Method for verifying a radio frequency identification number
By introducing a signature verification method using default telegrams and unique identification codes into RFID transponders, the problem of transponders being easily cloned in the ISO 11784/11785 standard is solved, achieving effective authentication of transponders and enhancing system security.
Patent Information
- Application Number
- CN202180013557.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-02-11
- Filing Date
- 2021-02-09
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2041-02-09
AI Technical Summary
The lack of certification standards in existing ISO 11784/11785 RFID technology makes animal identification numbers easy to clone. Existing technology relies on manufacturer-specific transponder hardware logic and scanner software, making it difficult to effectively verify the uniqueness of transponders.
An RFID transponder with an RF transceiver and a memory is used. The memory contains a default telegram and a unique identification code independently created by a third party. The authenticity of the transponder is verified by a signature verification method. The signature generation and verification process complies with the ISO 11784/11785 standard.
It enables effective authentication of transponders, prevents illegal copying and forgery, enhances the security and reliability of the identification system, and ensures the uniqueness and authenticity of transponders.
Smart Images

Figure CN115066684B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Generally, the present specification relates to a method for producing an RFID transponder, and in particular to an RFID transponder with an authentication data. Furthermore, the present specification relates to a method for authenticating an RFID with an independent RFID scanner. More specifically, the present disclosure proposes a method for producing and verifying an authenticated ISO 11784 / 11785 transponder, for example. BACKGROUND
[0002] The ISO 11784 / 11785:1996 standard specifies radio frequency identification (RFID) signals and data structures for animal identification. The standard lacks authentication specifications and makes identification numbers vulnerable to cloning. Existing ISO 11784 / 11785 radio frequency identification technology relies on manufacturers to guarantee the uniqueness of each animal identification number.
[0003] However, with the advent of programmable transponders, animal identification numbers can be easily cloned by standard RFID programmers. While existing technologies such as NXP’s Originality Signature store and retrieve an encrypted signature in the transponder, they use manufacturer-specific transponder hardware logic and scanner software. SUMMARY
[0004] The present specification describes a method for manufacturers to produce RFID transponders, for example, transponders compliant with the ISO 11784 / 11785 standard, with an authentication signature using commercially available transponders and RFID programmers. The present specification also describes a method for verifying the authentication signature using an RFID scanner capable of reading the transponder’s internal memory, thereby verifying the transponder.
[0005] Generally, one innovative aspect of the subject matter described in this specification can be embodied in a transponder that includes: a radio frequency (RF) transceiver; and a memory in communication with the RF transceiver, the memory storing data retrievable by a scanner via the RF transceiver. The memory includes: (i) a field-programmable memory including a default telegram automatically transmitted by the transponder upon activation of the transponder by the scanner; and (ii) a field-programmable memory including a signature generated using the default telegram, the signature transmitted by the transponder upon receipt of a memory read signal.
[0006] Implementations of the transponder can include one or more of the following features and / or aspects of other features. For example, the memory can include a read-only memory including a unique identification (UID) code independently established by a third party. The signature can be generated using both the UID code and the default telegram. The UID code can be transmitted by the transponder upon receipt of a UID read signal.
[0007] In some implementations, the default telegram includes an identification code and a signature indicator.
[0008] The transponder can conform to the ISO 11784 / 11785 code structure.
[0009] In another aspect, the subject matter features a passive integrated transponder (PIT) tag including a transponder.
[0010] In yet another aspect, the subject matter features a collar tag including a transponder.
[0011] In general, another innovative aspect of the subject matter described in this specification can be embodied in a method performed by a scanner for authenticating a transponder, the transponder including a memory that stores data retrievable by the scanner, the data having a default telegram and a signature. The method includes retrieving the default telegram by activating the transponder using a radio frequency (RF) signal from the scanner, retrieving at least a portion of the signature by sending a memory read signal from the scanner to the transponder, and computationally authenticating the signature based on the default telegram.
[0012] Implementations of the method can include one or more of the following features and / or features of other aspects. For example, the memory can include a unique identification (UID) code that is independently established by a third party, and the method can further include retrieving the UID code by sending the memory read signal from the scanner to the transponder. The signature can be computationally authenticated based on the default telegram and the UID code. The signature can be generated with the UID code and the default telegram.
