Radio Frequency Identification Integrated Circuit with Privacy Mode

By introducing the function of enabling the recycling of privacy mode in the RFID tag IC, the problem of leaking tags or item identification information in the RFID system is solved, and stronger privacy protection and user control are achieved.

CN114600121BActive Publication Date: 2025-05-30IMPINJE CORP
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202080075264.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-11-01
Filing Date
2020-10-28
Publication Date
2025-05-30
Estimated Expiration
2040-10-28

AI Technical Summary

Technical Problem

In existing RFID systems, when the RFID tag IC receives unverified reader commands, it may disclose the identification information of the tag or item, causing privacy issues.

Method used

An RFID tag IC with recycling privacy mode enabled is introduced. When the IC is in this mode, it only responds to commands containing correct verification information or specifying recycling indicators, otherwise it will not respond, thereby protecting the identification information of the tag or item.

Benefits of technology

It effectively protects the identification information of RFID tags or items, and only discloses and recycles related information when the authorized reader exists, enhancing the user's privacy control capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114600121B_ABST
    Figure CN114600121B_ABST
Patent Text Reader

Abstract

An RFID tag IC can be configured to have a privacy mode. When the tag IC is in the privacy mode, it will not respond to commands unless a previous command includes correct authentication information or specifies a recycling indicator for the tag IC. If a previous command includes correct authentication information, the tag IC will normally respond to one or more subsequent commands, e.g., by responding with one or more identifiers. If a previous command does not include correct authentication information but specifies a recycling indicator and the privacy mode enables recycling, the tag IC can respond to one or more subsequent commands with recycling information. The recycling information identifies whether an item associated with the RFID IC can be recycled or how to handle it, but does not identify the RFID IC or the item. Otherwise, the tag IC can remain silent.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross - Reference to Related Applications

[0002] This application claims priority to U.S. Provisional Patent Application No. 62 / 927,210, filed on October 29, 2019, and U.S. Provisional Patent Application No. 62 / 929,210, filed on November 1, 2019. The disclosures of the provisional applications are hereby incorporated by reference in their entireties. Background of the Invention

[0003] Radio Frequency Identification (RFID) systems typically include an RFID reader, also referred to as an RFID reader / writer or RFID interrogator, and RFID tags. RFID systems can be used in a variety of ways to locate and identify the items to which the tags are attached. In product - related and service - related industries, RFID systems are useful for tracking items being processed, inventoried, or handled. In such cases, RFID tags are typically attached to individual items or their packaging. RFID tags typically include or are radio frequency (RF) integrated circuits (ICs).

[0004] In principle, RFID technology requires the use of an RFID reader to inventory one or more RFID tags, where inventorying includes singulating tags, receiving identifiers from tags, and / or confirming received identifiers (e.g., by sending an acknowledgment command). "Singulating" is defined as the reader potentially picking out one tag from multiple tags for a reader - tag conversation. "Identifier" is defined as a number that identifies the tag or the item to which the tag is attached, such as a Tag Identifier (TID), an Electronic Product Code (EPC), etc. "Inventory round" is defined as the reader staging RFID tags for subsequent inventorying. The reader sends RF waves to perform inventorying. The RF waves are typically electromagnetic, at least in the far - field. The RF waves can also be mainly electrical or magnetic in the near - field or transitional near - field. The RF waves can encode one or more commands that command the tag to perform one or more actions. The operation of the RFID reader to send commands to the RFID tag is sometimes referred to as the reader "querying" the tag.

[0005] In a typical RFID system, the RFID reader sends a modulated RF inventory signal (command), receives a tag response, and sends an RF acknowledgment signal in response to the tag response. Tags that respond to the query RF wave respond by sending back another RF wave. The tag either initially generates the RF wave to be sent back or reflects back a portion of the query RF wave in a process called backscatter. Backscatter can occur in a variety of ways.

[0006] The reflected RF wave can encode data stored in the tag, such as numbers. The reader demodulates and decodes the response so that the reader can identify, count, or otherwise interact with the associated item. The decoded data can represent a serial number, price, date, time, destination, encrypted message, electronic signature, other attributes, any combination of attributes, etc. Thus, when the reader receives the tag data, it can learn about the item holding the tag and / or the tag itself.

[0007] RFID tags typically include an antenna section, a radio section, a power management section, and often include a logic section, a memory, or both. In some RFID tags, the power management section includes an energy storage device, such as a battery. RFID tags with an energy storage device are called battery-assisted, semi-active, or active tags. Other RFID tags can be powered only by the RF signals they receive. Such RFID tags do not include an energy storage device and are called passive tags. Of course, even passive tags typically include temporary energy and data / flag storage elements, such as capacitors or inductors. SUMMARY OF THE INVENTION

[0008] This Summary of the Invention is provided to introduce in a simplified form some concepts that will be further described in the Detailed Description below. This Summary of the Invention is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to help determine the scope of the claimed subject matter.

[0009] Embodiments relate to RFID tags and ICs having a recycling-enabled privacy mode. When the RFID IC is in the recycling-enabled privacy mode, it will not respond to commands unless a previous command (a) includes correct authentication information or (b) specifies a recycling indicator for the RFID IC. If the previous command includes correct authentication information, the RFID IC will respond normally (i.e., as if it were not in the recycling-enabled privacy mode) to one or more subsequent commands, e.g., by responding with one or more identifiers. If the previous command specifies a recycling indicator for the RFID IC, the RFID IC will respond to one or more subsequent commands with recycling information. The recycling information identifies whether the item associated with the RFID IC can be recycled or how it should be processed, but does not otherwise uniquely identify the RFID IC or the item.

[0010] These and other features and advantages will be apparent from reading the following Detailed Description and viewing the associated drawings. It should be understood that both the foregoing General Description and the following Detailed Description are merely illustrative and not restrictive of the claimed aspects. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] The following detailed description is made with reference to the accompanying drawings, in which:

[0012] Figure 1 is a block diagram of components of an RFID system.

[0013] Figure 2 is a diagram showing components of a passive RFID tag, such as a tag that can be used in a Figure 1 system.

[0014] Figure 3 is a conceptual diagram for explaining the half-duplex communication mode between components of a Figure 1 RFID system.

[0015] Figure 4 is a block diagram showing details of an RFID tag such as Figure 2 shown.

[0016] Figure 5A and 5B show the signal paths during tag-to-reader and reader-to-tag communications in the Figure 4 block diagram.

[0017] Figure 6 is a block diagram showing details of an RFID reader system such as Figure 1 shown.

[0018] Figure 7 depicts how an RFID reader and tag IC operate in normal and privacy modes according to an embodiment.

[0019] Figure 8 shows a partial state diagram of an RFID tag IC capable of operating in privacy mode according to an embodiment.

[0020] Figure 9 depicts how an RFID reader and tag IC operate in normal mode, privacy mode, and enabled recycle privacy mode according to an embodiment.

[0021] Figure 10 shows the interaction between an RFID reader and tag IC in enabled recycle privacy mode according to an embodiment.

[0022] Figure 11 is a diagram of an exemplary RFID tag IC memory configuration according to an embodiment.

[0023] Figure 12 depicts the process for an RFID tag IC in privacy mode to respond to an inventory command according to an embodiment. DETAILED DESCRIPTION

[0024] In the following detailed description, reference is made to the accompanying drawings which form a part hereof, and in which are shown by way of illustration specific embodiments or examples. These embodiments or examples may be combined, other aspects may be utilized, and structural changes may be made without departing from the spirit or scope of the present disclosure. Accordingly, the following detailed description should not be construed as limiting, and the scope of the present invention is defined by the appended claims and their equivalents.

[0025] As used herein, "memory" is one of ROM, RAM, SRAM, DRAM, NVM, EEPROM, FLASH, Fuse, MRAM, FRAM, and other similar volatile and non-volatile information storage technologies. Some portions of the memory may be writable while some portions are not. "Instruction" refers to a request to cause a tag to perform a single explicit action (e.g., write data to memory). "Command" refers to a reader request to cause one or more tags to perform one or more actions, and includes one or more tag instructions preceded by a command identifier or command code that identifies the command and / or the tag instruction. "Program" refers to a request to cause a tag to perform a set or series of instructions (e.g., read a value from memory and, if the read value is less than a threshold, then lock a memory word). "Protocol" refers to an industry standard for communication between a reader and a tag (and vice versa), such as the Class 1 Generation 2 UHF RFID protocol for communication at 860 MHz - 960 MHz of GS1 EPCglobal Inc. ("Gen2 protocol"), versions 1.2.0 and 2.0 of which are incorporated herein by reference.

[0026] It can be understood that RFID system users have privacy concerns regarding access to RFID tag IC data. For example, a consumer who purchases an item with an RFID tag IC may not want a random RFID reader to be able to retrieve information from the RFID tag IC. One possible solution is to allow the RFID tag IC to enter a "privacy mode". When the RFID tag IC is in privacy mode, it will only respond to commands from an authorized RFID reader and ignore commands from an unauthorized RFID reader. Several examples of privacy mode are described in commonly assigned U.S. Patent No. 10,402,710, issued on September 3, 2019, the entire contents of which are incorporated herein by reference.

[0027] RFID tag ICs can have different kinds of privacy modes. In one privacy mode, the RFID tag IC may not respond to any unauthorized RFID reader. In another privacy mode, the RFID tag IC may respond to certain commands with only limited information.

[0028] As an example of the latter, assume that the RFID tag IC stores information on how the associated item can be recycled or disposed of. Such information is referred to as recycling information, which may include item composition, disposal instructions, potential hazards, or other similar information. After purchasing an item, the consumer places the tag IC in a recycling privacy mode. At some later time, the consumer discards the item but neglects to de-privatize the tag IC. In this case, because the privacy mode is recycling-enabled, the RFID reader may be able to retrieve the recycling information from the tag IC. However, the RFID reader will not be able to retrieve other information unrelated to recycling from the tag IC.

[0029] Figure 1 FIG. is a diagram of components of a typical RFID system 100 in a combined embodiment. The RFID reader 110 and nearby RFID tag 120 communicate via RF signals 112 and 126. When sending data to the tag 120, the reader 110 may generate the RF signal 112 by the following steps: encoding the data, modulating an RF waveform with the encoded data, and transmitting the modulated RF waveform as the RF signal 112. Next, the tag 120 may receive the RF signal 112, demodulate the encoded data from the RF signal 112, and decode the encoded data. Similarly, when sending data to the reader 110, the tag 120 may generate the RF signal 126 by the following steps: encoding the data, modulating an RF waveform with the encoded data, and transmitting the modulated RF waveform as the RF signal 126. The data sent between the reader 110 and the tag 120 may be represented by symbols, also referred to as RFID symbols. If needed, the symbols may be delimiters, calibration values, or implemented to represent binary data, such as "0" and "1". When processed by the reader 110 and the tag 120, the symbols may be treated as values, numbers, or any other suitable data representation.

