RFID Mutual Authentication Using Dynamic Password Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

RFID tags used in sensitive applications such as identification cards and passports lack privacy features to prevent unauthorized access, as existing systems do not have methods to detect or prevent unwanted reading of information, especially with high potential read ranges.

Innovation Solution

A mutual authentication scheme between an RFID reader and tag is implemented, using a dynamically configurable pseudo-random sequence generator (PRSG) to change and synchronize password keys, ensuring secure data transfer and managing known secrets among server, interrogator, and tag, with the ability to adjust security levels and employ scrambling to enhance encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If RFID tags store additional data in writable non-volatile memory, then the utility and information storage capability are improved, but the security and privacy protection deteriorate because the data becomes accessible to unauthorized readers

Engineering Contradiction:
Improvedata storage capabilityVSAvoidunauthorized access
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authentication actions before allowing data access. The reader and tag perform mutual authentication exchanges before any data transfer, ensuring that only authorized parties can access the stored information. This preliminary security check prevents unauthorized reading of sensitive data while maintaining the tag's data storage capabilities.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces authentication protocols as an intermediary layer between the data storage function and the reading function. This intermediary authentication mechanism verifies the legitimacy of readers before allowing access to stored data, thus protecting the information while maintaining accessibility for authorized users.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If RFID tags have high read range capability, then the operational versatility is improved, but the privacy protection deteriorates because unauthorized reading becomes more likely

Engineering Contradiction:
Improveread rangeVSAvoidunauthorized reading
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by implementing authentication protocols that prevent unauthorized reading before it can occur. The mutual authentication process creates a security barrier that counteracts the vulnerability introduced by long read ranges, ensuring that even though tags can be read from distances, only authenticated readers can successfully access data.

Inventive Principle:
Principle #9Preliminary anti-action

3Ease of operation

If RFID systems use simple authentication, then the ease of operation is improved, but the security level deteriorates

Engineering Contradiction:
Improveauthentication processVSAvoidsecurity level
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent merges the authentication process with the existing RFID communication protocol, combining security functions with standard read/write operations. This integration allows authentication to occur seamlessly within the normal communication flow, maintaining ease of operation while implementing robust security measures through mutual authentication and encrypted data transfer.

Inventive Principle:
Principle #5Merging (Combining)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

The solution provides enhanced security by ensuring only authorized access to RFID data, maintaining password uniqueness, and increasing the difficulty of breaking encryption, thus protecting privacy and preventing unauthorized data access.

Implementation Method 1

Most RFID systems use a modulation technique known as backscatter to enable the tags to communicate with the reader or interrogator. In a backscatter system, the interrogator transmits a Radio Frequency (RF) carrier signal that is reflected by the RFID tag.

Methodology Applied
Scientific EffectBackscatter:

Implementation Method 2

Passive RFID tags have no internal power supply. The minute electrical current induced in the antenna by the incoming RF signal from the interrogator provides just enough power for the, e.g., CMOS integrated circuit in the tag to power up and transmit a response.

Methodology Applied
Scientific EffectElectromagnetic induction: Electromagnetic Induction

Data Source

PatentUS8681987B2RFID authentication architecture and methods for RFID authentication
Publication Date: 2014.03.25 SMART COSMOS SOLUTIONS INC
  • US8681987B2 patent drawing
  • US8681987B2 patent drawing
  • US8681987B2 patent drawing

AI summary

A method for mutual authentication in an RFID system comprising an RFID reader and an RFID tag, the method comprising requesting an identification from the tag, receiving the identification, using the received identification to select a password associated with the identification, generating a password key based on the selected password, encrypting the selected password using the password key, and transmitting the encrypted password to the tag.