RFID Security via Host-Mediated Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional RFID and contactless card technologies lack effective security measures, making them vulnerable to unauthorized use and data capture due to their wireless nature, which allows for eavesdropping and tampering without physical possession.

Innovation Solution

A Radio Frequency (RF) transaction securing system that employs security protocols, user credentials, digital certificates, and GPS-based location control to secure RFID transactions, using tag processing services to communicate with RFID read/write devices and databases to ensure encrypted and authenticated communication, preventing unauthorized use and tampering.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If wireless RF communication is used for RFID tags and contactless cards, then convenience and portability are improved, but security vulnerability increases due to eavesdropping and data capture

Engineering Contradiction:
ImproveconvenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary authentication and authorization actions before allowing any RF communication. The reader must be authenticated to the host computer, and the RFID instrument must be authorized before data exchange is permitted. This prevents unauthorized devices from participating in the communication protocol.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The host computer acts as an intermediary between the portable RFID reader and the RFID instrument. All communication must pass through the host computer which validates credentials, encrypts data, and controls the transaction. This intermediary prevents direct unauthorized access between the reader and the instrument.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If magnetic stripe or contactless card data is transmitted wirelessly, then transaction speed is improved, but data capture by recording devices increases

Engineering Contradiction:
Improvetransaction speedVSAvoiddata capture
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The system converts the potential harm of wireless data transmission into a benefit by implementing selective disclosure. Only authorized readers can access the data, and the data is encrypted during transmission. The recording device attempt fails because the data appears as random encrypted bytes without the proper authentication keys.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

Authentication and authorization actions are performed preliminarily before any data transmission occurs. The reader proves its identity to the host computer, and the RFID instrument proves its authorization status. Only after these preliminary actions succeed does the system allow data exchange, preventing data capture by unauthorized recording devices.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If RFID tags can be read and written by any portable device, then versatility is improved, but unauthorized use and tampering increase

Engineering Contradiction:
Improvedevice compatibilityVSAvoidunauthorized use
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The host computer serves as a mandatory intermediary that all readers must authenticate with before accessing RFID instruments. This intermediary layer provides centralized control over who can read/write which instruments, enabling versatility for authorized devices while preventing unauthorized use.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication of the reader and authorization of the instrument before allowing any read/write operations. This preliminary action ensures that only authenticated readers can access authorized instruments, preventing unauthorized use while maintaining versatility for legitimate devices.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If security protocols are implemented for RFID transactions, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The host computer is designed as a universal security platform that handles multiple security functions: authentication of readers, authorization of instruments, encryption of data, and transaction logging. By consolidating these functions in a single multi-functional system, the patent reduces overall system complexity while maintaining strong security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8049594B1Enhanced RFID instrument security
Publication Date: 2011.11.01 QUALCOMM FYX
  • US8049594B1 patent drawing
  • US8049594B1 patent drawing
  • US8049594B1 patent drawing

AI summary

A system and method for using an RFID read/write device to secure an RFID-operable instrument or an RF communication is provided. The invention includes security databases in communication with a processor for storing and communicating security protocols to the RFID read/write device. The invention includes a method for restricting the unauthorized use of an RFID read/write device. The invention includes a subscription service for communicating user credentials to a certificate authority to obtain a counter security protocol. The invention also includes decrypting information stored on an RF-operable device or transmitted via radio-frequency using counter security protocols.