[0030] The RF waveforms emitted by the reader 110 and / or the tag 120 may be in a suitable frequency range, such as frequencies near 900 MHz, 13.56 MHz, or similar frequencies. In some embodiments, the RF signals 112 and / or 126 may include non-propagating RF signals, such as reactive near-field signals or similar signals. The RFID tag 120 may be active or battery-assisted (i.e., having its own power source), or passive. In the latter case, the RFID tag 120 may obtain power from the RF signal 112.

[0031] Figure 2 is a schematic diagram of an RFID tag 220, which can be used as Figure 1The tag 120. The tag 220 can be formed on a substantially flat inlay 222, which can be manufactured in any suitable manner. The tag 220 includes a circuit that can be implemented as an IC 224. In some embodiments, the IC 224 is manufactured using complementary metal oxide semiconductor (CMOS) technology. In other embodiments, the IC 224 can be manufactured using other technologies, such as bipolar junction transistor (BJT) technology, metal semiconductor field effect transistor (MESFET) technology, and other technologies known to those skilled in the art. The IC 224 is disposed on the inlay 222.

[0032] The tag 220 also includes an antenna for transmitting RF signals and / or interacting with RF signals. In some embodiments, the antenna can be metal etched, deposited, and / or printed on the inlay 222; a conductive wire formed with or without a substrate; a patterned non-metallic conductor (such as graphene) on a substrate; a first antenna inductively, capacitively, or conductively coupled to a second antenna; or can be manufactured in numerous other ways for forming an antenna for receiving RF waves. In some embodiments, the antenna can even be formed in the IC 224. Regardless of the antenna type, the IC 224 is electrically coupled to the antenna through a suitable IC contact ( Figure 2 not shown in the figure). As used herein, the term "electrically coupled" can mean a direct electrical connection, or it can mean a connection including one or more intermediate circuit blocks, elements, or devices. The "electric" part of the term "electrically coupled" as used herein should mean the coupling of one or more of ohmic / current, capacitance, and / or inductance. Similarly, as used herein, the terms "electrically isolated" or "electrically decoupled" mean the absence of one or more types (e.g., current, capacitance, and / or inductance) of electrical coupling at least to the extent possible. For example, elements that are electrically isolated from each other are current isolated from each other, capacitance isolated from each other, and / or inductance isolated from each other. Of course, electrically isolated components typically have some unavoidable stray capacitance or inductance coupling between them, but the purpose of isolation is to minimize this stray coupling when compared to an electrically coupled path.

[0033] IC 224 is shown as having a single antenna port, including two IC contacts electrically coupled to two antenna segments 226 and 228, which are shown here as forming a dipole. Many other embodiments using any number of ports, contacts, antennas, and / or antenna segments are possible. Antenna segments 226 and 228 are described as being separate from IC 224, but in other embodiments, the antenna segments may alternatively be formed on IC 224. The tag antenna according to the embodiment can be designed in any form and is not limited to a dipole. For example, the tag antenna can be a patch, slot, loop, coil, horn, helix, monopole, microstrip, stripline, or any other suitable antenna.

[0034] Figure 2 In "250", a top view and a side view of the tag 252 formed using a strip are depicted. The tag 252 differs from the tag 220 in that it includes a substantially flat strip substrate 254 having strip contacts 256 and 258. The IC 224 is mounted on the strip substrate 254 such that the IC contacts on the IC 224 are electrically coupled to the strip contacts 256 and 258 through appropriate connections (not shown). The strip substrate 254 is then placed on the inlay 222 such that the strip contacts 256 and 258 are electrically coupled to the antenna segments 226 and 228. The strip substrate 254 can be fixed to the inlay 222 by pressing, an interface layer, one or more adhesives, or any other suitable means.

[0035] Figure 2 In "260", a side view of another alternative way of placing the strip substrate 254 on the inlay 222 is shown. Instead of the surface of the strip substrate 254 including the strip contacts 256 / 258 facing the surface of the inlay 222, the strip substrate 254 is placed with its strip contacts 256 / 258 facing away from the surface of the inlay 222. Then, the strip contacts 256 / 258 can be capacitively coupled to the antenna segments 226 / 228 via the strip substrate 254, or conductively coupled using vias, which can be formed by crimping the strip contacts 256 / 258 to the antenna segments 226 / 228. In some embodiments, the positions of the strip substrate 254 and the inlay 222 can be reversed, with the strip substrate 254 mounted under the inlay 222 and the strip contacts 256 / 258 being electrically coupled to the antenna segments 226 / 228 via the inlay 222. Of course, in other embodiments, the strip contacts 256 / 258 can be electrically coupled to the antenna segments 226 / 228 via the inlay 222 and the strip substrate 254.

[0036] In operation, the antenna couples with RF signals in the environment and propagates the signals to the IC 224, which can harvest power based on the incoming signals and the internal state of the IC and, if appropriate, respond. If the IC 224 uses backscatter modulation, it can generate a response signal (e.g., signal 126) from the RF signals in the environment (e.g., signal 112) by modulating the reflectivity of the antenna. The IC contacts that electrically couple and decouple the IC 224 can modulate the reflectivity of the antenna, such as by changing the admittance or impedance of parallel or series circuit elements coupled to the IC contacts. If the IC 224 is capable of transmitting signals (e.g., has its own power source, is coupled to an external power source, and / or can harvest enough power to transmit signals), the IC 224 can respond by transmitting a response signal 126. In Figure 2 embodiments, antenna segments 226 and 228 are separated from the IC 224. In other embodiments, the antenna segments can alternatively be formed on the IC 224.

[0037] An RFID tag, such as tag 220, is typically attached to or associated with a separate item or item packaging. The RFID tag can be manufactured and then attached to the item or packaging, can be partially manufactured before being attached to the item or packaging and then fully manufactured when attached to the item or packaging, or the manufacturing process of the item or packaging can include the manufacturing of the RFID tag. In some embodiments, the RFID tag can be integrated into the item or packaging. In such cases, portions of the item or packaging can be used as tag components. For example, a conductive item or packaging portion can be used as a tag antenna segment or contact. A non-conductive item or packaging portion can be used as a tag substrate or inlay. If the item or packaging includes an integrated circuit or other circuitry, certain portions of the circuitry can be configured to operate as part or all of the RFID tag IC. Thus, an "RFID IC" need not be distinct from the item, but more generally refers to an item that includes an RFID IC and an antenna capable of interacting with RF waves and receiving and responding to RFID signals. Because the boundaries between the IC, tag, and item are often blurred, the terms "RFIDIC", "RFID tag", "tag", or "tag IC" as used herein can refer to the IC, tag, or even the item, so long as the referenced element is capable of having RFID functionality.

[0038] Figure 1 The components of an RFID system can communicate with each other in any number of modes. One such mode is called full duplex, where both the reader 110 and the tag 120 can transmit simultaneously. In some embodiments, the RFID system 100 is capable of full-duplex communication. Another mode, which may be more suitable for passive tags, is called the half-duplex mode and is described below.

[0039] Figure 3 is a conceptual diagram for explaining Figure 1 half-duplex communication between components of an RFID system, in which case tag 120 is implemented as a passive tag. This explanation is made with reference to a timeline and also with reference to the anthropomorphic "speaking" and "listening". Now, the actual technical implementations for "speaking" and "listening" are described.

[0040] In the half-duplex communication mode, RFID reader 110 and RFID tag 120 take turns speaking and listening to each other. As seen on the timeline, reader 110 speaks to tag 120 during an interval designated as "R→T", and tag 120 speaks to reader 110 during an interval designated as "T→R". For example, a sample R→T interval occurs during time interval 312, during which reader 110 speaks (block 332) and tag 120 listens (block 342). A subsequent sample T→R interval occurs during time interval 326, during which reader 110 listens (block 336) and tag 120 speaks (block 346). Interval 312 can be of a different duration than interval 326, and here, for illustrative purposes only, the durations are shown as approximately equal.

[0041] During interval 312, reader 110 transmits a signal such as Figure 1 the signal 112 described in

[0042] (box 352), while tag 120 receives the reader signal (box 362), processes the reader signal to extract data, and obtains power from the reader signal. When receiving the reader signal, tag 120 does not backscatter (block 372), and thus reader 110 does not receive a signal from tag 120 (block 382). Figure 2 During interval 326, also known as the backscatter time interval or backscatter interval, reader 110 does not transmit a data-bearing signal. Instead, reader 110 transmits a continuous wave (CW) signal, which is a carrier for generally unencoded information. The CW signal provides the energy for tag 120 to acquire and a waveform that tag 120 can modulate to form a backscatter response signal. Thus, during interval 326, tag 120 does not receive a signal with encoded information (box 366), but instead modulates the CW signal (box 376) to produce a backscatter signal such as

[0043] Figure 4 is shown such as Figure 2Block diagram of details of the RFID IC of the IC 224 in []. The electrical circuit 424 may be implemented in an IC, such as the IC 224. The circuit 424 implements at least two IC contacts 432 and 433, adapted to be coupled to an antenna segment such as Figure 2 the antenna segments 226 / 228 in []. When the two IC contacts form a signal input from the antenna and a signal returned to the antenna, they are generally referred to as antenna ports. The IC contacts 432 and 433 may be made in any suitable manner, such as made of conductive pads, bumps or the like. In some embodiments, the circuit 424 implements more than two IC contacts, especially when configured with multiple antenna ports and / or coupled to multiple antennas.

[0044] The circuit 424 includes a signal routing section 435, which may include signal wiring, signal routing buses, receive / transmit switches, and the like that can route signals between components of the circuit 424. The IC contacts 432 / 433 may be coupled to the signal routing section 435 electrically, capacitively, and / or inductively. For example, selectable capacitors 436 and / or 438 may capacitively couple the IC contacts 432 / 433 to the signal routing section 435, thereby electrically decoupling the IC contacts 432 / 433 from the signal routing section 435 and other components of the circuit 424.

