is the concatenation of R1, T1, and SN. The reader uses the current session key K_current to perform AES-256 encryption on this plaintext challenge code, generating an encrypted challenge packet which is then sent to the tag via the RF interface. Upon receiving the encrypted challenge packet, the tag decrypts it using a locally stored copy of the session key, extracting the random number R1, timestamp T1, and session sequence number SN. The tag first checks if the timestamp T1 is within a valid time window. If it exceeds the time window, it is considered a replay attack and the authentication request is rejected. If the timestamp verification passes, the tag calculates the expected response code, calculated as R_tag, which is equal to the AES_256-ENC function performing AES encryption on the session key K_current, the received challenge code Challenge, the tag identifier TagID, and the tag's received timestamp Timestamp_R1. The tag sends the calculated response code R_tag back to the reader. After receiving the tag's response, the reader compares it with its own calculated expected response code. If the two match exactly, the tag authentication is successful; otherwise, the tag authentication fails.

[0088] During the reader authentication phase, the tag generates a second random number R2 and a second timestamp T2, and encapsulates the reader's device certificate Cert_device together to form a reverse challenge request packet. The tag encrypts the reverse challenge request packet using the current session key and sends it to the reader. Upon receiving the packet, the reader first decrypts it using the session key, extracting the random number R2, timestamp T2, and device certificate information Cert_device. The reader then verifies the legitimacy of the device certificate. The verification steps include: checking whether the device certificate signature was issued by a certificate authority on the trusted list; verifying the validity and legitimacy of each certificate level upwards according to the certificate chain; querying the certificate revocation list to confirm that the device certificate has not been revoked; and verifying the digital signature of the device certificate using the certificate authority's public key to confirm that the certificate content has not been tampered with. If certificate verification passes, the reader calculates the device response code using the formula R_device = RSA_SIGN. The function uses the reader's private key, PrivateKey_device, to perform a digital signature operation on the hash value of the device certificate Cert_device, the received reverse challenge code Challenge, and the received timestamp Timestamp_R2. The reader then sends the device response code back to the tag. Upon receiving it, the tag verifies it using the certificate authority's public key. If verification passes, the reader's authentication is successful; otherwise, authentication fails.

[0089] During the judgment phase, the system outputs an authentication pass signal and allows subsequent data read or write operations only if both conditions are met simultaneously: successful tag authentication and successful reader authentication. If any authentication stage fails, the system outputs an authentication failure signal and triggers local audible and visual alarms, uploads alarm information to the backend management server, records detailed authentication failure logs, and automatically locks the tag after multiple consecutive authentication failures.

[0090] In one embodiment, refer to Figure 2 and Figure 6 This embodiment details the implementation of the timestamp synchronization mechanism and the replay attack prevention mechanism. Timestamp synchronization and replay attack prevention are key auxiliary mechanisms for ensuring the security of the two-way authentication protocol.

[0091] In biobank applications, due to the low power consumption and intermittent operation of tag chips, a discrepancy inevitably exists between the local clock of the tag chip and the system clock of the reader / writer. This discrepancy stems from factors such as frequency errors of the crystal oscillator, aging drift caused by environmental temperature changes, and clock resets during tag chip sleep / wake-up. (Refer to...) Figure 2 The signal coverage topography map can help understand the spatial distribution relationship between the reader and the tag, while the accuracy of clock synchronization directly affects the accuracy of the transmission delay measurement of the authentication signal, and thus affects the reliability of the timestamp verification of the entire authentication protocol.

[0092] This invention designs a timestamp synchronization mechanism based on a simplified version of the Network Time Protocol (NTP). During system initialization, the reader sends a clock synchronization request frame to the tag chip. This frame includes the reader's current system timestamp, T_system, as a reference time. Upon receiving this frame, the tag chip compares its local clock with the reference time, calculates the clock offset value (Offset), which is equal to T_system minus T_local, and stores it in the system parameter area of ​​non-volatile memory. All subsequent timestamp calculations use this offset value for calibration. Clock synchronization is not a one-time operation. The reader includes clock calibration information with each normal authentication interaction with the tag. After receiving the challenge code, the tag first performs a fine-tuning update of the clock offset, and then uses the calibrated clock for timestamp-related calculations, ensuring that the clock offset is always controlled within a safe threshold.