[0013] The memory read signal can be sent by the scanner after retrieving the default telegram. The scanner can send the memory read signal in response to confirming a signature indicator included in the default telegram.
[0014] The entire signature can be retrieved when sending the memory read signal from the scanner to the transponder. In certain implementations, a portion of the signature is retrieved with the default telegram.
[0015] The method can include verifying the transponder when authenticating the signature.
[0016] The transponder can conform to the ISO 11784 / 11785 code structure.
[0017] The transponder can reside within an animal during retrieval of the default telegram and the signature. The method can include identifying the animal after authenticating the signature.
[0018] Generally speaking, another innovative aspect of the subject matter described in this specification can be embodied in a method for programming a transponder including a memory, the method comprising: generating a default telegram; generating a signature based on the default telegram; and writing the signature and the default telegram to the transponder's memory.
[0019] Implementations of the method may include one or more of the following features and / or features of other aspects. For example, the memory may include a unique identification (UID) code, and the method may further include receiving the UID code from the transponder. A signature may be generated based on the UID code and a default telegram.
[0020] The transponder may conform to the ISO 11784 / 11785 code structure.
[0021] Thus, the disclosed method comprises several steps and the relationship of one or more such steps to each of the others, as well as apparatus embodying features of structure, combination of elements and arrangement of parts suitable for effecting these steps, all exemplified in the following detailed disclosure, and the scope of the invention will be pointed out in the claims.
[0022] Many systems are designed around the functionality of RFID transponders, such as licensing and registration of animals, authentication of veterinary health certificates, time and attendance systems, and access control, each of which often implicitly relies on the integrity of the transponder identification code.
[0023] The secure transponder technology disclosed herein advances and facilitates identification of objects by preventing illegal duplication or counterfeiting of transponders put into use, and further strengthens such systems by creating accountability and preventing transponder repudiation.
[0024] Among other advantages, the secure transponder technology disclosed herein can facilitate identification (e.g., animal identification) technology by enabling signature verification for transponder authentication. In some embodiments, the transponder can be used as a certificate of authenticity, for example, in a manner similar to that used for luxury watches, artwork, souvenirs, etc.
[0025] The details of one or more embodiments of the subject matter of this specification are set forth in the accompanying drawings and the description below. Other features, aspects, and advantages of the subject matter will become apparent from the description, drawings, and claims. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] Figure 1A is a schematic diagram illustrating aspects of an RFID transponder.
[0027] Figure 1B The conventional 128-bit ISO Full Duplex Transmission (FDX) telegram defined in ISO 11785:1996 is shown.
[0028] Figure 1C Aspects of exemplary memory contents of the disclosed transponder are shown, featuring a signature indicator included in the identification data and a full authentication signature included in the authentication data.
[0029] Figures 2A-2B Aspects of exemplary memory contents of the disclosed transponder are shown, featuring a signature indicator included in the identification data and a full authentication signature included in the authentication data.
[0030] Figure 3 Identification code data in accordance with ISO 11784 including a signature indicator is shown.
[0031] Figures 4A-4B Aspects of exemplary memory contents of the disclosed transponder are shown, featuring a signature indicator included in the identification data and a full authentication signature included in the authentication data.
[0032] Figure 5 Identification code data in accordance with ISO 11784 including a signature indicator is shown.
[0033] Figure 6 is a flowchart of a scan process for a legacy ISO transponder.
[0034] Figure 7 is a flowchart of an example scan process for a disclosed ISO transponder.
[0035] Figure 8 is a flowchart of a program process for a legacy ISO transponder.
[0036] Figure 9 is a flowchart of an example program process for a disclosed ISO transponder.
[0037] Like reference numbers and designations in different figures indicate like elements. DETAILED DESCRIPTION
[0038] Generally, the disclosed technology relates to methods and systems for preventing fraudulent production of radio frequency identification (RFID) transponders. For example, the technology can include a signature indicator in a telegram of a default read and store a read-only authentication signature in an internal memory of the transponder. The RFID can be in accordance with ISO standards, such as the ISO 11784 / 11785 standards. Among other uses, the transponder can be used for animal identification. Depending on the end use, the transponder can be embedded or attached to a variety of items. For example, the transponder can be embedded in a tag, such as a passive integrated transponder (PIT) tag or a collar tag, for example, for attachment to an animal. In some embodiments, the transponder can be encapsulated in a staple or attached to an adhesive base.