[0045] In some cases, capacitive coupling (and resulting electrical decoupling) between the IC contacts 432 and / or 433 and components of the circuit 424 is desirable. For example, in some RFID tag embodiments, the IC contacts 432 and 433 may be electrically connected to the terminals of a tuning circuit on the tag. In these embodiments, electrically decoupling the IC contact 432 from the IC contact 433 can prevent the formation of a DC short circuit between the IC contacts via the tuning circuit.

[0046] The capacitors 436 / 438 may be implemented inside the circuit 424 and / or partially or fully outside the circuit 424. For example, a dielectric or insulating layer on the surface of the IC containing the circuit 424 may be used as the dielectric in the capacitor 436 and / or the capacitor 438. As another example, a dielectric or insulating layer on the surface of the tag substrate (e.g., the inlay 222 or the strip substrate 254) may be used as the dielectric in the capacitors 436 / 438. Metal or conductive layers located on both sides of the dielectric layer (i.e., between the dielectric layer and the IC and between the dielectric layer and the tag substrate) may then be used as the terminals of the capacitors 436 / 438. The conductive layers may include IC contacts (e.g., the IC contacts 432 / 433), antenna segments (e.g., the antenna segments 226 / 228), or any other suitable conductive layer.

[0047] Circuit 424 includes a rectifier and a PMU (Power Management Unit) 441 that harvests energy from the RF signals incident on antenna segments 226 / 228 during either or both of the reader-to-tag (R→T) and tag-to-reader (T→R) intervals to power the circuitry of IC 424. The rectifier and PMU 441 can be implemented in any manner known in the art and can include one or more components configured to convert alternating current (AC) or time-varying signals to direct current (DC) or substantially time-invariant signals.

[0048] Circuit 424 also includes a demodulator 442, a processing block 444, a memory 450, and a modulator 446. Demodulator 442 demodulates the RF signals received via IC contacts 432 / 433 and can be implemented in any suitable manner, such as using limiters, amplifiers, and other similar components. Processing block 444 receives the output from demodulator 442, performs operations such as command decoding, memory interfacing, and other related operations, and can generate output signals for transmission. Processing block 444 can be implemented in any suitable manner, such as by a combination of one or more of a processor, memory, decoder, encoder, and other similar components. Memory 450 stores data 452 and can be implemented at least in part as a permanent or semi-permanent memory, such as non-volatile memory (NVM), EEPROM, ROM, or other memory types configured to retain data 452 even when circuit 424 is without power. Processing block 444 can be configured to read data from and / or write data to memory 450.

[0049] Modulator 446 generates a modulated signal from the output signal generated by processing block 444. In one embodiment, modulator 446 generates the modulated signal by driving the load provided by the antenna segments coupled to IC contacts 432 / 433 to form a backscatter signal as described above. In another implementation, modulator 446 includes and / or uses a transmitter to generate a modulated signal and transmit the modulated signal via the antenna segments connected to IC contacts 432 / 433. Modulator 446 can be implemented in any suitable manner, such as using switches, drivers, amplifiers, and other similar components. Demodulator 442 and modulator 446 can be separate components, combined in a single transceiver circuit, and / or part of processing block 444.

[0050] In some embodiments, particularly those having more than one antenna port, circuit 424 can include multiple demodulators, rectifiers, PMUs, modulators, processing blocks, and / or memories.

[0051] Figure 5A is shown Figure 4Version 524 - A of the components of circuit 424, which is further modified to emphasize signal operation during the R→T interval (e.g., Figure 3 time interval 312). During the R→T interval, demodulator 442 demodulates the RF signal received from IC contacts 432 / 433. The demodulated signal is provided as C_IN to processing block 444, which in some embodiments may include the received symbol stream. Rectifier and PMU 441 may be active, e.g., obtaining power from the incident RF waveform and providing power to demodulator 442, processing block 444, and other circuit components. During the R→T interval, modulator 446 does not actively modulate the signal and may in fact be decoupled from the RF signal. For example, signal routing section 435 may be configured to decouple modulator 446 from the RF signal, or the impedance of modulator 446 may be adjusted to decouple it from the RF signal.

[0052] Figure 5B shows Figure 4 Version 524 - B of the components of circuit 424, which is further modified to emphasize signal operation during the T→R interval (e.g., Figure 3 time interval 326). During the T→R interval, processing block 444 outputs signal C_OUT, which may include a symbol stream for transmission. Then, modulator 446 generates a modulated signal from C_OUT and transmits the modulated signal via an antenna section coupled to IC contacts 432 / 433, as described above. During the T→R interval, rectifier and PMU 441 may be active while demodulator 442 may not actively demodulate the signal. In some embodiments, demodulator 442 may be decoupled from the RF signal during the T→R interval. For example, signal routing section 435 may be configured to decouple demodulator 442 from the RF signal, or the impedance of demodulator 442 may be adjusted to decouple it from the RF signal.

[0053] In typical embodiments, demodulator 442 and modulator 446 may be operable to demodulate and modulate signals according to a protocol (e.g., the Gen2 protocol mentioned above). In embodiments where circuit 424 includes multiple demodulators, modulators, and / or processing blocks, each demodulator, modulator, and / or processing block may be configured to support different protocols or different sets of protocols. The protocol partially specifies symbol encoding and may include a set of modulation, rate, timing, or any other parameters associated with data communication. The protocol may be a variant of an internationally approved protocol such as the Gen2 protocol, e.g., including fewer or more commands than the approved protocol, etc. In some instances, additional commands may sometimes be referred to as custom commands.

[0054] Figure 6FIG. 600 shows an RFID reader system according to an embodiment. The reader system 600 is configured to communicate with RFID tags and optionally communicate with entities external to the reader system 600, such as service 632. The reader system 600 includes at least one reader module 602, which is configured to send signals to and receive signals from RFID tags. The reader system 600 also includes at least one local controller 612 and, in some embodiments, at least one remote controller 622. The controllers 612 and / or 622 are configured to control the operation of the reader module 602, process data received from RFID tags communicated via the reader module 602, communicate with external entities such as service 632, and otherwise control the operation of the reader system 600.

[0055] In some embodiments, the reader system 600 may include multiple reader modules, local controllers, and / or remote controllers. For example, the reader system 600 may include at least one additional reader module 610, at least one additional local controller 620, and / or at least one additional remote controller 630. A single reader module may communicate with multiple local and / or remote controllers, a single local controller may communicate with multiple reader modules and / or remote controllers, and a single remote controller may communicate with multiple reader modules and / or local controllers. Similarly, the reader system 600 may be configured to communicate with multiple external entities, such as other reader systems (not depicted) and multiple services (e.g., services 632 and 640).

[0056] The reader module 602 includes a modulator / encoder block 604, a demodulator / decoder block 606, and an interface block 608. The modulator / encoder block 604 may encode and modulate data for transmission to an RFID tag. The demodulator / decoder block 606 may demodulate and decode signals received from the RFID tag to recover data transmitted from the tag. Modulation, encoding, demodulation, and decoding may be performed according to a protocol or specification, such as the Gen2 protocol. The reader module 602 may use the interface block 608 to communicate with the local controller 612 and / or the remote controller 622, e.g., to exchange tag data, receive instructions or commands, or exchange other relevant information.

[0057] Reader module 602 and blocks 604 / 606 are coupled to one or more antennas and / or antenna drivers (not shown) for transmitting and receiving RF signals. In some embodiments, reader module 602 is coupled to multiple antennas and / or antenna drivers. In these embodiments, reader module 602 may transmit and / or receive RF signals on different antennas in any suitable scheme. For example, reader module 602 may switch between different antennas to transmit and receive RF signals, transmit on one antenna but receive on another, or transmit and / or receive on multiple antennas simultaneously. In some embodiments, reader module 602 may be coupled to one or more phased array or synthetic beam antennas, the beams of which may be generated and / or steered, for example, by reader module 602, local controller 612, and / or remote controller 622.

[0058] Modulator / encoder block 604 and / or demodulator / decoder block 606 may be configured to perform conversions between analog and digital signals. For example, modulator / encoder block 604 may convert the digital signals received via interface block 608 into analog signals for subsequent transmission, and demodulator / decoder block 606 may convert the received analog signals into digital signals for transmission via interface block 608.

[0059] Local controller 612 includes processor block 614, memory 616, and interface block 618. Remote controller 622 includes processor block 624, memory 626, and interface 628. Local controller 612 differs from remote controller 622 in that local controller 612 is collocated with or at least physically close to reader module 602, while remote controller 622 is not physically close to reader module 602.

[0060] Processor block 614 and / or 624 may be configured to provide different functions either individually or in combination. Such functions may include controlling other components such as memory, interface blocks, reader modules, etc.; communicating with other components such as reader module 602, other reader systems, services 632 / 640, etc.; data processing or algorithm processing such as encryption, decryption, authentication, etc.; or any other suitable functions. In some embodiments, processor block 614 / 624 may be configured to convert analog signals to digital signals or vice versa as described above with respect to blocks 604 / 606; processor block 614 / 624 may also be configured to perform any suitable analog signal processing or digital signal processing such as filtering, carrier cancellation, noise determination, etc.

[0061] The processor blocks 614 / 624 can be configured to provide functionality by executing instructions or applications that can be retrieved from a memory (e.g., memories 616 and / or 626) or received from some other entity. The processor blocks 614 / 624 can be implemented in any suitable manner. For example, the processor blocks 614 / 624 can be implemented using: digital and / or analog processors such as microprocessors and digital signal processors (DSPs); controllers such as microcontrollers; software running on a machine such as a general-purpose computer; programmable circuits such as field-programmable gate arrays (FPGAs), field-programmable analog arrays (FPAA), programmable logic devices (PLDs), application-specific integrated circuits (ASICs), any combination of one or more of these; and equivalents.

[0062] The memories 616 / 626 are configured to store information and can be implemented in any suitable manner, such as the memory types described above, any combination thereof, or any other known memory or information storage technology. The memories 616 / 626 can be implemented as part of their associated processor blocks (e.g., processor blocks 614 / 624) or separately. The memories 616 / 626 can store instructions, programs, or applications for execution by the processor blocks 614 / 624. The memories 616 / 626 can also store other data, such as files, media, component configurations, or settings, etc.

[0063] In some embodiments, the memories 616 / 626 store tag data. The tag data can be data read from a tag, data to be written to a tag, and / or data associated with a tag or a tagged item. The tag data can include an identifier for the tag, such as an Electronic Product Code (EPC), a Tag Identifier (TID), or any other information suitable for identifying individual tags. The tag data can also include a tag password, a tag profile, a tag key (secret or public), a tag key generation algorithm, and any other suitable information about the tag or the item associated with the tag.

