RFID Card Memory Segmentation for Legacy Compatibility and Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current RFID systems lack effective authentication methods for devices and readers, making them vulnerable to eavesdropping, cloning, and tampering, especially in legacy systems, which are difficult and costly to upgrade, leading to security compromises and potential unauthorized access.

Innovation Solution

Implementing a system with promiscuous and non-promiscuous memory regions in RFID devices, where generic data is transmitted freely and sensitive 'shared-secret' data is selectively shared upon authentication challenges, allowing readers to verify the authenticity of cards and prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If promiscuous data transmission is used for compatibility with legacy systems, then ease of operation is improved, but security is worsened due to vulnerability to eavesdropping and cloning attacks

Engineering Contradiction:
Improvecompatibility with legacy systemsVSAvoidsecurity against eavesdropping and cloning
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the RFID card data into two distinct segments: promiscuous data (freely transmitted for compatibility) and non-promiscuous data (selectively transmitted for security). This segmentation allows the system to maintain legacy compatibility while implementing strong authentication mechanisms, resolving the contradiction between ease of operation and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different portions of the card data have different transmission properties. The promiscuous portion is freely available for backward compatibility, while the non-promiscuous portion is protected and only transmitted under specific authenticated conditions. This local differentiation in data quality and accessibility resolves the security-compatibility contradiction.

Inventive Principle:
Principle #3Local quality

2Reliability

If authentication challenges are implemented to verify card authenticity, then security is improved, but device complexity is worsened

Engineering Contradiction:
Improveauthentication capabilityVSAvoidreader and card system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements authentication challenges selectively rather than universally. The reader can choose to issue authentication challenges based on security requirements, and the card responds with non-promiscuous data only when challenged. This partial application of authentication reduces complexity compared to universal authentication while maintaining security where needed.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If selective transmission of non-promiscuous data is used for authentication, then security is improved, but loss of information is worsened due to restricted data access

Engineering Contradiction:
Improveauthentication securityVSAvoiddata accessibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system performs preliminary authentication using promiscuous data before accessing non-promiscuous data. This preliminary action establishes trust and authorization, ensuring that non-promiscuous data is only transmitted to authenticated readers. This resolves the contradiction by providing controlled access rather than complete restriction.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8322608B2Using promiscuous and non-promiscuous data to verify card and reader identity
Publication Date: 2012.12.04 ASSA ABLOY AB
  • US8322608B2 patent drawing
  • US8322608B2 patent drawing
  • US8322608B2 patent drawing

AI summary

A system and method for authenticating radio frequency identification (RFID) devices and validating readers of the RFID devices are disclosed. Embodiments of the invention use RFID devices adapted for storing data in a form of data segments selectively associated with promiscuous and non-promiscuous regions of their memories and monitor algorithmic, computational, communicational, or tampered errors of the readers.