5G RFID Tag Authentication Policy Selection Without Redundant Checks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The integration of RFID reader functions into a 5G base station increases vulnerability to man-in-the-middle attacks due to longer distances, necessitating stronger security assurance, but current authentication processes are redundant and complex.

Innovation Solution

A communication method that considers executed authentication policies and security information to determine optimized authentication policies, reducing redundancy and complexity by selectively applying unidirectional or bidirectional authentication based on previous authentication results.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current authentication policy is used, then security assurance is improved, but authentication process complexity increases

Engineering Contradiction:
Improvesecurity assuranceVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent stores executed authentication policy information in advance in the first device. When a new authentication request arrives, the device retrieves previously executed authentication policies and uses them to determine whether additional authentication is needed, avoiding redundant authentication steps while maintaining security requirements.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements a feedback mechanism where the first device queries whether the stored executed authentication policy meets the current authentication requirement. Based on this feedback, the device either proceeds directly to data transmission or initiates additional authentication, thereby optimizing the authentication process complexity while ensuring security.

Inventive Principle:
Principle #23Feedback

2Reliability

If authentication is performed for every operation command, then security is improved, but authentication process redundancy increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication process redundancy
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary authentication and stores the executed authentication policy information in the first device before actual data transmission. This preliminary action allows subsequent operation commands to reference previously executed authentication results, eliminating redundant authentication processes while maintaining security assurance.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent effectively discards redundant authentication actions by querying whether previously executed authentication policies still meet current requirements. When the stored authentication policy is sufficient, the system recovers by proceeding directly to data transmission without repeating authentication, thereby reducing time loss and process redundancy.

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentUS20250324253A1Communication method and related apparatus
Publication Date: 2025.10.16 HUAWEI TECH CO LTD
  • US20250324253A1 patent drawing
  • US20250324253A1 patent drawing
  • US20250324253A1 patent drawing

AI summary

A communication method includes: obtaining security information of a first tag and one or more operation command security policies of the first tag, where the security information is security information that has been executed, and includes a first authentication policy and/or a first security policy; receiving a first operation command from an application function (AF) entity; determining a second authentication policy and/or a second security policy of the first tag based on the security information and a first operation command security policy included in the one or more operation command security policies, where the first operation command security policy corresponds to the first operation command; and sending a first command to a second device, where the first command includes the second authentication policy and/or the second security policy, and a tag identifier of the first tag.