[0064] The memories 616 / 626 can also store information on how the reader system 600 will operate. For example, the memories 616 / 626 can store information such as algorithms for encoding commands to tags, algorithms for decoding signals from tags, communication and antenna operation modes, encryption / authentication algorithms, tag location and tracking algorithms, keys and key pairs associated with the reader system 600 and / or other entities (such as public / private key pairs), electronic signatures, and the like.

[0065] Interface blocks 608, 618, and 628 are configured to communicate with each other and with other appropriately configured interfaces. Communication between the interface blocks occurs via the exchange of signals that contain data, instructions, commands, or any other suitable information. For example, interface block 608 may receive data to be written to the tag, information about the operation of reader module 602 and its components, and the like; and may send data read from the tag. Interface blocks 618 and 628 may send and receive tag data, information about the operation of other components, other information for enabling local controller 612 and remote controller 622 to operate in coordination, and the like. Interface blocks 608 / 618 / 628 may also communicate with external entities such as services 632, 640, other services, and / or other reader systems.

[0066] Interface blocks 608 / 618 / 628 may communicate using any suitable wired or wireless means. For example, interface blocks 608 / 618 / 628 may communicate via circuit traces or interconnections, or other physical lines or cables, and / or using any suitable wireless signal propagation technology. In some embodiments, interface blocks 608 / 618 / 628 may communicate via an electronic communication network, such as a local area network (LAN), a metropolitan area network (MAN), a wide area network (WAN), a network such as the Internet. Communication from interface blocks 608 / 618 / 628 may be security protected, such as via encryption and other electronic means, or may be unprotected.

[0067] Reader system 600 may be implemented in any suitable manner. One or more components in reader system 600 may be implemented as integrated circuits using CMOS technology, BJT technology, MESFET technology, and / or any other suitable physical implementation technology. The components may also be implemented as software executed on general-purpose or special-purpose hardware.

[0068] In one embodiment, as used in this disclosure, a "reader" may include at least one reader module similar to reader module 602 and at least one local controller such as local controller 612. Such a reader may or may not include any remote controllers such as remote controller 622. A reader that includes a reader module and a local controller may be implemented as a stand-alone device or as a component in another device. In some embodiments, the reader may be implemented as a mobile device, such as a handheld reader, or as a component in a mobile device such as a laptop computer, a tablet computer, a smart phone, a wearable device, or any other suitable mobile device.

[0069] If not included in the reader, the remote controller 622 can be implemented separately. For example, the remote controller 622 can be implemented as a local host, a remote server, or a database coupled to one or more readers via one or more communication networks. In some embodiments, the remote controller 622 can be implemented as an application executing on the cloud or at a data center.

[0070] The functions within the reader system 600 can be distributed in any suitable manner. For example, the encoding and / or decoding functions of blocks 604 and 606 can be performed by processor blocks 614 and / or 624. In some embodiments, processor blocks 614 and 624 can cooperate to execute an application or perform some functions. One of the local controller 612 and the remote controller 622 may not implement a memory, while the other controller provides the memory.

[0071] The reader system 600 can communicate with at least one service 632. The service 632 provides one or more features, functions, and / or capabilities associated with one or more entities such as reader systems, tags, tagged items, and the like. Such features, functions, and / or capabilities can include providing information associated with the entity, such as warranty information, repair / replacement information, upgrade / update information, and the like; and providing services associated with the entity, such as storing and / or accessing entity-related data, location tracking of the entity, entity security services (e.g., authentication of the entity), entity privacy services (e.g., allowing who accesses what information about the entity), and the like. The service 632 can be separate from the reader system 600, and the two can communicate via one or more networks.

[0072] In some embodiments, the RFID reader or reader system implements the above functions and features at least partially in the form of firmware, software, or a combination, such as hardware or device drivers, operating systems, applications, etc. In some embodiments, an interface to various firmware and / or software components can be provided. Such an interface can include an application programming interface (API), a library, a user interface (graphical and others), or any other suitable interface. The firmware, software, and / or interface can be implemented via one or more processor blocks, such as processor blocks 614 / 624. In some embodiments, at least some of the reader or reader system functions and features can be provided as a service, for example, via service 632 or service 640.

[0073] Typically, an RFID tag IC has or stores one or more identifiers, which, as described above, are sequences of digits or bits that identify the tag IC or the associated item. The identifier may contain information about the tag IC or the item (such as a TID or an EPC), or may be used to look up information about the tag IC or the item. The tag IC identifier may uniquely identify (at least within the limits of a limited-length identifier) or be used to uniquely identify the tag IC or the associated item.

[0074] In some communication protocols, such as the Gen2 protocol, an RFID tag IC will send its identifier to a requesting reader without having previously received correct authentication information or the authenticating reader being authorized to receive information from the tag IC. For example, any reader may send a Gen2 query command such that all RFID tag ICs matching the flags specified in the command queue up and ultimately respond with their identifiers.

[0075] While the above feature is useful from the perspective of ensuring that all RFID tag ICs can be detected, it may be problematic for those who may want to keep their RFID tag ICs anonymous from a privacy perspective. One way to address this issue is to enable the RFID tag IC to have a privacy mode. When the RFID tag IC is in privacy mode, without the associated correct authentication information, it may not respond to an inventory command from an unauthenticated reader, or may respond with only limited information. For example, as described in more detail below, an RFID tag IC enabled with a recycling privacy mode may respond with recycling information of the tag IC or the associated item, but not with other identifying information.

[0076] Figure 7 Depicts how an RFID reader and tag IC operate in normal and privacy modes according to an embodiment. Figure 7 Describes RFID reader 702 and RFID tag ICs 704 and 706 in several different operating modes. Each of the tag ICs 704 and 706 has an identifier (labeled "ID1" and "ID2" respectively), a privacy indicator denoted as "P", and a secret (labeled "PIN1" and "PIN2" respectively).

[0077] The privacy indicator of the tag IC indicates whether the tag IC is in a privacy mode. For example, if the privacy indicator is implemented as a flag or a stored bit, it can be asserted or have a value of "1" if the tag IC is in the privacy mode, and it can be deasserted or have a value of "0" if the tag IC is not in the privacy mode. In some embodiments, multiple memory bits may be used to implement the privacy indicator. In these embodiments, the privacy indicator may be capable of having different values corresponding to different privacy modes. The privacy indicator of the tag IC may be publicly accessible in certain cases (e.g., after the tag IC has received correct authentication information, as described below), or it may be fully private and only readable by the tag IC itself. In some embodiments, the tag IC may use some means other than the privacy indicator to determine whether it is in the privacy mode.

[0078] Each tag IC has a secret that is preferably known only to the tag IC and an authorized entity. The secret can be a password, a personal identification number (PIN), a key, or any other suitable information. The tag IC can determine whether to respond to a reader command based on whether the reader command indicates knowledge of the secret of the tag IC. If the reader command indicates knowledge of the secret of the tag IC, for example, by including the secret or something derived from the secret, the tag IC can determine that the reader command includes the correct authentication information and that the reader sending the command is authenticated. Then, the tag IC can respond to subsequent reader commands.

[0079] Figure 7 In "700", the tag ICs 704 and 706 operating in the normal mode are described. When the reader 702 sends an inventory command (e.g., a query of the Gen2 protocol) requesting the tag IC identifier, the tag ICs 704 and 706 respond with their identifiers regardless of whether the reader 702 has previously authenticated itself to the tag IC by sending the correct authentication information. Specifically, the tag IC 704 responds with "ID1", and the tag IC 706 responds with "ID2".

[0080] Figure 7 In "710", the tag ICs 704 and 706 operating in the privacy mode are described. In Figure 7 In "710", the reader 702 does not send any authentication information before sending an inventory command requesting the tag IC identifier. In this case, the tag ICs 704 and 706 do not consider whether the reader 702 is authenticated and thus do not respond to subsequent commands from the reader 702. Therefore, the reader 702 may not detect the presence of the tag ICs 704 and 706 at all, let alone retrieve the tag IC identification information.

[0081] Figure 7The "720" again describes the tag ICs 704 and 706 operating in the privacy mode. Contrary to the situation in Figure 7 "710", here, the reader 702 first sends the correct authentication information before sending an inventory command requesting the tag IC identifier. Specifically, the reader 702 sends the authentication information by sending a select command specifying the secret (PIN1) of the tag IC 707. A select command is a command that does not initiate an inventory cycle but provides information on how the tag IC should participate and / or behave during the inventory cycle. For example, Gen2 Select and Challenge commands are examples of select commands. When the tag IC 704 determines that the received authentication information corresponds to its secret, it determines that the reader 702 has been authenticated and responds to the inventory command from the reader 702 with its identifier ID1. However, the tag IC 706 does not determine that the reader 702 has been authenticated or respond with its identifier because the authentication information sent by the reader 702 does not correspond to its secret.

[0082] Although in Figure 7 "720", the reader 702 sends the authentication information in the select command, in other embodiments, the reader may send the authentication information in other commands. For example, the reader may send the authentication information in the inventory command. The authentication information may be divided among multiple commands; for example, the reader may send the first part of the authentication information in the select command, the second part of the authentication information in the inventory command, or multiple parts in separate inventory commands.

[0083] Figure 8 FIG. shows a partial state diagram of an RFID tag IC capable of operating in the privacy mode according to an embodiment. At step 802, when the RFID tag IC is powered on, for example, when entering the state of an RFID reader providing power or after resetting the tag IC controller, the tag IC controller (or processing block) uses its privacy indicator ("P") to determine whether the tag IC is in the privacy mode. If the controller determines that the tag IC is in the privacy mode (e.g., P = 1), the controller causes the tag IC to transition to the hidden initialization state 804. If the controller determines that the tag IC is not in the privacy mode (e.g., P = 0), the controller causes the tag IC to transition to the protocol initialization state 806 described in the communication protocol. In some embodiments, the protocol initialization state 806 may be the ready state of the Gen2 protocol.

[0084] When the tag IC is in the hidden initialization state 804, it does not respond to any commands from the reader (and thus is "hidden"), unless the command contains the correct authentication information and / or the reader is authenticated, as described above. In the partial state diagram, the tag IC in the hidden initialization state 804 remains in state 804 unless it receives a command (in this example, a select command) that includes the correct authentication information (in this example, a PIN known to the tag IC). When a select command including the correct PIN is received, the tag IC controller causes the tag IC to transition to the protocol initialization state 806. In other embodiments, any other means of authenticating the reader or reader command as described above can cause the tag IC to transition to the protocol initialization state 806.

