CN102932338B - System and method for safe network access of radio-frequency identification system - Google Patents
System and method for safe network access of radio-frequency identification system Download PDFInfo
- Publication number
- CN102932338B CN102932338B CN201210411867.7A CN201210411867A CN102932338B CN 102932338 B CN102932338 B CN 102932338B CN 201210411867 A CN201210411867 A CN 201210411867A CN 102932338 B CN102932338 B CN 102932338B
- Authority
- CN
- China
- Prior art keywords
- module
- write line
- read write
- authentication
- network
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
- 238000000034 method Methods 0.000 title claims abstract description 30
- 238000004891 communication Methods 0.000 claims abstract description 81
- 238000012795 verification Methods 0.000 claims abstract description 28
- 238000012545 processing Methods 0.000 claims abstract description 25
- 230000002457 bidirectional effect Effects 0.000 claims abstract description 12
- 238000003780 insertion Methods 0.000 claims description 38
- 230000037431 insertion Effects 0.000 claims description 38
- 238000005259 measurement Methods 0.000 claims description 24
- 238000012937 correction Methods 0.000 claims description 20
- 238000002955 isolation Methods 0.000 claims description 15
- 239000000203 mixture Substances 0.000 claims description 13
- 230000006870 function Effects 0.000 claims description 11
- 230000005540 biological transmission Effects 0.000 claims description 4
- 230000000977 initiatory effect Effects 0.000 claims description 4
- 238000009472 formulation Methods 0.000 claims description 3
- 238000005538 encapsulation Methods 0.000 claims description 2
- 239000000306 component Substances 0.000 description 1
- 239000008358 core component Substances 0.000 description 1
- 238000010586 diagram Methods 0.000 description 1
- 230000000694 effects Effects 0.000 description 1
- 238000005516 engineering process Methods 0.000 description 1
- 238000011160 research Methods 0.000 description 1
- 238000011426 transformation method Methods 0.000 description 1
Landscapes
- Mobile Radio Communication Systems (AREA)
Abstract
The invention discloses a system and a method for safe network access of a radio-frequency identification system, belonging to the field of network security. The system comprises a label, a reader-writer and a back-end application system, wherein the label is composed of a hardware structure consisting of an antenna and a processing module and is characterized in that the hardware structure further comprises a security authentication module for realizing bidirectional identify authentication between the label and the reader-writer. The hardware structure of the reader-writer comprises an antenna, a radio-frequency communication module and a control processing module and is characterized by further comprising a completeness measuring module, an identity authentication unit, a network access proxy module and a strategy management module. The back-end application system comprises a server with a communication interface unit, and a service query unit is software and comprises an authentication module, a verification module and a security management module. According to the invention, illegal labels, illegal readers-writers and illegal access of malicious back-end application systems are prevented effectively, and the credible state of the reader-writer accessing to the network is fully guaranteed.
Description
Technical field
The present invention relates to a kind of network access system and method for radio-frequency recognition system, particularly a kind of network access system of safe radio-frequency recognition system and method.
Background technology
At present, radio-frequency recognition system is made up of label, read write line and backend application system.Wherein, adopt radiofrequency signal to communicate between label with read write line, between read write line and backend application system, then adopt the communication mode of wire transmission or wireless transmission.In the process that the network setting up radio-frequency recognition system connects, communication between read write line and backend application system, and the communication between read write line and label all also exists no small security risk, simultaneously, as accessing terminal of radio-frequency (RF) identification network, read write line is faced with the same various security risks that to access terminal with other.The research that the current network for radio-frequency recognition system connects is mostly is be absorbed in functionally to expand, and considers less in fail safe.Based on its composition structure, there is the security risk of several respects in radio-frequency recognition system in the process setting up network connection.The first, because label does not possess the ability that the read-write equipment communicated is carried out with it in identification, make label there is the security risk of being attacked by illegal read write line; The second, owing to communicating based on special frequency channel between label with read write line, and lack necessary authentication therebetween, make the communication information between the two there is the security risk being ravesdropping, distorting and destroying; 3rd, because read write line lacks necessary security protection, make to there is in the data of read-write terminal Storage and Processing the security risk be tampered; 4th, the communication between read write line and backend application system lacks necessary authentication and access control means, makes back end communications information there is the security risk being stolen, distorting and destroying.
