Abstract:
Abstract: In the traceability system of Chinese herbal medicine quality, due to the characteristics of Chinese herbal medicines, we need the shared ownership of radio frequency identification (RFID) tags between the Chinese herbal parties. Because Chinese herbal medicines have unique features as compared to other ordinary commodities, we should put forward higher requirements for the security of RFID tag's data based on the consideration of medicines quality and safety. In the process of the ownership transfer of RFID tags, the transfer protocol must have the advantages of high security, being able to withstand external attacks and prevent leakage of privacy data for real traceability of Chinese herbal medicines. But common ownership transfer protocols are mostly related to the ownership transfer process with a single tag, and have prevalence of privacy data leakage, ownership transfer process instability and other shortcomings. How to achieve the transfer protocol of the shared ownership becomes the emphasis to ensure data security focused on RFID tag, and also becomes the important key to the quality guarantee of Chinese herbal medicines. For the defects of existing ownership transfer protocol with single label, using TTP (trusted third party) symmetric encryption mechanism, we put a new shared ownership transfer protocol i.e. TTP model shared ownership transfer protocol (TSOTP) based on the lightweight encryption algorithm. After the process of initial label certification by the TTP certification authority, we use the symmetric encryption algorithms to produce the symmetric key of generation group. The new owner of the tags uses a shared group key to achieve authentication, and then assigns a new key for the RFID tag which is ultimately authorized; when the new owner of the tags receives the updated label key to confirm the results using hash function operation with the information of the backend server received,then detecting the legality of the shared key, he can read the sensitive data of label. In the implementation of RFID authentication protocol, the calculation of certification and response process will consume a lot of system resources, and how to reduce the amount of calculation becomes a key for the efficiency of protocol operation. After the reader receives the confirmation label, the label will generate a random number by the XOR,the result is encrypted by hash function and to compared with the received information for the previous step,if they get on matching,it will be sent a responsed information to the server,otherwise it will terminate implementation of the agreement in order to avoid the occurrence of the phenomenon of replay attacks. TSOTP protocol can improve the stability of the tab in the transfer process of ownership, well achieve the safe transfer of the shared ownership among users, ensure data security of RFID tags, improve forward and backward security, reduce private data leaks, Dos attacks, replay attacks and other risks, and meanwhile avoid the repeated transfer of ownership, simplify the calculation amount of label certification, which shows good stability and efficiency and meets the research needs of Chinese herbal medicine quality traceability system. Malicious attackers frequently tamper tag data and collect herbs in the transfer process in order to achieve the purpose of obtaining illegal profits. How to improve security of the RFID tags for Chinese herbal's circulation will become the research focus in the future process of medicine traceability system establishment.