[0085] Upon reaching the protocol initialization state 806, the tag IC is now not temporarily hidden and can operate, respond, and transition to other protocol states 808 as described in the corresponding protocol (e.g., the Gen2 protocol), with certain exceptions described below. Specifically, when the tag IC is in the protocol initialization state 806 or other protocol states 808 and is thus not hidden, the tag IC can behave and respond as described in the corresponding protocol, unless the tag IC receives a select command or a mismatched inventory command, or some other event that causes the tag IC to revert to being hidden. The select command is as described above. A mismatched inventory command is an inventory command that does not specify the tag IC and thus initiates or continues an inventory cycle in which the tag IC does not participate. For example, a mismatched Gen2 inventory command can be a query command for which the values specified for Sel (Select) and Target (Target) do not match the corresponding values of the tag IC. In these cases, the tag IC can behave differently.

[0086] When not hidden and in protocol state 806 or 808, if the tag IC receives a mismatched inventory command, the tag IC controller determines whether the tag IC is in privacy mode (e.g., whether P is 0 or 1). If the controller determines that the tag IC is in privacy mode, the controller causes the tag IC to transition to the hidden initialization state 804. If the controller determines that the tag IC is not in privacy mode, the controller causes the tag IC to transition to (or remain in) the protocol initialization state 806.

[0087] When in protocol states 806 or 808, if the tag IC receives a select command, the tag IC controller determines whether the tag IC has recently transitioned to the privacy mode. If the privacy indicator P was 0 when the tag IC was last in the powered-on state 802 but is currently 1, the controller may determine that the tag IC has recently transitioned to the privacy mode. In other embodiments, if the duration between when P was 0 last time and the current time (when P is 1) is below a specific threshold, the controller may determine whether the tag IC has recently transitioned. If the controller determines that the tag IC has recently transitioned to the privacy mode, the controller causes the tag IC to transition to the hidden initialization state 804. If the controller determines that the tag IC has not recently transitioned to the privacy mode (e.g., if the privacy indicator P (a) is currently 0 or (b) is currently 1 and the tag IC was 1 the last time it was in state 802), the controller causes the tag IC to transition to the protocol initialization state 806.

[0088] Other events may also cause the tag IC to resume being hidden from a temporarily unhidden state. For example, if the tag IC loses power and then regains power, the tag IC may enter the powered-on state 802, and if its privacy indicator P is currently 1, it may then transition to the hidden initialization state 804. In some embodiments, the tag IC may remain temporarily unhidden for only a certain duration before becoming hidden. The duration may be measured from the last time the tag IC became temporarily unhidden (e.g., upon receiving correct authentication information), from the last time the tag IC received a command, from the last time the tag IC detected any command, or from any other appropriate event (e.g., via a counter).

[0089] In some embodiments, the tag IC may not resume being hidden even when receiving a mismatched inventory command, or when receiving a select command after recently transitioning to the privacy mode, but may resume in some other events. For example, a tag IC that is temporarily unhidden may remain unhidden until the duration measured (e.g., via a counter) from an event (such as those described above) expires, until power-off, or upon receiving a command indicating that the tag IC should resume being hidden.

[0090] The reader can cause the tag IC to transition to and from the privacy mode when correct authentication information is provided. For example, when the tag IC has a privacy indication value of 0 and thus is not in the privacy mode, the reader can cause the tag IC to change its privacy indication value from 0 to 1 after providing the correct authentication information, and thus transition to the privacy mode. In one particular embodiment, the reader can provide the correct access password to the tag IC, as described in the Gen2 protocol, to enable the reader to write a "1" value to the privacy indicator of the tag IC. As another example, when the tag IC has a privacy indicator value of 1 and thus is in the privacy mode, the reader can first cause the tag IC to participate in an inventory cycle by sending a select command with the correct authentication information. When communicating with the tag IC during the inventory cycle, the reader can then cause the tag IC to change its privacy indication value from 1 to 0, and thus transition out of the privacy mode. In some embodiments, the reader may have to provide additional correct authentication information to cause the tag IC to change its privacy indicator value to 0. The additional correct authentication information can be the same information provided in the select command, or it can be different information (e.g., another password or string known to the tag IC). In one embodiment, the reader can provide the access password as the authentication information to cause the tag IC to become temporarily unhidden, and then provide the access password again to cause the tag IC to change its privacy indication value.

[0091] In addition to causing the tag IC to transition to and from the privacy mode, a reader that provides correct authentication information is also able to update the authentication information stored on or known to the tag IC. For example, the reader can add, delete, or change the authentication information stored on the tag IC. The reader can also change the storage location on the tag IC where the authentication information is stored.

[0092] If the tag IC receives a command with incorrect authentication information, it can enter a timeout during which the tag IC does not respond to reader commands, even commands accompanied by or followed by correct authentication information. In some embodiments, if the command specifies a memory location where authentication information is stored, but the authentication information included in the command does not correspond to the stored authentication information, or if the specified memory location is incorrect, the tag IC determines that the command includes incorrect authentication information. The timeout can be based on a duration (e.g., the timeout can expire after a specific duration) or a command rate (e.g., the timeout can expire after receiving a specific number of other commands without authentication information).

[0093] Figure 9 Depicts how an RFID reader and tag IC operate in normal mode, privacy mode, and enabled-recovery privacy mode according to an embodiment. Figure 9Shows RFID reader 902 and RFID tag ICs 904 and 906 in several different operating modes. Each of ICs 904 and 906 has an identifier (labeled "ID1" and "ID2" respectively), a "recycling indicator" denoted as "R", and recycling information. The recycling indicator shows whether the tag IC is configured to respond with its recycling information when in the privacy mode. For example, if the tag IC is configured to respond with its recycling information when in the privacy mode, the recycling indicator can be "1", and if the tag IC is not configured to respond with its recycling information when in the privacy mode, the recycling indicator can be "0". In some embodiments, another indicator on the tag IC can also be used as the recycling indicator. For example, the tag IC can have a mode indicator that identifies whether the tag IC is in the normal mode or the privacy mode (e.g., the privacy indicator as described above). This mode indicator can also be configured to identify whether the tag IC is in the enabled recycling privacy mode. As another example, the tag IC can have a "non-removable" indicator or bit that indicates whether the tag IC is configured to be removed from its associated item, such as the NR bit described in the Gen2 protocol. For example, as described above, a tag IC integrated into an item can be considered "non-removable", and accordingly its non-removable indicator is asserted or de-asserted. The non-removable indicator can also be used to indicate whether the tag IC responds with its recycling information when in the privacy mode.

[0094] The recycling information of the tag IC describes how the tag IC and / or its associated item can be recycled or processed. The recycling information can include the item or tag components, precautions taken during recycling or disposal, and any other information required for safe recycling or disposal. For example, tag IC 904 can store recycling information indicating that it or its associated item is "paper", while tag IC 906 can store recycling information indicating that it or its associated item is "cotton". In some embodiments, the recycling information stored on the tag IC can indicate where additional recycling or processing information can be found. For example, the stored recycling information can include an address or a link (e.g., a Uniform Resource Locator, etc.) to a network location or service (e.g., service 632 or 640). Then, the user can obtain additional recycling / processing information for the item from the specified network location or service.

[0095] In some embodiments, the tag IC can be configured to allow its owner to decide whether to enable the recycling privacy mode. For example, the tag IC owner may not want the tag IC to respond to an unauthenticated / unauthorized reader under any circumstances, even for processing purposes. In this case, even if the tag IC receives a selection or other command specifying the recycling indicator of the tag IC, it will not participate in the inventory. This allows the tag IC owner to exert more control over how the tag IC responds (or does not respond).

[0096] Figure 9 The "900" therein describes the tag ICs 904 and 906 operating in the normal mode, similar to the Figure 7 "700" above. When the reader 902 sends an inventory command to request the tag IC identifier (e.g., a query of the Gen2 protocol), the tag ICs 904 and 906 respond with their identifiers regardless of whether the reader 902 is authenticated or correct authentication information was previously provided. Specifically, the tag IC 904 responds with "ID1" and the tag IC 906 responds with "ID2".

[0097] Figure 9 The "910" therein shows the tag ICs 904 and 906 operating in the privacy mode, similar to the Figure 7 "710" above. In this case, if the reader 902 sends an inventory command requesting the tag IC identifier, the tag ICs 904 and 906 do not respond if the reader 902 did not previously provide correct authentication information. Thus, the reader 902 may not be able to detect the presence of the tag ICs 904 and 906 at all, let alone retrieve the tag IC identification information. On the other hand, if the reader 902 did previously provide correct authentication information, the tag ICs will respond with their respective identifiers.

[0098] Figure 9 The "920" therein describes the tag ICs 904 and 906 operating in the enabled recycling privacy mode. In this case, the tag ICs 904 and 906 are in the privacy mode and will not respond to the reader 902 with their respective identifiers unless the reader 902 has previously provided correct authentication information. However, if the reader 902 first transmits a select command specifying a particular value of the recycling indicator R and then transmits an inventory command requesting the tag IC identifier, the tag ICs in the enabled recycling privacy mode having a matching R value can respond with their recycling information regardless of whether correct authentication information was provided. For example, assume the reader 902 sends a select command specifying an R value of "1" and then sends an inventory command requesting the identifier. The tag IC 904 has an R value of "0" and thus will not respond to the inventory command. On the other hand, the tag IC 906 has an R value of "1" and thus will respond to the inventory command with its recycling information ("cotton") but will not respond with other identification information.

[0099] The tag IC can be configured to send its recycling information at any appropriate point during the inventory process. Figure 10 Shows the interaction between an RFID reader and a tag IC in the enabled recycling privacy mode according to an embodiment. Figure 10Shows an RFID reader 1002 and an RFID tag IC 1004. The tag IC 1004 has an identifier ID1, a recovery indicator R that asserts (= "1"), and recovery information "cotton". In Figure 10 "1000", the reader 1002 first sends a select command specifying the asserted recovery indicator (e.g., a select command according to the Gen2 protocol), and then sends a query command to initiate an inventory cycle (e.g., a query command according to the Gen2 protocol). When the tag IC 1004 responds, it responds with a pseudo-random number RN. Then, the reader 1002 sends an acknowledge command with RN (e.g., an ACK command according to the Gen2 protocol). Then, the tag IC 1004 responds to the acknowledge command with its recovery information.