Summary of the invention
The present invention is directed to the applied environment of radio-frequency recognition system, provide a kind of Safe Transformation method of radio-frequency recognition system and a kind of network security access scheme for radio-frequency recognition system, solve current radio-frequency recognition system in the problem setting up the identity spoofing in network attach procedure, information is distorted and illegally accessed.
Radio-frequency recognition system in the present invention comprises three parts: label, read write line and backend application system.
Label comprises the hardware composition of antenna and processing module, it is characterized in that hardware forms the security authentication module further comprised for realizing carrying out bidirectional identity authentication between read write line.
Read write line comprises antenna, the hardware composition of radio-frequency communication module and control treatment module, it is characterized in that further comprising for read write line provides secure hardware module and the Security Middleware layer of hardware level secure service function, this Security Middleware layer adopts embedded chip, Security Middleware layer software comprises the integrity measurement module for realizing carrying out the crucial software and hardware configuration of read write line integrity measurement, for realize read write line respectively with label, backend application system carries out the identification authenticating unit of bidirectional identity authentication, for realizing the network insertion proxy module of read write line as the network security access function of terminal, for managing the policy management module of the security strategy in read write line in network insertion process.
Backend application system adopts the server containing communications interface unit, service-seeking unit on server is software, service-seeking unit composition comprise authentication module for realizing carrying out with read write line bidirectional identity authentication, for complete the integrity state of the crucial software and hardware of read write line is verified correction verification module, for realizing the safety management module of the unified management of the security strategies such as authentication to backend application system, completeness check and network admittance.
In radio-frequency recognition system of the present invention label antenna A be bi-directionally connected with processing module and security authentication module respectively, be coupled energy transferring label and read write line between and the data communication of the antenna B in read write line by radiofrequency signal;
Being bi-directionally connected between processing module and security authentication module, being responsible for receiving radiofrequency signal and data are resolved;
Security authentication module realizes the bidirectional identity authentication between read write line, ensures that the privacy information in label transmits between legitimate device.
Read write line is the core component of radio-frequency recognition system in the present invention, mainly complete three basic functions in the present invention: 1) according to the integrity measurement strategy of backend application system, complete the integrity measurement to own configuration information, collect measurement results, application system proposes network connecting request to the back-end; 2) according to the communication protocol of System Back-end communication, realize being connected with the network security of backend application system; 3) communication protocol between basis and label, realizes the bidirectional identity authentication between selected label.
In read write line, be bi-directionally connected between antenna B and radio-frequency communication module, be coupled energy transferring label and read write line between and the data communication of the antenna A in label by radiofrequency signal, and the signal received from antenna A sent to radio-frequency communication module;
Be bi-directionally connected between radio-frequency communication module and control treatment module, by receiving the instruction that control treatment module issues, the radiofrequency signal realized sending from antenna B or receiving encapsulates or resolves;
Control treatment module is bi-directionally connected respectively and between radio-frequency communication module and secure hardware module, as the hardcore processing module of read write line, is responsible for scheduling and the process of all data in inside of read write line;
Secure hardware module is bi-directionally connected respectively and between identification authenticating unit and integrity measurement module, as the core security hardware component being read write line, is a small-sized SOC (system on a chip) having crypto-operation unit and memory cell.Specifically can adopt COS chip; By providing the characteristic such as key management and configuration management, together with other software function module, the authentication of implementation platform, safe storage, data encryption, the function such as access control and integrity measurement;
Being bi-directionally connected between identification authenticating unit and integrity measurement module, is the software function module being responsible for read write line and label, bidirectional identity authentication between read write line and backend application system;
Integrity measurement module has been responsible for the software module to read write line terminal key soft hardware integrality state collection;
Network insertion agency respectively and identification authenticating unit, to be bi-directionally connected between integrity measurement module and policy management module, it is the software comprising modules of read write line, be responsible for the network insertion strategy that strategically administration module issues, set up and safeguard that read write line is connected with the network of backend application system;
Policy management module is the software comprising modules of read write line, is responsible for the implementation status of the formulation of read write line internal security strategy, amendment and regular query strategy, and supervises the implementation status of the security strategy that backend application system issues.
Backend application system is the backend services treatment system of radio-frequency recognition system, is responsible for the parsing to all data of the front end communication system that label and read write line form and process.