[0039] An example RFID transponder for implementing the method is shown in Figure 1A Here, the transponder 120 includes a radio frequency transceiver 121 and a memory 122. The RF transceiver 121 typically includes control circuitry (e.g., comprised of one or more integrated circuits) and an antenna. The memory 122 includes an internal memory 123 (e.g., read-only memory) and a field programmable memory 124. The memory 122 is in communication with the RF transceiver 121, which receives RF signals 132 (e.g., from an RF scanner 140) and transmits RF signals 130 (e.g., to the RF scanner 140). Typically, the transmitted RF signals 130 include information stored in the memory 122 that uniquely identifies the transponder 120. The information includes a default telegram stored in the field programmable memory 124 that is automatically transmitted by the transponder 120 upon activation of the transponder 140. The field programmable memory 124 also includes a signature generated using at least a portion of the default telegram (e.g., using only a portion of the default telegram or using the entire default telegram). The internal memory 123 can store information such as a unique identification (ID) code established independently by a third party (such as the manufacturer of the integrated circuit of the memory).
[0040] Generally, the signature can employ any public-private key encryption such as AES, ECDSA, RSA, etc.
[0041] Examples of specific protocols for partitioning and retrieving information (including the signature) stored in the memory 122 are given below. While these examples use the ISO 11784 / 11785 standard, more generally, the disclosed innovative concepts can also be applied to other standards.
[0042] Figure 1B and 1C A conventional 128-bit ISO FDX telegram 101 defined in ISO 11785:1996 and a conventional 64-bit identification code data content 106 defined in 11784:1996, 11784Amd.1:2004, and 11784Amd.2:2010, respectively, are shown. The identification code 106 is a portion of the data that makes up the telegram 101.
[0043] Figure 1C The indices used in the above are provided in Table 1.
[0044] Table 1
[0045]
[0046] Turning now to an RFID tag that includes a signature for authentication, typically the transponder memory is partitioned into two parts: identification data and authentication data. Reference is made to Figure 2A andFigure 2B In one example, the identification memory 205 stores ISO 11784 / 11785 telegrams and their contents are continuously transmitted by the transponder whenever the transponder is activated. The authentication memory 206 stores authentication data and its contents are only transmitted by the transponder, typically once each time a memory read command is received by the transponder. In some cases, multiple read commands may be required to retrieve the complete authentication. Conventional scanners without authentication capabilities will follow Figure 6 The conventional recognition processing flow shown can only access ISO telegrams stored in the recognition memory 205.
[0047] exist Figures 2A-2B In the example embodiment implementation shown, signatures 204 are stored in a baseline configuration. Figure 2B In the baseline signature storage format shown, the complete signature 204 is stored in the transponder's internal memory 206, with no portion of it appearing in the transponder's internal memory 206. Figure 2A In order to retrieve the complete signature 204, the RFID scanner must send a memory read command 508 to the transponder, such as Figure 7 shown.
[0048] refer to Figure 3 ,for Figures 2A-2B In the embodiment shown in , the signature indicator 112 may be introduced into the user information field 112 of the identification code 113 specified in the ISO 11784:1996 / Amd. 1:2004 standard.
[0049] In some embodiments, at least part of the signature may be stored as part of the identification data. Figures 4A-4B , signatures 301 and 303 are stored in a partial signature trailer configuration. In the partial signature trailer format shown here, a portion of the signature is stored in the telegram trailer 301. Figure 4A As shown, the telegram trailer 301 is sent as part of the ISO 11784 / 11785 telegram 302. All compliant scanners can Figure 6 The conventional transponder scanning process shown reads and collects this portion of the signature. Specifically, at the beginning of the scan (401), the scanner sends an activation signal (402), which causes the transponder to send a default telegram 442. The scanner receives and reads the telegram (403). This completes the scan (405). When the activation field is no longer present, the transponder will shut down.