[0093] The anti-replay attack mechanism provides freshness assurance from three dimensions. The first dimension is random number freshness. At the start of each authentication session, both the reader and the tag generate a new random number as part of the challenge code, with a length of no less than 128 bits, ensuring no collision possibility under realistic computing capabilities. After authentication, both parties record the used random number in a used random number buffer. When a new authentication request is received, it first checks whether the random number is duplicated with a record in the used buffer. The second dimension is timestamp freshness. Each authentication message carries a timestamp of the sending time. Before processing the message, the receiver first checks whether the timestamp is within a preset valid time window. The default time window is five minutes, which can be narrowed to one minute in high-security scenarios. Messages exceeding the time window are considered replay attacks and rejected. The third dimension is sequence number freshness. The reader assigns a strictly increasing sequence number to each authentication session. After receiving an authentication request, the tag first checks whether the sequence number is greater than the sequence number of its last successfully authenticated session. If the sequence number is not increasing or is decreasing, it is considered a possible replay of a historical message and rejected.

[0094] In one embodiment, this embodiment describes in detail the specific implementation of the key-gene sample identity binding mechanism. The core idea of ​​this mechanism is to cryptographically bind the gene sample sequence number stored in the tag with a dynamically derived session key, so that each session key can only be used to access its corresponding specific gene sample data.

[0095] The key-sample identity binding mechanism is motivated by the need for fine-grained access control of gene samples. In the actual management scenario of biobanks, different gene samples have different sensitivity levels and access permission requirements. Samples involving rare disease gene resources require stricter access control than ordinary samples, and samples involving family genetic information require stricter privacy protection than other samples. In traditional RFID authentication systems, all tags share the same authentication protocol and key derivation strategy. An attacker who obtains the authentication credentials of one tag can theoretically apply them to all tags in the same batch. The key-sample identity binding mechanism fundamentally changes this security model, making the authentication credentials of each tag unique and impossible to transfer laterally.

[0096] The specific implementation of key-sample identity binding is based on the one-wayness and collision resistance of hash functions. In the session key derivation process, in addition to input parameters such as the master key, the physically unclonable function response value, the timestamp, and the random number, the gene sample sequence number is additionally introduced as one of the input parameters of the key derivation function. Specifically, the session key derivation calculation formula is that K_current equals the HKDF-SHA256 function, which combines the key seed Secret, the tag's unique identifier TagID, the gene sample sequence number SampleID, the timestamp, and the random number Nonce to generate a session key deeply bound to the gene sample. The value of this session key depends on both the tag's identity and the gene sample sequence number stored within the tag. Only by knowing the correct gene sample sequence number can the correct session key be derived. Even if an attacker obtains the session key for a particular session, this key can only be used to access the specific gene sample it is bound to and cannot be applied laterally to other sample data within the same tag group.

[0097] The key-sample identity binding mechanism also supports sample data integrity verification. After collecting the physical characteristic parameters of the gene sample, the sensor module of the tag chip stores these parameters along with the sample serial number in the tag's secure storage area. During key derivation, these physical characteristic parameters are introduced as an optional additional entropy source, ensuring that the session key is bound not only to the sample's identity but also to the sample's physical state. If an attacker attempts to replace the gene sample in the storage container without updating the sample serial number in the tag's memory, the subsequently derived session key will fail to match due to the change in physical characteristic parameters, leading to authentication failure and effectively preventing sample substitution attacks.

[0098] In one embodiment, this embodiment describes in detail the specific structure of a gene sample dynamic key derivation and two-way encryption authentication system and device. The system consists of multiple functional modules, which are connected through standardized data interfaces to jointly complete the entire process from tag identification to authentication decision.

