The invention discloses a bidirectional
security authentication method for an RFIP
system. Aiming at the defects that according to existing
system certification, calculation and storage cost much and are vulnerable to resetting and counterfeit attacks, the bidirectional
security authentication method combines pseudo-random numbers,
shared secret keys and hash functions to achieve
authentication encryption. According to the method, a
label and a back-end data base share a secret key, an identification and the two hash functions; a
label identification and a logic operation result encrypted by the hash functions of the
system serve as response messages to be sent to the back-end data base, so that system
authentication expenses are substantially reduced; the back-end data base carries out system
hash function encryption on an
authentication secret key and a private hash
encryption result and responds the authentication secret key and the private hash encryption result to the
label, and reverse authentication carried out by the label on the system is achieved. A reader identification does not need to be stored in the label, pseudo-random numbers are needless to be generated, accordingly, cost of the label is reduced, and the application range of the method is enlarged. The method is high in security, low in cost and complexity and capable of being used in environments with large label scales on the premise that basic authentication functions are completed.