Be bi-directionally connected between communications interface unit and service-seeking unit, mainly complete parsing and the encapsulation of the communication data between read write line;
Service-seeking unit respectively and authentication module, to be bi-directionally connected between correction verification module and safety management module, be mainly the inquiry service that front end communication system provides related service, simultaneously for the authentication module on upper strata, correction verification module and safety management module provide the service support on basis;
Be bi-directionally connected between correction verification module and authentication module, according to the network connection of system and the strategy of integrity measurement, complete the completeness check docked into read write line;
Authentication module mainly completes the authentication of read write line and provides authentication result to read write line;
Safety management module is bi-directionally connected respectively and between correction verification module and authentication module, mainly completes the function that network connects decision-making and security policy manager; Network decision mainly according to network connection strategy and the integrity measurement strategy of system, judges whether current read-write device is in trusted state, to determine whether allow its access network, connect with it; Tactical management is responsible to define all security strategies of system, and monitor the implementation status of security strategy, the secure data bag that safety management module is responsible for service-seeking module forwards is come simultaneously is resolved and distributes, and the session key between unified management read write line and label.
Invention effect
1. the present invention effectively prevent the illegal access of illegal label, illegal read write line and malice backend application system, ensure that radio-frequency recognition system is in network connection establishment process, the legitimacy of label, read write line and backend application system identity.
2. the invention provides the mechanism of the read write line of log on access being carried out to the verification of crucial software and hardware state integrity, and the mechanism of repairing Secure isolation and the safety of the read write line that crucial software and hardware state integrity is destroyed is provided, fully ensure that the state of the read write line of access network is credible.
Accompanying drawing explanation
The composition schematic diagram of Fig. 1 radio-frequency recognition system.
Embodiment
Workflow of the present invention is divided into two stages by priority execution sequence: back-end network access phase and front network access phase.Back-end network connects the network establishment of connection stage referred between read write line and backend application system, and front network connects the authentication phase of the equipment identities referred between read write line and label.
System is carrying out, in network attach procedure, completing the certification to read write line by the authentication module in backend application system, and its workflow is as follows.
1) the network insertion agency of read write line is by obtaining the request strategy of network connection to policy management module, initiates application system to the back-end and carries out network connecting request;
2) communications interface unit of backend application system receives and forwards this request to service-seeking unit, service-seeking unit is being transmitted to safety management module to solicited message, safety management module is according to network connecting request, the equipment issued initiating connection request carries out the order of authentication to authentication module, authentication module composition is to the ID authentication request packet of read write line and issue service-seeking unit, and service-seeking unit is acted on behalf of this Packet Generation by communications interface unit to the network insertion of read write line;
3) after the network insertion agency of read write line receives this authentication request, issue and collect its identity information and generate the order of ID authentication request packet to identification authenticating unit, identification authenticating unit is by communicating with policy management module, obtain the collection strategy of identity information, by communicating with secure hardware module, the identity information of read write line is extracted according to collection strategy, and the authentication request generated backend application system, these two packets are acted on behalf of the communications interface unit sending to backend application system in the lump by network insertion;
4) after the communications interface unit of backend application system receives this packet, by service-seeking module, this packet is transmitted to safety management module, safety management module is resolved this packet, obtain the identity information data bag of read write line and the authentication request packet to backend application system, and be transmitted to authentication module, the authenticity of the identity information that authentication module checking read write line provides, if authentication failed, then tell safety management module, safety management module is stopped with the communication of this equipment by service-seeking module notice communications interface unit and records the information that this equipment provides, in write blacklist, generate the system journal of this operation simultaneously, flow process terminates, if the verification passes, step 5) is performed,
5) authentication module forwards according to safety management module the ID authentication request packet to backend application system of coming, obtain the identity information of backend application system, simultaneously, notice correction verification module initiates the state integrity check request to read write line, authentication module and correction verification module by with service-seeking module, the identity information of backend application system is organized bag together with the solicited message verified current read-write device state integrity information and sends to the network insertion of read write line to act on behalf of through communications interface unit;
6) after the network insertion agency of read write line receives the packet of this authentication information and checking request, first authentication information is resolved, and identity verify is carried out to authentication information, if differentiate unsuccessfully, then stop the communication with current back end application system, record the identity information of this backend application system, generate the network insertion daily record of this operation, flow process terminates simultaneously; If differentiate to pass through, perform step 7);
