Secure RFID Tag Credential Distribution via Controller Key Derivation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing RFID tag communication systems face challenges in providing secure communications while managing limited battery life and computational power, which restricts the complexity of encryption algorithms and key management.
Innovation Solution
A mechanism for distributing and implementing secure credentials on a WLAN using RFID tags, where symmetric keys are provisioned to enable optimized re-association and secure announcements, allowing the controller to regenerate keys without maintaining key states for every tag, using a master key, identifier, and address to derive announce mode and secondary association mode keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If symmetric keys are provisioned to RFID tags for secure communications, then security is improved, but computational overhead and key management complexity increase
Solution Approach 1:
The patent extracts key management complexity from the RFID tag by implementing announce mode where the tag sends unencrypted announcements containing its identifier. The controller handles all key management operations including key generation, distribution, and regeneration, while the tag only performs lightweight encryption/decryption of data payloads. This separation reduces the tag's computational burden and key management complexity.
Solution Approach 2:
The communication protocol is segmented into two distinct modes: announce mode for unencrypted identifier transmission and data mode for encrypted communication. This segmentation allows the system to use simple unencrypted announcements for tag identification while reserving encrypted communication for actual data transmission, thereby reducing overall computational overhead and key management complexity.
2Reliability
If complex encryption algorithms are employed for secure RFID communications, then security is improved, but battery life is reduced due to increased computational power requirements
Solution Approach 1:
The patent applies partial encryption by only encrypting the data payload while leaving the announcement portion unencrypted. The announce mode transmissions remain unencrypted to minimize computational overhead, while only the necessary data portions are encrypted using AES. This partial approach provides adequate security for the sensitive data while preserving battery life by avoiding full encryption of all communications.
Solution Approach 2:
The patent implements a key regeneration mechanism where session keys are temporarily used and then discarded after a single use or after a short time period. The controller generates new keys as needed without maintaining long-term key states for every tag. This disposable key approach provides strong security for each communication session while reducing the computational burden of maintaining complex key management structures.
3Duration of action of moving object
If key management is simplified for RFID tags, then battery life is extended, but security may be compromised
Solution Approach 1:
The patent introduces the controller as an intermediary that handles all complex key management operations. The controller generates keys, distributes them to tags, and manages key regeneration without requiring the tag to maintain complex key states. This intermediary approach allows the tag to use simple encryption/decryption operations that preserve battery life while the controller ensures strong security through centralized key management.
Solution Approach 2:
The announce mode mechanism allows tags to self-identify by sending unencrypted announcements containing their identifiers. This self-service approach eliminates the need for tags to perform complex authentication handshakes or maintain complex key states for identification purposes. The tag simply transmits its identifier, and the controller handles the security aspects, thereby extending battery life while maintaining security.
Data Source
AI summary
Described herein in an example embodiment, is a mechanism to distribute and implement secure credentials on a WLAN (wireless local area network) employing radio frequency identification (RFID) tags (30). Symmetric keys are provisioned to the tag in a manner that allows for optimized re-association and secure announcements. The provisioned keys are derived in a way that enables the controller (22) to operate without having to maintain the key state for every tag. In an example embodiment, the controller generates keys for the RFID tags that are derived from a master key associated with the controller, an identifier assigned to the RFID tag and an address associated with the RFID tag.


