Hybrid Cryptographic Authentication for RFID Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods in communication systems, such as RFID, face challenges in quickly and reliably authenticating devices from unknown origins while managing key exchange between different agencies, particularly in open systems where key management is complex and time-sensitive transactions are required.

Innovation Solution

The method combines asymmetric and symmetric key generation algorithms, where a first communication device receives a session key portion from a second device, generates a session key using an asymmetric algorithm, and then uses this key to generate a second session key using a symmetric algorithm, allowing for quick and reliable authentication with minimal processing power.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If asymmetric cryptography is used for tag authentication in open systems, then key exchange security is improved, but transaction speed deteriorates

Engineering Contradiction:
Improvekey exchange securityVSAvoidtransaction speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The authentication process is divided into two distinct phases: first, asymmetric cryptography is used for secure key exchange and tag authentication; second, symmetric cryptography is used for rapid mutual authentication and data transfer. This segmentation allows each cryptographic method to be used for its optimal purpose, resolving the contradiction between security and speed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The asymmetric key exchange and tag authentication are performed in advance as a preliminary step. Once the tag is authenticated, a shared symmetric key is established for subsequent communications. This preliminary action eliminates the need for repeated asymmetric operations during the actual transaction, thereby improving speed while maintaining security.

Inventive Principle:
Principle #10Preliminary action

2Speed

If symmetric cryptography is used for mutual authentication, then transaction speed is improved, but key management complexity increases in open systems

Engineering Contradiction:
Improveauthentication speedVSAvoidkey management complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The reader acts as an intermediary that manages the symmetric key distribution. The reader obtains the tag's symmetric key from a secure database after asymmetric authentication, then uses this key for mutual authentication. This intermediary approach simplifies key management for tags while enabling fast symmetric authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the manual or complex key distribution mechanism with an automated system where the reader retrieves pre-stored symmetric keys from a secure database. This substitution eliminates the need for complex real-time key management protocols while maintaining authentication speed.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If protocol selection is performed to determine authentication method, then adaptability is improved, but transaction time increases

Engineering Contradiction:
Improveauthentication method selectionVSAvoidprotocol selection time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs tag authentication using asymmetric cryptography as a preliminary step to determine tag origin and establish a shared symmetric key. This preliminary action enables the system to adapt to different tag types without requiring protocol selection during the actual transaction, as the symmetric key is already established for the specific tag-reader pair.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication system is designed to be universal by supporting both asymmetric and symmetric cryptography within a single framework. The reader can handle tags from different agencies and types using the same overall protocol structure, with the specific cryptographic method automatically determined by the tag's capabilities and the pre-established key relationships.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2922236B1Authentication by use of symmetric and asymmetric cryptography
Publication Date: 2019.04.24 EM MICROELECTRONIC-MARIN
  • EP2922236B1 patent drawingFigure 1
  • EP2922236B1 patent drawingFigure 2

AI summary

The present invention concerns a mutual authentication method in a communication system. According to the method, a first communication device (1), such as an RFID reader, authenticates a second communication device (3), such as an RFID tag, by using an asymmetric authentication protocol based on a generated a session key. The tag authenticates the reader by using a symmetric communication protocol based on a generated other session key. At least a portion of the session key is used to generate the other session key.