7) read write line network insertion agency communicates with policy management module, obtain integrity information collection strategy, and issue the order of the integrity information of the software and hardware configuration of collecting current read-write device and strategy to integrality metric module, the soft hardware integrality information of integrity measurement module collection read write line, after secure hardware module encryption, sends to the integrity information after encryption the communications interface unit of backend application system through network insertion agency;
8) after the communications interface unit of backend application system receives the integrity information that read write line network agent sends, this information through service-seeking module forwards to safety management module, safety management module sends to correction verification module after resolving this information, correction verification module carries out completeness check to the integrity information after parsing, the integrity state information of the information after parsing and system storage is carried out consistency checking, if the verification passes, then tell safety management module, safety management module agrees to that setting up this connects, and the packet agreeing to set up network connecting request is sent to the network Connection Proxy of read write line by communications interface unit through service-seeking module, back-end network connects flow process to be terminated, perform step 13), if authentication failed, then perform step 9),
9) correction verification module sends to safety management module the failed result of verification, safety management module assert that this read write line integrity state is destroyed, be in insincere state, issue the Secure isolation order in network connection security strategy, Secure isolation order, through service-seeking module, sends to the network insertion of read write line to act on behalf of by communications interface unit;
10) network insertion agency performs Secure isolation strategy, allows current read-write device be in Secure isolation state, and current state information is sent to the communications interface unit of backend application system;
11) after communications interface unit receives the Secure isolation state information of read write line, through service-seeking unit forwards to safety management module, after safety management module receives this information, verify the authenticity of its isolation, after confirming its Secure isolation state, issue safe correcting strategy to service-seeking module, be transmitted to the network insertion agency of read write line through communication interface modules;
12) after network insertion agency receives safe correcting strategy, this strategy is sent to control treatment module by integrity measurement module, secure hardware module, control treatment module performs safe correcting strategy, integrality reparation is carried out to read write line state, after reparation completes, repeat this network attach procedure, namely get back to step 1).
Authentication between read write line with label is based upon setting up on basis that network is connected of read write line and backend application system to carry out, and its flow process is described below.
13) request of the session key of the label that the communications interface unit initiation that application system is to the back-end acted on behalf of in the network insertion of read write line obtains and selectes;
14) communications interface unit of backend application system this solicited message through service-seeking module forwards to safety management module, safety management module searches this session key, through service-seeking module, the network insertion of read write line is sent to act on behalf of by communications interface unit;
15) after read write line receives this key, this key is transmitted to secure hardware module through identification authenticating unit, communicate with policy management module simultaneously, obtain the strategy generating ID authentication request information, and this strategy is transmitted to identification authenticating unit, identification authenticating unit is by the communication with secure hardware module, and the radiofrequency signal of the authentication request to label successively after control treatment module, radio-frequency communication module and antenna B transmission session key sends to the antenna A of label;
16) after the antenna A of label receives authentication request radiofrequency signal, this signal is transmitted to processing module, after processing module receives this signal, signal is resolved, issue the instruction of collecting identity information after parsing, with generating, the instruction of ID authentication request is carried out to security authentication module to read write line, security authentication module receives producing authentication information after instruction, and produces the authentication request to read write line, and treated module converter is that radiofrequency signal sends to the antenna B of read write line together by antenna A;
17) after antenna B receives this radiofrequency signal, through radio-frequency communication module, be transmitted to control treatment module, control treatment module is resolved this radiofrequency signal, resolve after authentication information and authentication request after secure hardware module decryption processing, be transmitted to identification authenticating unit, first identification authenticating unit resolves authentication information, completes the authentication to label, if authentification failure, then stop with the communication of this label, record the identity information of this label simultaneously; If after certification is passed through, collect and the authentication information generating read write line through secure hardware module, be radiofrequency signal to send to label by antenna B antenna A through radio-frequency communication module by control treatment module package;
18) after antenna A receives the radiofrequency signal of antenna B, be transmitted to processing module, processing module is resolved this radiofrequency signal, and the identity information after resolving is transmitted to security authentication module, and the identity information of security authentication module to the read write line after parsing carries out certification, if authentification failure, stop further communicating with it and thinking that this read write line is illegality equipment, flow process terminates, and records this equipment simultaneously, if certification is passed through, then perform step 19);
19) security authentication module sends to processing module authentication result, processing module is according to authentication result, agree to the connection established between this read write line, and the radiofrequency signal agreeing to set up the connection of front radio-frequency network is issued antenna B through antenna A, front network connects flow process and terminates.