[0099] The tag unique identification information acquisition module is the system's front-end entry module, responsible for establishing an RF communication connection with the tag chip and acquiring the tag's unique identification information. This module comprises two sub-modules: an RF transceiver unit and a protocol parsing unit. The RF transceiver unit operates in the UHF or HF RF band, supports ISO / IEC 18000-3 and EPC Global C1G2 standard protocols, and the antenna configuration is flexibly selected according to the identification distance requirements of the application scenario. The protocol parsing unit is responsible for parsing the query commands and response messages sent by the reader, extracting the tag's unique identification information and gene sample sequence number, and transmitting the parsing results to the dynamic key derivation module.

[0100] The dynamic key derivation module is connected to the tag unique identifier information acquisition module. It is responsible for generating the current session key based on a preset key derivation algorithm and input parameters. This module comprises four sub-modules: a key seed calculation unit, a random number generation unit, a timestamp acquisition unit, and a key derivation operation unit. The key seed calculation unit performs an XOR operation between the master key and the response value of the physically non-cloning function to generate the key input for the key derivation function. The random number generation unit calls the system's high-quality true random number generator to generate cryptographically secure random numbers required for each authentication session. The timestamp acquisition unit obtains the current precise timestamp from the system clock and converts it to a unified Unix timestamp format. The key derivation operation unit performs iterative operations on the extraction and expansion stages of the HKDF-SHA256 function, ultimately outputting a 256-bit session key.

[0101] The two-way authentication communication module connects to the dynamic key derivation module and is responsible for managing the two-way authentication interaction process with the tag. This module comprises four sub-modules: a challenge code generation unit, a message encryption unit, a message decryption unit, and a response verification unit. The challenge code generation unit constructs a challenge message containing a random number, timestamp, and session sequence number, and adds necessary protocol control fields. The message encryption unit uses the current session key to encrypt the message to be sent using AES-256, ensuring the confidentiality of the transmitted content. The message decryption unit decrypts the received encrypted message to extract the plaintext content. The response verification unit performs response code comparison verification or RSA signature cryptographic verification to determine the legitimacy of the authentication counterpart.

[0102] The authentication decision module connects to the two-way authentication communication module and is responsible for making the final decision based on the results of the two-way authentication. This module comprises three sub-modules: a decision logic unit, an alarm management unit, and a log recording unit. The decision logic unit performs AND operations, outputting an authentication pass signal only when both the reader's authentication of the tag and the tag's authentication of the reader are successful. The alarm management unit triggers audible and visual alarms or uploads alarm information to the backend management server when authentication fails. The log recording unit writes the detailed process and results of each authentication to a security log for post-event auditing and analysis.

[0103] The physically non-cloning function module comprises three sub-modules: an excitation generation unit, a response acquisition unit, and a response preprocessing unit. The excitation generation unit generates a standardized excitation sequence according to a preset excitation protocol. This excitation sequence elicits a characteristic physical response in the physically non-cloning function module of the tag chip. The response acquisition unit converts the physical response into a digital bit string using an analog-to-digital converter and performs necessary error correction and stability processing. The response preprocessing unit performs post-processing on the bit string, including bit balance correction, threshold decision, and format normalization, to ensure output consistency and usability.

[0104] The key and sample identity binding module is embedded within the dynamic key derivation module and comprises three sub-modules: a sample sequence number acquisition unit, a binding parameter assembly unit, and a binding verification unit. The sample sequence number acquisition unit retrieves the sequence number of the gene sample to be authenticated from a tag storage device or an external information system. The binding parameter assembly unit assembles the sample sequence number with other key derivation parameters to form a complete key derivation input. After authentication, the binding verification unit compares the currently used sample sequence number with historical records to detect any abnormal identity binding changes.

[0105] The backend management server, acting as the system's centralized management node, is responsible for the lifecycle management of the key system, the configuration and updating of authentication policies, and the aggregation and analysis of authentication logs. The server is equipped with a hardware security module for high-security key storage and computation, and connects to each reader / writer via a two-way authenticated transport layer security protocol, ensuring the confidentiality and integrity of control commands and key update data during transmission. The server's machine learning engine periodically receives authentication history data from each reader / writer, and dynamically optimizes key derivation parameters and security policies by analyzing features such as authentication latency distribution, authentication success rate changes, and abnormal authentication patterns.