[0100] Figure 10 "1050" describes an alternative inventory process related to the tag IC recovery information. In Figure 10 "1050", the reader 1002 also first sends a select command specifying the asserted recovery indicator, and then sends a query command to initiate an inventory cycle. However, instead of responding with a pseudo-random number, the tag IC 1004 responds with its recovery information. This behavior accelerates the overall inventory process by removing the pseudo-random number exchange.

[0101] Although in the above the reader extracts the recovery information from the tag IC by first sending a select command specifying the R value and then sending an inventory command, in other embodiments, the reader can extract the recovery information in any suitable manner. For example, the reader can send an inventory command specifying the R value, and tag ICs having a matching R value can respond with their recovery information regardless of whether the correct authentication information is provided.

[0102] A select command that contains both the correct authentication information and specifies the asserted recovery indicator can cause one of several tag behaviors. For example, such a select command can cause tag ICs that are in privacy mode and also have the asserted recovery indicator to participate in subsequent inventory cycles by responding with their identifiers. Such a select command can also cause tag ICs that are in privacy mode and also have the asserted recovery indicator to participate in subsequent inventory cycles by responding with their identifiers and their recovery information in a certain specific format (e.g., concatenated with their identifiers, concatenated with another response, or as a completely independent response).

[0103] An RFID tag IC configured with a recycling privacy mode enabled may have a partial state diagram similar to but different from the partial state diagram. For example, such a tag IC may be configured to transition from a hidden initialization state (e.g., state 804) to a protocol initialization state (e.g., state 806) upon receiving a selection command that either contains correct authentication information or specifies a recycling indicator value. If the tag IC transitions from the hidden initialization state to the protocol initialization state due to the specification of the recycling indicator value rather than due to receiving correct authentication information, the tag IC may operate according to the protocol but does not provide access to information other than recycling information. For example, the tag IC may respond only with its recycling information, rather than with a random number, identifier, or other requested information. The tag IC may also ignore certain protocol commands, such as those related to memory access or commands that allow access to other tag IC features in addition. In this case, although the tag IC is configured to respond with recycling information, it can still be considered that the tag IC is in a "hidden" state because it does not provide access to other identification information.

[0104] Figure 11 is a diagram of an example RFID tag IC memory configuration according to an embodiment. Figure 11 1 shows an RFID tag IC memory 1150, similar to the physical memory configuration described in the Gen2 protocol. The memory 1150 includes four partitions or sections 1152, 1154, 1156, and 1158. Partition 1152 ("user memory") can be configured to store user data. Partition 1154 ("TID memory") can be configured to store an identifier of the tag IC itself, such as a tag identifier or TID. Partition 1156 ("EPC memory") can be configured to store an identifier of an item associated with or attached to the tag IC, such as an electronic product code or EPC. Partition 1158 ("reserved memory") can be configured to store information that is reserved for the tag IC itself, or information that is not necessarily publicly accessible otherwise, such as passwords, PINs, encryption keys, and the like. The Gen2 protocol specifies two passwords, an access password and a kill password, that can be stored in partition 1158. If an access password is present, it can be used to restrict certain tag IC operations, as described in the Gen2 protocol. If a kill password exists, it can be used to put the tag IC into a kill state as described in Gen2 Proto Col. Because these passwords are sensitive, partition 1158 is generally not publicly accessible.

[0105] The configuration of tag IC memory 1150 is provided as an example. The tag IC memory may have any number of partitions configured to store any suitable information.

[0106] As described above, an RFID tag IC capable of enabling a recycling privacy mode can implement a recycling indicator and store recycling information. The recycling indicator can be implemented as a flag structure similar to the flags described in the Gen2 protocol, or as one or more bits in the tag IC memory, such as the NR bit described in the Gen2 protocol. The RFID tag IC can store the recycling information in user memory, reserved memory, TID memory, EPC memory, and / or any other suitable memory location. In some embodiments, the tag or item identifier can include recycling information. For example, one or more bits of the EPC can indicate the composition of the associated item.

[0107] In some embodiments, the authentication information can be stored in partition 1158 or elsewhere in memory 1150. For example, memory 1150 can store a first string or bit sequence in a first memory location. If the received command (e.g., a select command) specifies the first string or bit sequence and specifies or addresses the first memory location, the tag IC can determine that the command includes the correct authentication information. As another example, if the received command includes a known string or bit sequence correctly encrypted with a key known to the tag IC, with or without specifying or addressing a memory location, the tag IC can determine that the command includes the correct authentication information. The data in memory 1150 can be stored, updated, and / or erased during tag IC manufacture or during tag IC operation, e.g., in response to a reader command.

[0108] For memory economy reasons, the authentication information can be a pre-existing password (e.g., an access password), or can be a completely independent string or password. To enable both, the authentication information sent from the reader can specify or address a static memory location that the receiving tag IC can map, point to, or redirect to different actual memory locations. For example, assume the tag IC receives authentication information that specifies a particular memory location and a string or bit sequence that matches the information stored in that particular memory location. Further assume that the authentication information can either be an authentication string stored in a particular memory location (e.g., the start of partition 1152) or an access password (stored in partition 1158). The particular storage location can be publicly accessible, but partition 1158 and its contents (e.g., the access password) can be hidden or private to the tag IC. In other words, a reader command can specify and access the information at a particular memory location, but cannot specify or access locations in the hidden / private partition 1158, or will fail if it attempts to do so.

[0109] In some embodiments, the tag IC may be configured to map a first memory location that is publicly accessible (e.g., the above - mentioned specific memory location) to a hidden or private memory location (e.g., a location in partition 1158). For example, the tag IC may be configured to map the first memory location either to itself (i.e., the specific memory location) or to a hidden access password location. If the tag IC has a verification string stored in the first memory location, the tag IC may map the first memory location to itself. If the tag IC does not have a separate verification string, the tag IC may map the first memory location to the access password location. This dynamic mapping allows the received verification information to specify a static memory location (e.g., the first memory location), while the tag IC has the flexibility to store the verification information in other memory locations, even in hidden or private memory locations (e.g., either the first memory location or the hidden access password location).

[0110] In one embodiment, the verification information may be one or more specific memory locations on the tag IC, independent of the information actually stored in those memory locations. In this case, the specific memory locations serve as the tag IC's secret. Upon receiving a command, the tag IC determines whether the command indicates those specific memory locations. If so, the IC concludes that the command includes the correct verification information.

[0111] In one embodiment, the verification information may be a string or value that has been encrypted with a key known to the tag IC. In this case, the key is never sent in the reader command or the tag IC response. Instead, the tag IC receives an encrypted version of a known value from the reader. Then, the tag IC uses its known key to determine whether the processed version corresponds to the known value. For example, the tag IC may recover a sequence from the version and compare the recovered sequence with the known value, or the tag IC may encrypt the known value to form a test version and compare the test version with the known value. If the recovered or test version corresponds to the known value, the tag IC concludes that the reader knows the key and thus has provided the correct verification information. The tag IC may be configured to pre - compute or pre - process the known value to form and store the test version, so that the tag IC does not have to perform the computation or processing in real - time during communication.

[0112] In an exemplary implementation, the reader sends a select command that includes a first multi-bit sequence (e.g., a random or pseudo-random number) and a version of the first sequence that has been encrypted using a key known to the tag IC. When the tag IC receives the select command, it uses its key to determine whether the encrypted version included in the select command corresponds to the first sequence. For example, the tag IC can process the first sequence using the key and compare the processed sequence with the received version, or the tag IC can use the key to reverse the processing of the received version and compare the result with the received first sequence. If the two compared sequences correspond, the tag IC can participate in subsequent inventory cycles in a limited manner. For example, in subsequent inventory cycles, the tag IC can respond to an inventory command from the reader with a second multi-bit sequence (e.g., another random or pseudo-random number). The reader then generates an encrypted version of the second sequence using the key and sends an acknowledgment command (e.g., Gen2 ACK) that includes the version of the second sequence. When the acknowledgment command is received, the tag IC again uses its key to determine whether the received version of the second sequence corresponds to the second sequence, similar to the comparison involving the first sequence described above. In some embodiments, the tag IC can pre-compute the correctly encrypted version of the second sequence to compare with the version received from the reader to avoid having to perform the computation after receiving the reader's version. If the two compared sequences correspond, the tag IC can respond with one or more identifiers and effectively become unhidden. Otherwise, the tag IC determines that it has not received the correct authentication information and can exit the inventory cycle and return to a hidden state (e.g., the hidden initialization state 804). In some embodiments, if either comparison fails, the tag IC can set a pause during which the tag IC does not respond to the reader (or any reader), even if the reader subsequently sends the correct authentication information. Although two consecutive comparisons are described above, in some embodiments, the tag IC may need to make more than two successful comparisons before becoming unhidden. This can provide additional security at the cost of the inventory speed.

[0113] Figure 12 Process 1200 for an RFID tag IC in privacy mode responding to an inventory command according to an embodiment is depicted. Process 1200 begins at step 1202, where the tag IC receives an inventory command from the reader. At step 1204, the controller (or processing block) of the tag IC determines whether the tag IC is currently in privacy mode. For example, the tag IC can determine whether it has a privacy indicator with a specific value. If the tag IC is not in privacy mode, then at step 1206, the controller causes the tag IC to respond with one or more identifiers, such as a pseudo-random or random number, TID, EPC, or similar identifier.

[0114] If the tag IC is in privacy mode, at step 1208, the controller determines whether an inventory command has been verified. For example, if the inventory command is accompanied by correct verification information, a previous command containing correct verification information is received, and / or if the reader that sent the inventory command was previously verified (e.g., previously provided correct verification information), the controller may determine that the inventory command has been verified. In some embodiments, the tag IC determines that the received verification information is correct if (a) the verification information specifies both a memory location and a string or bit sequence that matches the string or bit sequence stored at the specified memory location on the tag IC, (b) the verification information specifies a known memory location on the tag IC, or (c) the verification information matches a string or bit sequence known to the tag IC when tag IC key encryption processing (e.g., encryption or decryption) is used. If at step 1208 the controller determines that the inventory command has been verified, the controller may cause the tag IC to become unhidden and respond at step 1206 with one or more identifiers. In some embodiments, the tag IC may also respond to the verified inventory command with its recycling information, as described above. After a certain time or event (e.g., power-off and subsequent power-on)

[0115] If at step 1208 the controller determines that the inventory command has not been verified, the controller may cause the tag IC to remain hidden and ignore the inventory command at step 1214, e.g., by not responding with any tag IC information. If the tag IC supports enabling the recycling privacy mode, the controller may determine at an optional step 1210 whether the recycling indicator of the tag IC has been correctly selected. For example, if the correct recycling indicator location (e.g., if the recycling indicator is located at a certain location in the tag IC memory) and value are specified by the inventory command or a previous selection command, the controller may determine that the recycling indicator has been correctly selected. If the controller determines that the recycling indicator has been correctly selected, at an optional step 1212, the controller may cause the tag IC to become partially unhidden and respond with recycling information. If at the optional step 1212 the controller determines that the recycling indicator has not been correctly selected, or if the tag IC does not support enabling the recycling privacy mode, at step 1214, the controller may cause the tag IC to remain hidden and ignore the inventory command.