Claims (2)
1. a network access system for the radio-frequency recognition system of safety, comprises three parts: label, read write line and backend application system, is characterized in that:
Label comprises the hardware composition of antenna and processing module, and hardware forms the security authentication module further comprised for realizing carrying out bidirectional identity authentication between read write line;
Read write line comprises antenna, the hardware composition of radio-frequency communication module and control treatment module, it is characterized in that further comprising for read write line provides secure hardware module and the Security Middleware layer of hardware level secure service function, this Security Middleware layer adopts embedded chip, Security Middleware layer software comprises the integrity measurement module for realizing carrying out the crucial software and hardware configuration of read write line integrity measurement, for realize read write line respectively with label, backend application system carries out the identification authenticating unit of bidirectional identity authentication, for realizing the network insertion proxy module of read write line as the network security access function of terminal, for managing the policy management module of the security strategy in read write line in network insertion process,
Backend application system adopts the server containing communications interface unit, service-seeking unit on server is software, service-seeking unit composition comprise authentication module for realizing carrying out with read write line bidirectional identity authentication, for complete the integrity state of the crucial software and hardware of read write line is verified correction verification module, for realizing the safety management module of the unified management of the security strategies such as authentication to backend application system, completeness check and network admittance;
In radio-frequency recognition system label antenna A be bi-directionally connected with processing module and security authentication module respectively, be coupled energy transferring label and read write line between and the data communication of the antenna B in read write line by radiofrequency signal;
Being bi-directionally connected between processing module and security authentication module, being responsible for receiving radiofrequency signal and data are resolved;
Security authentication module realizes the bidirectional identity authentication between read write line, ensures that the privacy information in label transmits between legitimate device;
In read write line, be bi-directionally connected between antenna B and radio-frequency communication module, be coupled energy transferring label and read write line between and the data communication of the antenna A in label by radiofrequency signal, and the signal received from antenna A sent to radio-frequency communication module;
Be bi-directionally connected between radio-frequency communication module and control treatment module, by receiving the instruction that control treatment module issues, the radiofrequency signal realized sending from antenna B or receiving encapsulates or resolves;
Control treatment module is bi-directionally connected respectively and between radio-frequency communication module and secure hardware module, as the hardcore processing module of read write line, is responsible for scheduling and the process of all data in inside of read write line;
Secure hardware module is bi-directionally connected respectively and between identification authenticating unit and integrity measurement module, as the core security hardware component of read write line, is a small-sized SOC (system on a chip) having crypto-operation unit and memory cell;
Being bi-directionally connected between identification authenticating unit and integrity measurement module, is the software function module being responsible for read write line and label, bidirectional identity authentication between read write line and backend application system;
Integrity measurement module has been responsible for the software module to read write line terminal key soft hardware integrality state collection;
Network insertion agency respectively and identification authenticating unit, to be bi-directionally connected between integrity measurement module and policy management module, it is the software comprising modules of read write line, be responsible for the network insertion strategy that strategically administration module issues, set up and safeguard that read write line is connected with the network of backend application system;
Policy management module is the software comprising modules of read write line, is responsible for the implementation status of the formulation of read write line internal security strategy, amendment and regular query strategy, and supervises the implementation status of the security strategy that backend application system issues;
Backend application system is the backend services treatment system of radio-frequency recognition system, is responsible for the parsing to all data of the front end communication system that label and read write line form and process;
Be bi-directionally connected between communications interface unit and service-seeking unit, mainly complete parsing and the encapsulation of the communication data between read write line;
Service-seeking unit respectively and authentication module, to be bi-directionally connected between correction verification module and safety management module, be mainly the inquiry service that front end communication system provides related service, simultaneously for the authentication module on upper strata, correction verification module and safety management module provide the service support on basis;
Be bi-directionally connected between correction verification module and authentication module, according to the network connection of system and the strategy of integrity measurement, complete the completeness check docked into read write line;
Authentication module mainly completes the authentication of read write line and provides authentication result to read write line;
Safety management module is bi-directionally connected respectively and between correction verification module and authentication module, mainly completes the function that network connects decision-making and security policy manager; Network decision refers to network connection strategy and the integrity measurement strategy of system, judges whether current read-write device is in trusted state, to determine whether allow its access network, connect with it; Tactical management refers to the security strategy that formulation system is all, and monitor the implementation status of security strategy, the secure data bag that safety management module is responsible for service-seeking module forwards is come simultaneously is resolved and distributes, and the session key between unified management read write line and label.
