Elliptic Curve Authentication for RFID Privacy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

RFID-based data communication systems face challenges in ensuring the security and privacy of data, particularly in preventing unauthorized reading and tracking, due to limitations in hardware resources and the need for efficient authentication methods that provide both data privacy and location privacy protection.

Innovation Solution

An authentication method using asymmetric encryption based on elliptical curves, which involves participants with secret and public keys, randomizes and encrypts replies to ensure only authorized base stations can decrypt and authenticate, providing enhanced security and privacy without requiring secure links to central databases.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If asymmetric encryption based on elliptical curves is used for authentication, then security and privacy protection are improved, but computational complexity and hardware requirements increase

Engineering Contradiction:
Improveauthentication securityVSAvoidhardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms the authentication problem by changing the mathematical parameters from traditional symmetric encryption to asymmetric encryption based on elliptic curves. This parameter change enables stronger security with smaller key sizes, reducing the actual hardware burden despite the increased algorithmic complexity. The use of elliptic curve cryptography (ECC) provides equivalent security to RSA with much shorter keys, making it suitable for resource-constrained RFID systems.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces traditional mechanical authentication mechanisms (physical contact, centralized database verification) with cryptographic mathematical operations. The authentication is achieved through elliptic curve point multiplication and verification, eliminating the need for secure physical connections to central databases and reducing hardware complexity in the field devices.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of manufacture

If traditional symmetric authentication methods are used, then hardware resources are saved, but data privacy and location privacy protection are compromised

Engineering Contradiction:
Improvehardware costVSAvoidprivacy protection
Core Design Contradiction:
Ease of manufactureVSLoss of information

Solution Approach 1:

The patent applies asymmetry by using different keys for encryption and decryption (public and private keys). The transponder uses its private key to sign authentication data, while the base station verifies using the transponder's public key. This asymmetric approach enables strong privacy protection because the transponder's private key never leaves the device, preventing unauthorized reading and tracking while keeping hardware requirements manageable.

Inventive Principle:
Principle #4Asymmetry

Solution Approach 2:

The patent introduces cryptographic hash functions and elliptic curve cryptographic operations as intermediaries between the physical hardware and the authentication data. These mathematical intermediaries transform raw authentication data into protected forms, enabling privacy protection without requiring complex hardware security modules or secure physical connections.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Speed

If authentication data is transmitted in plaintext, then communication speed is improved, but vulnerability to unauthorized reading increases

Engineering Contradiction:
Improveauthentication speedVSAvoidunauthorized reading vulnerability
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary cryptographic operations before data transmission. The transponder pre-computes authentication signatures using its private key and elliptic curve operations before sending data to the base station. This preliminary action ensures that even if transmission occurs quickly, the data is already protected, preventing unauthorized reading while maintaining communication speed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent converts the potential harm of wireless transmission (vulnerability to eavesdropping) into a benefit by using the transmission medium itself to distribute public keys and verification data. The public key infrastructure enables fast wireless communication while the cryptographic design ensures that intercepted data cannot be used for unauthorized authentication, turning the openness of wireless communication into an advantage for key distribution.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

4Reliability

If centralized database verification is used for authentication, then authentication reliability is improved, but system complexity and security risks increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the critical authentication verification function from the centralized database and places it in the field devices themselves. Each transponder contains its own private key and can perform self-authentication using elliptic curve cryptography. The base station verifies authentication using public keys without needing to query a central database, eliminating the single point of failure and reducing system complexity while maintaining reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent enables self-service authentication where transponders autonomously generate and verify their own authentication credentials using embedded elliptic curve cryptographic operations. The transponder signs authentication data with its private key and the base station verifies using the public key, eliminating the need for centralized verification services and reducing overall system complexity while improving reliability through distributed security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8458472B2Authentication method and communications system used for authentication
Publication Date: 2013.06.04 CERTIVA DIGITAL LLC
  • US8458472B2 patent drawing
  • US8458472B2 patent drawing
  • US8458472B2 patent drawing

AI summary

An authentication method authenticates between subscribers of a communications system using an asymmetric elliptic curve encryption algorithm. The method involves providing a first and at least one second subscriber having a first or second secret key known only to the respective subscriber and a public key; authenticating an inquiry transmitted by the first subscriber with respect to the validity of the first certificate contained therein and associated with the first subscriber; calculating the response of the second subscriber associated with the inquiry; randomized encryption of the calculated response and a second certificate associated with the second subscriber using the public key; decryption and authentication of the response transmitted by the second subscriber with respect to the validity of the second certificate contained therein.