[0050] The remaining portion of the signature 303 is stored in the transponder's internal memory 206. In order to retrieve the complete signatures 301 and 303, the RFID scanner must send a memory read command 508 to the transponder. Figure 7 shown.
[0051] While the preceding example features a portion of the signature being stored in the telegram trailer 301, other configurations are possible. For example, in some embodiments, a portion of the signature can be stored in the telegram’s identification code. Figure 5 An implementation of the telegram’s identification code 802 is shown, in which a portion of the signature is included in the user information field 801. In some embodiments, an authentication signature generated from the transponder UID 203 and the animal identification number 111 is introduced into each transponder for authentication. The scanner can verify the authenticity of the signature by using the animal identification number 111, the known public key, and the transponder UID 203 as input parameters to a verification function.
[0052] As Figure 7 Further shown, to authenticate a signature-equipped transponder, the RF scanner must perform additional data extraction 505, 506 and transponder interrogation 508. Upon completion of the operations 501, 502, 503 and 542 corresponding to Figure 6 Following the operations 501, 502, 503 and 542 of the identification process shown (i.e., operations 401, 402, 403 and 442), the scanner attempts to detect 505 the signature indicator 112 in the user information field 107 of the telegram 202 / 302. The absence 505N of the signature indicator 112 immediately classifies 513 the transponder as “unsigned”. Such transponders cannot be authenticated for identity. This is the case for existing conventional ISO transponders on the market.
[0053] If the signature indicator 112 is detected 505Y, the scanner extracts 506 the partial signature from the telegram trailer 301 for signature-equipped transponders using the partial signature trailer 301 storage configuration. Thereafter, the scanner reads the transponder UID 203 and the remaining signature data 204, 303 from the transponder by sending multiple memory read commands 508. When the transponder UID 203 and the full signature 204, 301 and 303 are collected from the transponder via UID and signature data transmission 545, the scanner can verify 510, 511 the signature stored in the transponder using the public key, the identification code 111 and the transponder UID 203 as decryption parameters. The verification process described above is shown in Figure 7 The UID and signature read order can be interchanged when verification.
[0054] Figure 8 is a flowchart of the programming process of a conventional ISO transponder. To produce a conventional transponder, an ISO 11784 / 11785 programmer starts 601 data collection 602, which includes obtaining the identification code 609 from the programmer’s memory. The programmer writes the transponder configuration 604, the telegram 605 and the transponder lock 606 to the transponder in sequence in the telegram write (643), configuration write (642) and lock (644) steps, asFigure 8 The generation of a signed transponder requires additional steps to interrogate the transponder 704 and compute the signature 706.
[0055] Figure 9 is a flowchart of the programming process for a signed transponder according to the disclosed technology. For a signed transponder, the programmer needs the additional steps of reading the transponder’s UID 704 and generating an authentication signature 706 before programming the telegram and signature 709. For a public key based authentication signature, the programmer uses the private key, the transponder UID 203, the identification code 111 and a random salt as parameters for the signature generation 706. With the generated signature, the programmer can then write the configuration 708, the telegram 709, the signature 709 and the lock configuration 710 to the transponder in the order as shown in Figure 9 The same Figure 8 The same Figure 9 The steps in the process as shown in Figure 8 In the process as shown in Figure 9 In the process as shown in
[0056] In summary, this specification describes a device for a manufacturer to produce an ISO 11784 / 11785 compliant transponder with an authentication signature using a common transponder and RFID programmer. This specification also describes a method to verify the authentication signature using an RFID scanner with transponder programming capabilities.
[0057] It can therefore be seen that the above objects, among those apparent from the preceding description, are effectively achieved, and since certain changes can be made in the execution of the above method and in the described structure without, however, departing from the spirit and scope of the invention, it is intended in the foregoing description to encompass all such modifications as fall within the scope of the invention, and that all matters set forth or shown in the foregoing description and associated drawings are to be interpreted as illustrative and not in a limiting sense.