2. application rights requires the method for network access of a kind of safe radio-frequency recognition system of system described in 1, it is characterized in that step is as follows:
1) the network insertion agency of read write line is by obtaining the request strategy of network connection to policy management module, initiates application system to the back-end and carries out network connecting request;
2) communications interface unit of backend application system receives and forwards this request to service-seeking unit, service-seeking unit is being transmitted to safety management module to solicited message, safety management module is according to network connecting request, the equipment issued initiating connection request carries out the order of authentication to authentication module, authentication module composition is to the ID authentication request packet of read write line and issue service-seeking unit, and service-seeking unit is acted on behalf of this Packet Generation by communications interface unit to the network insertion of read write line;
3) after the network insertion agency of read write line receives this authentication request, issue and collect its identity information and generate the order of ID authentication request packet to identification authenticating unit, identification authenticating unit is by communicating with policy management module, obtain the collection strategy of identity information, by communicating with secure hardware module, the identity information of read write line is extracted according to collection strategy, and the authentication request generated backend application system, these two packets are acted on behalf of the communications interface unit sending to backend application system in the lump by network insertion;
4) after the communications interface unit of backend application system receives this packet, by service-seeking module, this packet is transmitted to safety management module, safety management module is resolved this packet, obtain the identity information data bag of read write line and the authentication request packet to backend application system, and be transmitted to authentication module, the authenticity of the identity information that authentication module checking read write line provides, if authentication failed, then tell safety management module, safety management module is stopped with the communication of this equipment by service-seeking module notice communications interface unit and records the information that this equipment provides, in write blacklist, generate the system journal of this operation simultaneously, flow process terminates, if the verification passes, step 5 is performed),
5) authentication module forwards according to safety management module the ID authentication request packet to backend application system of coming, obtain the identity information of backend application system, simultaneously, notice correction verification module initiates the state integrity check request to read write line, authentication module and correction verification module by with service-seeking module, the identity information of backend application system is organized bag together with the solicited message verified current read-write device state integrity information and sends to the network insertion of read write line to act on behalf of through communications interface unit;
6) after the network insertion agency of read write line receives the packet of this authentication information and checking request, first authentication information is resolved, and identity verify is carried out to authentication information, if differentiate unsuccessfully, then stop the communication with current back end application system, record the identity information of this backend application system, generate the network insertion daily record of this operation, flow process terminates simultaneously; If differentiate to pass through, perform step 7);
7) read write line network insertion agency communicates with policy management module, obtain integrity information collection strategy, and issue the order of the integrity information of the software and hardware configuration of collecting current read-write device and strategy to integrality metric module, the soft hardware integrality information of integrity measurement module collection read write line, after secure hardware module encryption, sends to the integrity information after encryption the communications interface unit of backend application system through network insertion agency;
8) after the communications interface unit of backend application system receives the integrity information that read write line network agent sends, this information through service-seeking module forwards to safety management module, safety management module sends to correction verification module after resolving this information, correction verification module carries out completeness check to the integrity information after parsing, the integrity state information of the information after parsing and system storage is carried out consistency checking, if the verification passes, then tell safety management module, safety management module agrees to that setting up this connects, and the packet agreeing to set up network connecting request is sent to the network Connection Proxy of read write line by communications interface unit through service-seeking module, back-end network connects flow process to be terminated, perform step 13), if authentication failed, then perform step 9),