[0106] Although the present invention has been specifically described above with reference to preferred embodiments, it should be understood that the present invention is not limited to the embodiments described above. Various modifications and variations can be made by those skilled in the art without departing from the spirit of the present invention, and such modifications and variations should fall within the scope defined by the appended claims and their equivalents.

Claims

1. A method for dynamic key derivation and two-way encryption authentication of gene samples, characterized in that, include: Step 1: Obtain the unique identifier information of the tag to be certified; Step 2: Based on the preset dynamic key derivation algorithm, combine the master key, the unique identifier of the tag, and the current timestamp to perform dynamic key derivation and generate the current session key; Step 3: Send a challenge code containing a random number to the tag, receive a response code generated by the tag based on the session key and a preset encryption algorithm, and simultaneously send a verification request for the legitimacy of the reader / writer to the tag, and receive a device response code generated by the reader / writer based on the device certificate and a preset verification algorithm; Step 4: If the response code matches the expected response code generated by the tag and the device response code passes verification, then the authentication is successful.

2. The gene sample dynamic key derivation and two-way encryption authentication method according to claim 1, characterized in that, The tag is an RFID tag chip embedded in a gene sample storage container. The RFID tag chip integrates a micro sensor module, which includes a biological sample characteristic acquisition sensor for real-time acquisition of physical characteristic parameters of the gene sample and at least one environmental parameter sensor for acquisition of temperature, humidity and air pressure parameters of the sample storage environment. The RFID tag chip has a built-in non-volatile memory for storing the unique identification information of the RFID tag chip, the sequence number of the gene sample, and the current status information of the dynamically derived session key.

3. The gene sample dynamic key derivation and two-way encryption authentication method according to claim 1, characterized in that, The dynamic key derivation algorithm includes at least one of the following methods: a hash chain-based key derivation method, wherein the current session key is generated by iteratively applying a one-way hash function to the session key at the previous moment; a key negotiation method based on the elliptic curve Diffie-Hellman protocol, wherein the reader and the tag calculate a shared secret based on their respective elliptic curve private keys and the other party's public key, and then generate a session key by combining the timestamp and the tag's unique identification information through a key derivation function. The key derivation method based on the hierarchical key structure involves the master key being derived into an intermediate key through the first-level key, and the intermediate key being derived into a session key by combining the dynamic tag information with the second-level key.

4. The gene sample dynamic key derivation and two-way encryption authentication method according to claim 1, characterized in that, The expression derived from the dynamic key is: K_current = HKDF(Secret, TagID||Timestamp||Nonce, kdf_info), where K_current is the currently derived session key, HKDF is the HMAC-based key derivation function, Secret is the key seed obtained by XORing the master key with the tag's physical non-cloning function response value, TagID is the tag's unique identifier, Timestamp is the current timestamp, Nonce is a random number generated in this key derivation session, and kdf_info is an optional parameter string containing key derivation context information; the master key is the root key preset in the reader, and the tag's physical non-cloning function response value is the bit string generated after the physical characteristic fingerprint formed during the tag chip manufacturing process is extracted by the stimulus-response process.

5. The gene sample dynamic key derivation and two-way encryption authentication method according to claim 4, characterized in that, The specific implementation of the two-way challenge response mechanism includes the following stages: The first stage is that the reader initiates authentication to the tag. The reader generates a first random number as a challenge code and attaches the current session number and timestamp. After encapsulation, it is encrypted using the current session key and sent to the tag. After decryption, the tag extracts the challenge code, calculates the expected response code in combination with its own stored session key copy, and sends it back. The second stage involves the tag initiating authentication with the reader. The tag generates a second random number as a reverse challenge code and simultaneously encapsulates the reader's device certificate information. After encrypting the information using the tag's side session key, the tag sends the encrypted information to the reader. The reader decrypts the information, verifies the validity of the device certificate, calculates the device response code, and sends it back to the tag. The tag then verifies the device response code to confirm the authenticity of the reader.