[0058] It is also to be understood that the following claims are intended to cover all of the generic and specific features of the invention herein described and all statements of the elements of the scope of the invention, as such statements can come within the language of the claims by virtue of the doctrine of equivalents, and that no disclaimer is intended, except as can be recited in the transition of the claims.
[0059] Embodiments of the subject matter and the functional operations described in this specification can be implemented in digital electronic circuitry, in tangibly-embodied computer software or firmware, in computer hardware, including the structures disclosed in this specification and their structural equivalents, or in combinations of one or more of them. Embodiments of the subject matter described in this specification can be implemented as one or more computer programs, i.e., one or more modules of computer program instructions encoded on a tangible non-transitory storage medium for execution by, or to control the operation of, data processing apparatus. The computer storage medium can be a machine-readable storage device, a machine-readable storage substrate, a random or serial access memory device, or a combination of one or more of them. Alternatively or additionally, the program instructions can be encoded on an artificially generated propagated signal, e.g., a machine-generated electrical, optical, or electromagnetic signal that is generated to encode information for transmission to suitable receiver apparatus for execution by a data processing apparatus.
[0060] The term“data processing apparatus” refers to data processing hardware and encompasses all kinds of apparatus, devices, and machines for processing data, including by way of example a programmable processor, a computer, or multiple processors or computers. The apparatus can also be, or further include, special purpose logic circuitry, e.g., an FPGA (field programmable gate array) or an ASIC (application-specific integrated circuit). The apparatus can optionally include, in addition to hardware, code that creates an execution environment for computer programs, e.g., code that constitutes processor firmware, a protocol stack, a database management system, an operating system, or a combination of one or more of them.
[0061] A computer program, which can also be referred to or described as a program, software, a software application, an app, a module, a software module, a script, or code, can be written in any form of programming language, including compiled or interpreted languages, or declarative or procedural languages; and it can be deployed in any form, including as a stand-alone program or as a module, component, subroutine, or other unit suitable for use in a computing environment. A program may, but need not, correspond to a file in a file system. A program can be stored in a portion of a file that holds other programs or data, e.g., one or more scripts stored in a markup language document, in a single file dedicated to the program in question, or in multiple coordinated files, e.g., files that store one or more modules, sub programs, or portions of code. A computer program can be deployed to be executed on one computer or on multiple computers that are located at one site or distributed across multiple sites and networks.
[0062] The processes and logic flows described in this specification can be performed by one or more programmable computers executing one or more computer programs to perform functions by operating on input data and generating output. The processes and logic flows can also be performed by special purpose logic circuitry, e.g., an FPGA or an ASIC, or by a combination of special purpose logic circuitry and one or more programmed computers.
[0063] Computers suitable for the execution of a computer program can be based on general or special purpose microprocessors or both, or any other kind of central processing unit. Generally, a central processing unit will receive instructions and data from a read-only memory or a random access memory or both. The essential elements of a computer are a central processing unit for performing or executing instructions and one or more memory devices for storing instructions and data. The central processing unit and the memory can be supplemented by, or incorporated in, special purpose logic circuitry. Generally, a computer will also include, or be operatively coupled to receive data from or transfer data to, or both, one or more mass storage devices for storing data, e.g., magnetic, magneto-optical disks, or optical disks. However, a computer need not have such devices. Moreover, a computer can be embedded in another device, e.g., a mobile telephone, a personal digital assistant (PDA), a mobile audio or video player, a game console, a Global Positioning System (GPS) receiver, or a portable storage device (e.g., a universal serial bus (USB) flash drive, etc.).
[0064] Computer readable media suitable for storing computer program instructions and data include all forms of non-volatile memory, media and memory devices, including by way of example semiconductor memory devices, e.g., EPROM, EEPROM, and flash memory devices; magnetic disks, e.g., internal hard disks or removable disks; magneto-optical disks; and CD-ROM and DVD-ROM disks.
[0065] To provide for interaction with a user, embodiments of the subject matter described in this specification can be implemented on a computer having a display device, e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor, for displaying information to the user and a keyboard and a pointing device, e.g., a mouse or a trackball, by which the user can provide input to the computer. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback, e.g., visual feedback, auditory feedback, or tactile feedback; and input from the user can be received in any form, including acoustic, speech, or tactile input. In addition, a computer can interact with a user by sending documents to and receiving documents from a device that is used by the user; for example, by sending web pages to a web browser on a user’s device in response to requests received from the web browser. Also, a computer can interact with a user by sending text messages or other forms of message to a personal device, e.g., a smartphone that is running a messaging application, and receiving responsive messages from the user in return.