9) correction verification module sends to safety management module the failed result of verification, safety management module assert that this read write line integrity state is destroyed, be in insincere state, issue the Secure isolation order in network connection security strategy, Secure isolation order, through service-seeking module, sends to the network insertion of read write line to act on behalf of by communications interface unit;
10) network insertion agency performs Secure isolation strategy, allows current read-write device be in Secure isolation state, and current state information is sent to the communications interface unit of backend application system;
11) after communications interface unit receives the Secure isolation state information of read write line, through service-seeking unit forwards to safety management module, after safety management module receives this information, verify the authenticity of its isolation, after confirming its Secure isolation state, issue safe correcting strategy to service-seeking module, be transmitted to the network insertion agency of read write line through communication interface modules;
12) after network insertion agency receives safe correcting strategy, this strategy is sent to control treatment module by integrity measurement module, secure hardware module, control treatment module performs safe correcting strategy, integrality reparation is carried out to read write line state, after reparation completes, repeat this network attach procedure, namely get back to step 1);
13) request of the session key of the label that the communications interface unit initiation that application system is to the back-end acted on behalf of in the network insertion of read write line obtains and selectes;
14) communications interface unit of backend application system this solicited message through service-seeking module forwards to safety management module, safety management module searches this session key, through service-seeking module, the network insertion of read write line is sent to act on behalf of by communications interface unit;
15) after read write line receives this key, this key is transmitted to secure hardware module through identification authenticating unit, communicate with policy management module simultaneously, obtain the strategy generating ID authentication request information, and this strategy is transmitted to identification authenticating unit, identification authenticating unit is by the communication with secure hardware module, and the radiofrequency signal of the authentication request to label successively after control treatment module, radio-frequency communication module and antenna B transmission session key sends to the antenna A of label;
16) after the antenna A of label receives authentication request radiofrequency signal, this signal is transmitted to processing module, after processing module receives this signal, signal is resolved, issue the instruction of collecting identity information after parsing, with generating, the instruction of ID authentication request is carried out to security authentication module to read write line, security authentication module receives producing authentication information after instruction, and produces the authentication request to read write line, and treated module converter is that radiofrequency signal sends to the antenna B of read write line together by antenna A;
17) after antenna B receives this radiofrequency signal, through radio-frequency communication module, be transmitted to control treatment module, control treatment module is resolved this radiofrequency signal, resolve after authentication information and authentication request after secure hardware module decryption processing, be transmitted to identification authenticating unit, first identification authenticating unit resolves authentication information, completes the authentication to label, if authentification failure, then stop with the communication of this label, record the identity information of this label simultaneously; If after certification is passed through, collect and the authentication information generating read write line through secure hardware module, be radiofrequency signal to send to label by antenna B antenna A through radio-frequency communication module by control treatment module package;
18) after antenna A receives the radiofrequency signal of antenna B, be transmitted to processing module, processing module is resolved this radiofrequency signal, and the identity information after resolving is transmitted to security authentication module, and the identity information of security authentication module to the read write line after parsing carries out certification, if authentification failure, stop further communicating with it and thinking that this read write line is illegality equipment, flow process terminates, and records this equipment simultaneously, if certification is passed through, then perform step 19);
19) security authentication module sends to processing module authentication result, processing module is according to authentication result, agree to the connection established between this read write line, and the radiofrequency signal agreeing to set up the connection of front radio-frequency network is issued antenna B through antenna A, front network connects flow process and terminates.
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201210411867.7A CN102932338B (en) | 2012-10-24 | 2012-10-24 | System and method for safe network access of radio-frequency identification system |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN201210411867.7A CN102932338B (en) | 2012-10-24 | 2012-10-24 | System and method for safe network access of radio-frequency identification system |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| CN102932338A CN102932338A (en) | 2013-02-13 |