[0116] In the above description, the RFID tag IC is configured to respond to a single inventory command with different information according to a previous selection command. For example, the above RFID tag IC in the enabled recycling privacy mode that receives an inventory command will depend on the previous selection command and (a) respond with the tag IC or item identifier and optionally recycling information if the selection command includes the correct verification information, (b) respond only with recycling information if the selection command correctly specifies a recycling indicator, or (c) not respond. This concept is not limited to the tag IC / item identifier and recycling information. For example, the RFID tag IC can be configured to, according to a previous selection command, (a) respond with different parts of the tag IC or item identifier, (b) respond with different combinations of the tag IC or item identifier, (c) respond with different information stored in the tag IC memory, or (c) otherwise make other different responses or behaviors.

[0117] The steps described in process 1200 are for illustrative purposes only. These steps can be implemented in a different order using additional or fewer steps and using the principles described herein.

[0118] The RFID system can use the above in any number of ways. For example, a retailer with RFID-tagged items can keep all tags in a non-privacy mode in the store for easy inventory, tracking, and loss prevention. When a customer purchases an item, the associated tag can be placed in privacy mode based on a secret known to the retailer and / or the customer. Then, the customer can leave the retailer without triggering the retailer's electronic article surveillance (EAS) system because the EAS system will not even detect a tag in privacy mode. If the customer later wishes to return the item and the retailer knows the secret, the retailer can easily verify that the tag associated with the returned item is the original tag (assuming it is attached to the same item, especially if the tag is configured to be non-removable).

[0119] As another example, a person with multiple tagged items can place multiple associated tags in privacy mode based on a single secret, which can be referred to as a "group PIN" or "group key". Then, the person can use that single secret to track those tags, and others who do not have the secret will not even be able to detect those tags.

[0120] As another example, an RFID reader system can be configured to retrieve recycling information from tags in a privacy mode, even if the reader system is not configured to otherwise authenticate itself to tags in a privacy mode. For example, recycling and waste disposal facilities and / or vehicles can be equipped with such a reader system. In one embodiment, the reader system can send a selection command specifying a particular recycling indicator and / or particular recycling information at an appropriate time (e.g., periodically, upon the occurrence of an event such as receiving a load of waste materials, upon receiving a command, etc.). The reader system then sends an inventory command, receives recycling information from appropriately configured tags in a privacy mode, and performs an appropriate action based on the received recycling information. For example, if the reader system receives recycling information indicating that at least one current item has a material incompatible with the recycling or disposal process, the reader system can flag the entire load for further attention. As another example, the reader system can route the waste of the load to different destinations based on the distribution of the received recycling information.

[0121] As previously mentioned, embodiments are directed to RFID tag ICs having different privacy levels and modes. Embodiments additionally include programs and methods of operating the programs. Due to the nature and order of the elements in the steps, a program is generally defined as a set of steps or operations that result in a desired outcome. A program is typically advantageously implemented as a sequence of steps or operations of a processor, but can be implemented in other processing elements such as an FPGA, a DSP, or other devices as previously described.

[0122] Performing the steps, instructions, or operations of a program requires the manipulation of physical quantities. Generally, although not necessarily, these quantities can be transferred, combined, compared, and otherwise manipulated or processed according to the steps or instructions, and they can also be stored in a computer-readable medium. These quantities include, for example, electrical, magnetic, and electromagnetic charges or particles, states of matter, and, more generally, can include the state of any physical device or element. The information represented by the state of these quantities can be referred to as bits, data bits, samples, values, symbols, characters, items, numbers, etc. However, these and similar terms are each individually or collectively associated with appropriate physical quantities and are merely convenient labels applied to the appropriate physical quantities.

[0123] Embodiments also include a storage medium. Such a medium stores, alone or in combination with others, instructions, data, keys, signatures, and other data of a program made according to an embodiment. A storage medium according to an embodiment is a computer-readable medium, such as a memory, and can be read by a processor of the type described above. If it is a memory, it can be implemented in any manner and using any of the techniques described above.

[0124] Even if a program can be stored on a computer-readable medium, it need not be a single memory, or even a single machine. Its various parts, modules, or features can reside in separate memories, or even in separate machines. The separate machines can be directly connected, or connected via a network such as a local area network (LAN) or a global network such as the Internet.

[0125] Generally, for convenience only, it is desirable to implement and describe the program as software. The software can be single, or considered according to various interconnected different software modules.

[0126] According to some examples, a method is described for a radio frequency identification (RFID) integrated circuit (IC) in a hidden state to transition from the hidden state to a non-hidden state or remain in the hidden state and provide recycling information while in the hidden state. The method can include receiving a selection command; determining whether the selection command includes authentication information, a request for the recycling information, or both; in response to determining that the selection command includes authentication information, determining whether the authentication information is correct; in response to determining that the authentication information is correct, transitioning to the non-hidden state and responding to a subsequent inventory command with identification information; in response to determining that the selection command does not include authentication information but includes a request for the recycling information, remaining in the hidden state and responding to a subsequent inventory command with the recycling information instead of identification information; and in response to determining that the selection command does not include correct authentication information or a request for the recycling information, remaining in the hidden state and not responding to a subsequent inventory command.

[0127] According to other examples, the correct authentication information can include one or more of the following: a correct personal identification number (PIN), a correct password, and information correctly encrypted based on a key known to the IC. Determining whether the selection command includes a request for the recycling information can include determining whether the selection command specifies a non-removable bit of the IC, the non-removable bit indicating whether the IC can be removed from the associated item. The recycling information may not uniquely identify the IC and may indicate whether the item associated with the IC can be recycled; indicate the composition of the item; and / or indicate disposal information of the item. The recycling information can indicate where additional information about the item associated with the IC is located. The method can further include, in response to determining that the selection command contains both correct authentication information and a request for the recycling information, responding to a subsequent inventory command with one or more of the identification information and the recycling information. Responding to a subsequent inventory command with the recycling information can include responding to a subsequent inventory command with the recycling information instead of a random number.

[0128] According to a further example, a radio frequency identification (RFID) integrated circuit (IC) may include a memory configured to store identification information and recovery information; a transceiver configured to receive commands and send responses; and a processing block coupled to the memory and the transceiver. The processing block may be configured to receive a select command via the transceiver; determine whether the select command includes authentication information, a request for the recovery information, or both; in response to determining that the select command includes authentication information, determine whether the authentication information is correct; in response to determining that the authentication information is correct, transition to a non-hidden state and respond to subsequent inventory commands with the identification information; in response to determining that the select command does not include authentication information but includes a request for the recovery information, remain in the hidden state and respond to subsequent inventory commands with the recovery information instead of the identification information; and in response to determining that the select command does not include correct authentication information or a request for the recovery information, remain in the hidden state and not respond to subsequent inventory commands.

[0129] According to additional examples, correct authentication information may include one or more of the following: a personal identification number (PIN) in the memory, a password in the memory, and information correctly encrypted based on a key known to the IC. The IC may implement a non-removable bit indicating whether the IC can be removed from an associated item, and the select command may include a request for the recovery information by specifying the non-removable bit. The recovery information may not uniquely identify the IC and may indicate whether the item associated with the IC can be recycled; indicate the composition of the item; and / or indicate disposal information of the item. The recovery information may indicate where additional information about the item associated with the IC is located. The processing block may also be configured to, in response to determining that the select command contains both correct authentication information and a request for recovery information, respond to subsequent inventory commands with one or more of the identification information and the recovery information. The processing block may be configured to respond with the recovery information by responding to subsequent inventory commands with the recovery information instead of a random number.

[0130] According to some examples, a method is described for a radio frequency identification (RFID) integrated circuit (IC) in a hidden state to transition from the hidden state to a non-hidden state or remain in the hidden state and provide recycling information while in the hidden state. The method may include receiving a select command; determining whether the select command includes authentication information, a request for the recycling information, or both; in response to determining that the select command includes authentication information, determining whether the authentication information is correct; in response to determining that the authentication information is correct, transitioning to the non-hidden state and responding to subsequent inventory commands with identification information; in response to determining that the select command does not include authentication information but includes a request for the recycling information and the IC is configured to expose the recycling information, remaining in the hidden state and responding to the subsequent inventory commands with the recycling information instead of the identification information; and in response to determining that the select command does not include correct authentication information or a request for the recycling information, remaining in the hidden state and not responding to subsequent inventory commands.

[0131] According to other examples, correct authentication information may include one or more of the following: a correct personal identification number (PIN), a correct password, and information correctly encrypted based on a key known to the IC. Determining whether the select command includes a request for the recycling information may include determining whether the select command specifies a non-removable bit of the IC, the non-removable bit indicating whether the IC can be removed from an associated item. The recycling information may not uniquely identify the IC and may indicate whether an item associated with the IC can be recycled; indicate the composition of the item; and / or indicate disposal information of the item. The recycling information may indicate where additional information about the item associated with the IC is located. The method may further include, in response to determining that the select command includes both correct authentication information and a request for the recycling information, responding to subsequent inventory commands with one or more of the identification information and the recycling information. Responding to subsequent inventory commands with the recycling information may include responding to subsequent inventory commands with the recycling information instead of a random number.

[0132] According to an example, a method for an RFID IC is provided. The method may include, upon power-up, if the IC is in a privacy mode, transitioning to a hidden state in which the IC ignores an inventory command by avoiding responding with the IC identifier, or otherwise transitioning to a non-hidden state in which the IC responds to the inventory command with the IC identifier. The method further includes, if the IC is in the privacy mode and also in the hidden state, ignoring any inventory commands and temporarily transitioning from the hidden state to the non-hidden state upon receipt of correct authentication information. The authentication information may be provided in a select command. The method may further include, if the IC is in the privacy mode and also in the non-hidden state: responding with the IC identifier upon receipt of an inventory command specifying the IC, transitioning from the non-hidden state to the hidden state without responding with the IC identifier upon receipt of an inventory command not specifying the IC, transitioning if the IC has most recently entered the privacy mode upon receipt of a select command to transition from the non-hidden state to the hidden state, or otherwise remaining in the non-hidden state, and / or exiting the privacy mode upon receipt of the authentication information and an instruction to exit the privacy mode. The method may further include, if the IC is not in the privacy mode and also in the non-hidden state, responding with the IC identifier upon receipt of an inventory command specifying the IC, and / or entering the privacy mode upon receipt of the authentication information and an instruction to enter the privacy mode.