Claims
1. A radio frequency identification (RFID) transponder comprising: Radio frequency (RF) transceiver; as well as a memory in communication with the RF transceiver, the memory storing data retrievable by a scanner via the RF transceiver, the memory being programmed according to an ISO 11784 / 11785 code structure and comprising: (i) a read-only memory comprising a unique identification (UID) code unique to the transponder, wherein the RFID transponder is programmed to transmit the UID code upon receipt of a UID read signal by the transponder; (ii) a field programmable memory comprising a default RFID telegram comprising a sequence of data automatically and continuously transmitted by the transponder upon activation of the transponder by the scanner, the default RFID telegram comprising data identifying an animal associated with the transponder; and (iii) a field programmable memory including an encrypted signature generated by encrypting a signature including the default RFID telegram and the UID code using a public-private key encryption scheme, the RFID transponder being programmed to transmit the encrypted signature upon receipt of a memory read signal by the transponder, The RFID transponder complies with the ISO 11784 / 11785 code structure.
2. The transponder according to claim 1, wherein The default telegram includes an identification code and a signature indicator.
3. A passive integrated transponder (PIT) tag comprising the transponder according to claim 1.
4. A collar tag comprising the transponder according to claim 1.
5. A method performed by a scanner for authenticating a radio frequency identification (RFID) transponder, the RFID transponder comprising a memory storing data retrievable by the scanner, the memory comprising a read-only memory, the read-only memory comprising a unique identification (UID) code unique to the transponder, the data comprising a default RFID message and an encrypted signature, the default RFID message comprising data identifying an animal associated with the RFID transponder, the encrypted signature being generated by encrypting a signature comprising the default RFID message and the UID code using a public-private key encryption scheme, the method comprising: retrieving the default telegram by activating the transponder using a radio frequency (RF) signal from the scanner; retrieving at least a portion of the encrypted signature by sending a memory read signal from the scanner to the transponder; as well as computationally authenticating the cryptographic signature based on the default telegram, Wherein, authenticating the encrypted signature in a computational manner includes: using a public key to verify the encrypted signature, and The RFID transponder complies with the ISO 11784 / 11785 code structure.
6. The method according to claim 5, wherein: The UID is a code independently created by a third party, and The method further comprises: The UID code is retrieved by sending the memory read signal from the scanner to the transponder.
7. The method according to claim 6, wherein: The cryptographic signature is computationally authenticated based on the default telegram and the UID code.
8. The method according to claim 5, wherein After the default telegram is retrieved, the memory read signal is sent by the scanner.
9. The method according to claim 8, wherein The scanner transmits the memory read signal in response to confirming a signature indicator included in the default telegram.
10. The method according to claim 5, wherein When the memory read signal is sent from the scanner to the transponder, the entire encrypted signature is retrieved.
11. The method according to claim 5, wherein: A portion of the encrypted signature is retrieved using the default telegram.
12. The method according to claim 5, further comprising: The transponder is verified upon authenticating the encrypted signature.
13. The method according to claim 5, wherein: The transponder resides within the animal during the retrieval of the default telegram and the encrypted signature.
14. The method according to claim 13, further comprising: The animal is identified after authenticating the encrypted signature.
15. A method for programming a radio frequency identification (RFID) transponder comprising a memory, the memory comprising a read-only memory, the read-only memory comprising a unique identification (UID) code unique to the RFID transponder, the method comprising: generating a default RFID telegram comprising data identifying an animal associated with the RFID transponder; generating an encrypted signature by encrypting a signature including the default telegram and the UID code using a public-private key encryption scheme; as well as writing the encrypted signature and the default telegram to the memory of the transponder, The RFID transponder complies with the ISO 11784 / 11785 code structure.
Citation Information
Patent Citations
RFID and Sensor Signing System
US20080303667A1
Sensor management system
US20180129835A1