无线射频所有权转移协议在中药材溯源中的应用

    Application of radio frequency iIdentification (RFID) ownership transfer protocol on tracing of Chinese herbal-trace

    • 摘要: 针对现有的所有权转移协议,大多只涉及到单个标签的所有权转移过程,普遍存在隐私数据泄露、所有权转移过程不稳定等问题,该文在轻量级加密算法的基础上,提出一种改进的共享所有权转移协议(TSOTP,TTP model shared ownership transfer protocol),采用基于可信第三方(TTP,trusted third party)的对称加密机制,在完成初始标签认证后,通过TTP授权认证,使用对称加密算法,产生群组对称密钥,新所有者利用共享群组密钥对标签身份进行认证,然后为标签分配新的密钥,从而最终获得授权,读取标签中包含的药材敏感数据。TSOTP协议能够提高标签在所有权转移过程中的稳定性,很好地实现所有权在共享用户之间的安全转移,保证标签的数据安全,减少隐私数据泄露、Dos攻击、重放攻击等风险,提高前向与后向安全性,同时可以避免所有权重复转移,简化了标签认证计算量。经过试验证明,TSOTP协议与群组所有权转移协议(GOT,group ownership transfer)协议相比,标签数据库认证消耗时间节省57%,标签计算量消耗时间节省38%,能够成功阻止重放攻击和异步攻击等,具备较好的稳定性和认证效率,可以满足中药材质量溯源系统的研究需要,研究结果为建立中药材质量溯源系统的标签安全机制提供了技术参考。

       

      Abstract: Abstract: In the traceability system of Chinese herbal medicine quality, due to the characteristics of Chinese herbal medicines, we need the shared ownership of radio frequency identification (RFID) tags between the Chinese herbal parties. Because Chinese herbal medicines have unique features as compared to other ordinary commodities, we should put forward higher requirements for the security of RFID tag's data based on the consideration of medicines quality and safety. In the process of the ownership transfer of RFID tags, the transfer protocol must have the advantages of high security, being able to withstand external attacks and prevent leakage of privacy data for real traceability of Chinese herbal medicines. But common ownership transfer protocols are mostly related to the ownership transfer process with a single tag, and have prevalence of privacy data leakage, ownership transfer process instability and other shortcomings. How to achieve the transfer protocol of the shared ownership becomes the emphasis to ensure data security focused on RFID tag, and also becomes the important key to the quality guarantee of Chinese herbal medicines. For the defects of existing ownership transfer protocol with single label, using TTP (trusted third party) symmetric encryption mechanism, we put a new shared ownership transfer protocol i.e. TTP model shared ownership transfer protocol (TSOTP) based on the lightweight encryption algorithm. After the process of initial label certification by the TTP certification authority, we use the symmetric encryption algorithms to produce the symmetric key of generation group. The new owner of the tags uses a shared group key to achieve authentication, and then assigns a new key for the RFID tag which is ultimately authorized; when the new owner of the tags receives the updated label key to confirm the results using hash function operation with the information of the backend server received,then detecting the legality of the shared key, he can read the sensitive data of label. In the implementation of RFID authentication protocol, the calculation of certification and response process will consume a lot of system resources, and how to reduce the amount of calculation becomes a key for the efficiency of protocol operation. After the reader receives the confirmation label, the label will generate a random number by the XOR,the result is encrypted by hash function and to compared with the received information for the previous step,if they get on matching,it will be sent a responsed information to the server,otherwise it will terminate implementation of the agreement in order to avoid the occurrence of the phenomenon of replay attacks. TSOTP protocol can improve the stability of the tab in the transfer process of ownership, well achieve the safe transfer of the shared ownership among users, ensure data security of RFID tags, improve forward and backward security, reduce private data leaks, Dos attacks, replay attacks and other risks, and meanwhile avoid the repeated transfer of ownership, simplify the calculation amount of label certification, which shows good stability and efficiency and meets the research needs of Chinese herbal medicine quality traceability system. Malicious attackers frequently tamper tag data and collect herbs in the transfer process in order to achieve the purpose of obtaining illegal profits. How to improve security of the RFID tags for Chinese herbal's circulation will become the research focus in the future process of medicine traceability system establishment.

       

    /

    返回文章
    返回