RFID Tag Host Interface Access Control Unit
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
RFID/NFC tags with host interfaces face security vulnerabilities due to unauthenticated access to non-volatile memory via the host interface, lacking robust access control mechanisms to protect sensitive data.
Innovation Solution
Incorporating a host access control unit and host interface access control data to define and enforce access rules for data memory access through the host interface, ensuring secure read and write operations by authenticating host devices and preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a host interface is added to an RFID/NFC tag to enable electronic solutions and data exchange, then adaptability and application space are improved, but security vulnerability increases due to unauthenticated access to non-volatile memory
Solution Approach 1:
The patent segments the memory access control by creating separate access control data structures for RF interface and host interface. The host interface access control data (bytes 6-7) are distinct from RF interface access control data, allowing independent security policies for each interface type. This segmentation enables the system to maintain security while supporting multiple access paths.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism between the host interface and the non-volatile memory. The host access control unit acts as a mediator that intercepts and validates host interface access requests against stored access control rules before allowing memory access. This intermediary layer prevents direct unauthenticated access while maintaining host interface functionality.
2Reliability
If host interface access control mechanisms are implemented to secure data memory, then security is improved, but device complexity increases due to additional control units and access control data
Solution Approach 1:
The patent merges the host interface access control functionality with the existing RF interface access control unit. Both RF and host interface access control data are stored in the same memory structure and processed by the same access control unit, which selectively applies the appropriate access rules based on the interface type. This merging approach reduces device complexity by avoiding duplicate control units while maintaining comprehensive security.
3Reliability
If RF authentication procedures are used for memory access, then security is improved for RF interface, but ease of operation deteriorates due to authentication requirements preceding every memory operation
Solution Approach 1:
The patent implements preliminary authentication by storing host interface access control data in advance during tag initialization or manufacturing. The access control unit pre-loads and caches these access rules, allowing subsequent host interface memory operations to proceed without repeated authentication handshakes. This preliminary action maintains security while significantly improving operational convenience for authorized hosts.
Data Source
AI summary
There is described an RF communication device, the device comprising (a) a data memory for storing data, (b) an RF interface (112) for RF communication with an external RF device (130), (c) a host interface (111) for communication with a host device (120), (d) a host access memory unit (214, 215) comprising host interface access control data, the host interface access control data defining host access rules for accessing data in the data memory through the host interface (111), and (e) a host access control unit for, based on the host interface access control data, controlling access to data in the data memory through the host interface (111). There is also described a system and a method.


