RFID Security via Host-Mediated Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional RFID and contactless card technologies lack effective security measures, making them vulnerable to unauthorized use and data capture due to their wireless nature, which allows for eavesdropping and tampering without physical possession.
Innovation Solution
A Radio Frequency (RF) transaction securing system that employs security protocols, user credentials, digital certificates, and GPS-based location control to secure RFID transactions, using tag processing services to communicate with RFID read/write devices and databases to ensure encrypted and authenticated communication, preventing unauthorized use and tampering.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If wireless RF communication is used for RFID tags and contactless cards, then convenience and portability are improved, but security vulnerability increases due to eavesdropping and data capture
Solution Approach 1:
The system performs preliminary authentication and authorization actions before allowing any RF communication. The reader must be authenticated to the host computer, and the RFID instrument must be authorized before data exchange is permitted. This prevents unauthorized devices from participating in the communication protocol.
Solution Approach 2:
The host computer acts as an intermediary between the portable RFID reader and the RFID instrument. All communication must pass through the host computer which validates credentials, encrypts data, and controls the transaction. This intermediary prevents direct unauthorized access between the reader and the instrument.
2Productivity
If magnetic stripe or contactless card data is transmitted wirelessly, then transaction speed is improved, but data capture by recording devices increases
Solution Approach 1:
The system converts the potential harm of wireless data transmission into a benefit by implementing selective disclosure. Only authorized readers can access the data, and the data is encrypted during transmission. The recording device attempt fails because the data appears as random encrypted bytes without the proper authentication keys.
Solution Approach 2:
Authentication and authorization actions are performed preliminarily before any data transmission occurs. The reader proves its identity to the host computer, and the RFID instrument proves its authorization status. Only after these preliminary actions succeed does the system allow data exchange, preventing data capture by unauthorized recording devices.
3Adaptability or versatility
If RFID tags can be read and written by any portable device, then versatility is improved, but unauthorized use and tampering increase
Solution Approach 1:
The host computer serves as a mandatory intermediary that all readers must authenticate with before accessing RFID instruments. This intermediary layer provides centralized control over who can read/write which instruments, enabling versatility for authorized devices while preventing unauthorized use.
Solution Approach 2:
The system performs preliminary authentication of the reader and authorization of the instrument before allowing any read/write operations. This preliminary action ensures that only authenticated readers can access authorized instruments, preventing unauthorized use while maintaining versatility for legitimate devices.
4Reliability
If security protocols are implemented for RFID transactions, then security is improved, but system complexity increases
Solution Approach 1:
The host computer is designed as a universal security platform that handles multiple security functions: authentication of readers, authorization of instruments, encryption of data, and transaction logging. By consolidating these functions in a single multi-functional system, the patent reduces overall system complexity while maintaining strong security.
Data Source
AI summary
A system and method for using an RFID read/write device to secure an RFID-operable instrument or an RF communication is provided. The invention includes security databases in communication with a processor for storing and communicating security protocols to the RFID read/write device. The invention includes a method for restricting the unauthorized use of an RFID read/write device. The invention includes a subscription service for communicating user credentials to a certificate authority to obtain a counter security protocol. The invention also includes decrypting information stored on an RF-operable device or transmitted via radio-frequency using counter security protocols.