[0133] The foregoing detailed description has set forth various embodiments of the apparatus and / or processes by use of block diagrams and / or examples. In cases where such block diagrams and / or examples contain one or more functions and / or aspects, each function and / or aspect within such a block diagram or example can be implemented, individually and / or jointly, by a variety of hardware, software, firmware, or in fact any combination thereof. Some aspects of the embodiments disclosed herein may be implemented, in whole or in part, equivalently as an integrated circuit, as one or more computer programs running on one or more computers (e.g., as one or more programs running on one or more computer systems), as one or more programs running on one or more processors (e.g., as one or more programs running on one or more microprocessors), as firmware, or as in fact any combination thereof, and designing the circuitry and / or writing the code for the software and / or firmware would be within the skill of one of ordinary skill in the art in light of this disclosure.

[0134] The present disclosure should not be limited to the specific embodiments described in this application, which are intended to illustrate various aspects. Many modifications and variations can be made without departing from the spirit and scope of the invention. Functionally equivalent methods and devices within the scope of the present disclosure will be apparent to those skilled in the art from the foregoing description, in addition to those enumerated herein. These modifications and variations are intended to fall within the scope of the appended claims. The present disclosure is limited only by the terms of the appended claims and the full scope of equivalents to which those claims are entitled. It should be understood that the present disclosure is not limited to specific methods, configurations, tags, RFICs, readers, systems, etc., which can of course vary. It should also be understood that the terms used herein are for the purpose of describing particular embodiments only and are not intended to be limiting.

[0135] Regarding the use of substantially any plural and / or singular terms herein, those skilled in the art can convert the plural to singular and / or the singular to plural, according to context and / or the needs of the application. For clarity, various singular / plural permutations may be explicitly set forth herein.

[0136] Generally, the terms used herein, especially those used in the appended claims (e.g., the body of the appended claims), are generally intended to be "open-ended" terms (e.g., the term "comprising" should be interpreted as "comprising but not limited to", the term "having" should be interpreted as "having at least", the term "including" should be interpreted as "including but not limited to", etc.). If the intention is to claim a specific number of the introduced claim recitations, such intention will be explicitly recited in the claim, and in the absence of such recitation, there is no such intention. For example, for purposes of illustration, the appended claims may include the use of introductory phrases "at least one" and "one or more" to introduce claim recitations. However, the use of such phrases should not be construed as implying that a claim recitation introduced by the indefinite article "a" or "an" limits any particular claim containing such introduced claim recitation to an embodiment containing only one such recitation, even when the same claim includes the introductory phrases "one or more" or "at least one" as well as the indefinite article such as "a" or "an" (e.g., "a" and / or "an" should be interpreted to mean "at least one" or "one or more"); this applies equally to the use of a definite article to introduce a claim recitation. Additionally, even if a specific number of the introduced claim recitations is explicitly recited, such recitation should be interpreted to mean at least the recited number (e.g., the mere recitation of "two recitations" without other modifiers means at least two recitations, or two or more recitations).

[0137] In addition, in those cases where the convention is similar to "at least one of A, B, and C, etc.". "Generally, such a construction is intended in the sense that a person skilled in the art would understand the convention (e.g., "a system having at least one of A, B, and C" would include, but not be limited to, a system having only A, only B, only C, having A and B, having A and C, having B and C, and / or having A, B, and C, etc.). Whether in the specification, claims, or drawings, any separate word and / or phrase that represents two or more alternative terms should be understood as being intended to include the possibility of one of these terms, any one of these terms, or both. For example, the phrase "A or B" will be understood to include the possibility of "A" or "B" or "A and B".

[0138] For any and all purposes, such as for providing a written description, all ranges disclosed herein also cover any and all possible sub-ranges and combinations of their sub-ranges. Any listed range can be readily considered to be fully described and such that the same range can be broken down into at least equal halves, thirds, quarters, fifths, tenths, etc. By way of non-limiting example, each range discussed herein can be readily broken down into a lower third, a middle third, and an upper third, etc. All languages such as "up to", "at least", "greater than", "less than", etc. include the recited numbers and refer to ranges that can subsequently be broken down into sub-ranges as described above. Finally, a range includes each individual member. Thus, for example, a group having 1 - 3 units refers to a group having 1, 2, or 3 units. Similarly, a group having 1 - 5 units refers to a group having 1, 2, 3, 4, or 5 units, and so on.

Claims

1. A method for a radio frequency identification (RFID) integrated circuit (IC) in a hidden state to transition from the hidden state to a non-hidden state or remain in the hidden state and provide recovery information while in the hidden state, the method comprises: When the IC is in the hidden state: Receiving a selection command; Determining whether the selection command includes authentication information, a request for the recovery information, or both; In response to determining that the selection command includes authentication information, determining whether the authentication information is correct; In response to determining that the authentication information is correct, transitioning to the non-hidden state and responding to subsequent inventory commands with identification information; In response to determining that the selection command does not include authentication information but includes a request for the recovery information, remaining in the hidden state and responding to the subsequent inventory commands only with the recovery information rather than the identification information; And In response to determining that the selection command does not include correct authentication information or a request for the recovery information, remaining in the hidden state and thus ignoring the subsequent inventory commands.

2. The method according to claim 1, wherein the correct authentication information includes one or more of the following: A correct personal identification number (PIN), A correct password, and Information correctly encrypted based on a key known to the IC.

3. The method according to claim 1, wherein, Determining whether the selection command includes a request for recovery information includes determining whether the selection command specifies a non-removable bit of the IC, the non-removable bit indicating whether the IC can be removed from an associated item.

4. The method according to claim 1, wherein the recovery information does not uniquely identify the IC and indicates at least one of the following: Indicating whether an item associated with the IC can be recycled; Indicating the composition of the item; and Indicating the disposal information of the item.

5. The method according to claim 1, wherein the recovery information indicates where additional information about an item associated with the IC is located.

6. The method according to claim 1, further comprises: In response to determining that the selection command contains both correct authentication information and a request for the recovery information, responding to the subsequent inventory commands with one or more of the identification information and the recovery information.

7. The method according to claim 1, wherein, Responding to the subsequent inventory commands with the recovery information includes responding to the subsequent inventory commands with the recovery information instead of a random number.

8. A radio frequency identification (RFID) integrated circuit (IC), comprises: A memory configured to store identification information and recovery information; A transceiver configured to receive commands and send responses; And A processing block coupled to the memory and the transceiver and configured to: When the IC is in the hidden state: Receive a selection command via the transceiver; Determine whether the selection command includes authentication information, a request for the recovery information, or both; In response to determining that the selection command includes authentication information, determine whether the authentication information is correct; In response to determining that the authentication information is correct, transition to the non-hidden state, and respond to subsequent inventory commands with the identification information; in response to determining that the selection command does not include authentication information but includes a request for the recovery information, remain in the hidden state and respond to the subsequent inventory commands only with the recovery information rather than the identification information; and in response to determining that the selection command does not include correct authentication information or a request for the recovery information, remain in the hidden state and thus ignore the subsequent inventory commands.

9. The IC according to claim 8, wherein the correct authentication information comprises one or more of the following: a personal identification number (PIN) in the memory, a password in the memory, and information correctly encrypted based on a key known to the IC.

10. The IC according to claim 8, wherein: the IC implements a non-removable bit indicating whether the IC can be removed from an associated item, and the selection command includes a request for the recovery information by specifying the non-removable bit.

11. The IC according to claim 8, wherein the recovery information does not uniquely identify the IC and indicates at least one of the following: indicating whether an item associated with the IC can be recycled; indicating the composition of the item; and indicating the disposal information of the item.

12. The IC according to claim 8, wherein, the recovery information indicates where additional information about an item associated with the IC is located.

13. The IC according to claim 8, wherein the processing block is further configured to: in response to determining that the selection command includes both the correct authentication information and a request for the recovery information, respond to the subsequent inventory commands with one or more of the identification information and the recovery information.

14. The IC according to claim 8, wherein, the processing block is configured to respond with the recovery information by responding to the subsequent inventory commands with the recovery information instead of a random number.

15. A method for a radio frequency identification (RFID) integrated circuit (IC) in a hidden state to transition from the hidden state to a non-hidden state or remain in the hidden state and provide recovery information while in the hidden state, the method comprises: when the IC is in the hidden state: receive a selection command; determine whether the selection command includes authentication information, a request for the recovery information, or both; in response to determining that the selection command includes authentication information, determine whether the authentication information is correct; in response to determining that the authentication information is correct, transition to the non-hidden state and respond to subsequent inventory commands with identification information; in response to determining that the selection command does not include authentication information but includes a request for the recovery information and the IC is configured to expose the recovery information, remain in the hidden state and respond to the subsequent inventory commands only with the recovery information rather than the identification information; and in response to determining that the selection command does not include correct authentication information or a request for the recovery information, remain in the hidden state and thus ignore the subsequent inventory commands.

16. The method according to claim 15, wherein the correct verification information includes one or more of the following: A correct personal identification number (PIN), A correct password, and Information correctly encrypted based on a key known to the IC.

17. The method according to claim 15, wherein determining whether the selection command includes a request for recovery information includes determining whether the selection command specifies a non-removable bit of the IC, the non-removable bit indicating whether the IC can be removed from an associated article.

18. The method according to claim 15, wherein the recovery information does not uniquely identify the IC and indicates at least one of the following: Indicating whether an article associated with the IC can be recycled; Indicating the composition of the article; Indicating the disposal information of the article; and Indicating where additional information about the article associated with the IC is located.

19. The method according to claim 15, further comprising: In response to determining that the selection command includes both the correct verification information and a request for the recovery information, responding to the subsequent inventory command with one or more of the identification information and the recovery information.

20. The method according to claim 15, wherein responding to the subsequent inventory command with the recovery information includes responding to the subsequent inventory command with the recovery information instead of a random number.

Citation Information

Patent Citations

  • RFID tags with public and private inventory states

    US10402710B1

  • Privacy aware camera and device status indicator system

    CN104871170A

  • Secure read-write method of ultrahigh-frequency passive radio frequency identification system electronic label

    CN105373762A