6. The gene sample dynamic key derivation and two-way encryption authentication method according to claim 5, characterized in that, The expression for generating the response code is: R_tag=AES_ENC(K_session,Challenge||TagID||Timestamp_R1), where R_tag is the response code generated by the tag, AES_ENC is the encryption function based on the AES algorithm, K_session is the current session key, Challenge is the plaintext challenge code containing a random number sent by the reader, TagID is the unique identifier of the tag, and Timestamp_R1 is the local timestamp when the tag receives the challenge code; The expression for generating the device response code is: R_device = RSA_SIGN(PrivateKey_device, Cert_device||Challenge||Timestamp_R2), where R_device is the device response code generated by the reader, RSA_SIGN is the digital signature function based on the RSA algorithm, PrivateKey_device is the reader's private key, Cert_device is the reader's device certificate, Challenge is the plaintext of the reverse challenge code sent by the tag, and Timestamp_R2 is the local timestamp when the reader receives the reverse challenge code.

7. The gene sample dynamic key derivation and two-way encryption authentication method according to claim 6, characterized in that, The specific implementation of the device certificate verification is based on the Public Key Infrastructure (PKI) system, which includes a hierarchical certificate trust chain consisting of Certificate Authorities (CAs), root Certificate Authorities (CAPs), and intermediate Certificate Authorities (CATs). During the authentication process, the reader sends its device certificate and complete certificate chain to the tag. The tag first verifies whether the root certificate of the root certificate authority exists in its trust list, and then verifies the signature validity and validity period of each certificate in the certificate chain in turn, and checks the certificate revocation list to confirm that no certificate has been revoked. If the complete certificate chain of the device certificate is verified and the certificate has not been revoked, the device response code is verified.

8. The gene sample dynamic key derivation and two-way encryption authentication method according to claim 1, characterized in that, It also includes a timestamp synchronization mechanism, the steps of which include: Step 1: During the initialization phase, the reader and the tag establish a clock synchronization connection based on the network time protocol. The reader periodically sends clock synchronization frames to the tag to calibrate the tag's local clock. Step 2: Before each authentication session begins, the reader compares its current timestamp with the tag's local clock. If the difference between the two exceeds a preset threshold, a clock calibration process is executed. Step 3: Both the challenge code and the response code contain a timestamp field. After receiving the message, the receiver first parses the timestamp field. If the timestamp exceeds the preset time window range, the message is determined to be a replay attack and is rejected. Step 4: The time window range is dynamically adjusted according to the clock drift rate of the tag chip and the security level requirements. In high security level scenarios, the time window range is set to one-quarter of the default time window range, and the shortest is no less than 30 seconds, in order to enhance the ability to prevent replay attacks.

9. A gene sample dynamic key derivation and two-way encryption authentication system, used to implement the gene sample dynamic key derivation and two-way encryption authentication method as described in any one of claims 1-8, characterized in that, include: The unique identifier information acquisition module is used to obtain the unique identifier information of the label to be certified; The dynamic key derivation module is connected to the tag unique identifier information acquisition module. It is used to perform dynamic key derivation based on a preset key derivation algorithm, combined with the master key, the tag unique identifier information and the current timestamp, to generate the current session key. A two-way authentication communication module, connected to the dynamic key derivation module, is used to send a challenge code containing a random number to the tag to receive a response code generated by the tag based on the session key, and simultaneously send a verification request for the legitimacy of the reader / writer to the tag to receive a device response code generated by the reader / writer based on the device certificate. The authentication decision module, connected to the two-way authentication communication module, is used to output an authentication pass signal when the response code matches the expected response code and the device response code passes verification. The physically unclonable function module is used to form a unique physical fingerprint during the tag chip manufacturing process, serving as the tag's hardware-level identity credential. The key and sample identity binding module is used to hash and bind the gene sample sequence number stored in the tag with the dynamically derived session key so that the key and sample data correspond one-to-one.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the gene sample dynamic key derivation and two-way encryption authentication method as described in any one of claims 1 to 8.