| CN102932338B true CN102932338B (en) | 2015-01-21 |
Family
ID=47647040
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| CN201210411867.7A Active CN102932338B (en) | 2012-10-24 | 2012-10-24 | System and method for safe network access of radio-frequency identification system |
Country Status (1)
| Country | Link |
|---|---|
| CN (1) | CN102932338B (en) |
Families Citing this family (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN103281189B (en) * | 2013-05-23 | 2016-08-17 | 无锡昶达信息技术有限公司 | A kind of lightweight security protocol verification system and method for radio frequency identification equipment |
| CN105099710A (en) * | 2015-08-28 | 2015-11-25 | 中国航天科工集团第二研究院七〇六所 | Cross-domain access control method for trusted radio frequency identification network |
| CN106855924B (en) * | 2016-12-16 | 2020-05-26 | 南方城墙信息安全科技有限公司 | Embedded smart chip devices and background application systems |
| CN109214221B (en) * | 2018-08-23 | 2022-02-01 | 武汉普利商用机器有限公司 | Authentication method of identity card reader, upper computer and identity card reader |
| CN110492994B (en) * | 2019-07-25 | 2022-08-09 | 北京笛卡尔盾科技有限公司 | Trusted network access method and system |
| CN115456604B (en) * | 2022-11-08 | 2023-01-31 | 大尧信息科技(湖南)有限公司 | An Online Reconfiguration System for Remote Experimental Projects |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN1433558A (en) * | 2000-02-04 | 2003-07-30 | 3M创新有限公司 | Method of authenticating tag |
| CN1932835A (en) * | 2006-09-30 | 2007-03-21 | 华中科技大学 | Safety identification method in radio frequency distinguishing system |
| CN101159549A (en) * | 2007-11-08 | 2008-04-09 | 西安西电捷通无线网络通信有限公司 | Bidirectional access authentication method |
| CN101976365A (en) * | 2010-11-05 | 2011-02-16 | 中国航天科工集团第二研究院七○六所 | Safe radio frequency identification system |
Family Cites Families (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7940179B2 (en) * | 2005-01-12 | 2011-05-10 | British Telecommunications Public Limited Company | Radio frequency identification tag security systems |
-
2012
- 2012-10-24 CN CN201210411867.7A patent/CN102932338B/en active Active
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN1433558A (en) * | 2000-02-04 | 2003-07-30 | 3M创新有限公司 | Method of authenticating tag |
| CN1932835A (en) * | 2006-09-30 | 2007-03-21 | 华中科技大学 | Safety identification method in radio frequency distinguishing system |
| CN101159549A (en) * | 2007-11-08 | 2008-04-09 | 西安西电捷通无线网络通信有限公司 | Bidirectional access authentication method |
| CN101976365A (en) * | 2010-11-05 | 2011-02-16 | 中国航天科工集团第二研究院七○六所 | Safe radio frequency identification system |
Also Published As
| Publication number | Publication date |
|---|---|
| CN102932338A (en) | 2013-02-13 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN102448061B (en) | Method and system for preventing phishing attack on basis of mobile terminal | |
| US10681540B2 (en) | Communication network system, transmission node, reception node, and message checking method | |
| CN103517273B (en) | Authentication method, managing platform and Internet-of-Things equipment | |
| CN111783068B (en) | Device authentication method, system, electronic device and storage medium | |
| CN103259667B (en) | The method and system of eID authentication on mobile terminal | |
| CN101777978B (en) | Method and system based on wireless terminal for applying digital certificate and wireless terminal | |
| CN102932338B (en) | System and method for safe network access of radio-frequency identification system | |
| CN112073375A (en) | Isolation device and isolation method suitable for power Internet of things client side | |
| CN102638468B (en) | The method of protection information transmission security, transmitting terminal, receiving terminal and system | |
| CN107148019B (en) | It is a kind of for connecting the method and apparatus of wireless access point | |
| CN110267270B (en) | Identity authentication method for sensor terminal access edge gateway in transformer substation | |
| CN101853409B (en) | RFID (Radio Frequency Identification) system, reader and data transmission method | |
| CN110147666B (en) | Lightweight NFC identity authentication method and IoT communication platform in IoT scenarios | |
| CN114499876B (en) | Internet of Things data storage method based on blockchain and NB-IoT chip | |
| CN102026180A (en) | M2M transmission control method, device and system | |
| CN106851632A (en) | A kind of smart machine accesses the method and device of WLAN | |
| CN113766450B (en) | Vehicle virtual key sharing method, mobile terminal, server and vehicle | |
| CN109347875A (en) | Internet of things equipment, platform of internet of things and the method and system for accessing platform of internet of things | |
| CN108024243A (en) | A kind of eSIM is caught in Network Communication method and its system | |
| CN111988328A (en) | A method and system for ensuring data security of a collection terminal of a power generation unit in a new energy power plant | |
| CN117061164A (en) | Internet of things system access security processing method | |
| CN107612949A (en) | A kind of intelligent wireless terminal access authentication method and system based on radio-frequency fingerprint | |
| CN113452517A (en) | Key updating method, device, system, storage medium and terminal | |
| CN102158863A (en) | System and method for authenticating JAVA-based mobile terminal, server and terminal | |
| CN108566385A (en) | The mutual authentication method of efficient secret protection based on cloud |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| C06 | Publication | ||
| PB01 | Publication | ||
| C10 | Entry into substantive examination | ||
| SE01 | Entry into force of request for substantive examination | ||
| C14 | Grant of patent or utility model | ||
| GR01 | Patent grant |