RFID Tag Verification Using Sealed TPM Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing RFID-based supply chain verification systems, particularly those using e-pedigree and discovery services, face challenges in maintaining confidentiality and are vulnerable to disruptions due to reliance on centralized resources, requiring entities to share sensitive information and risking service disruptions when central resources are unavailable.
Innovation Solution
A verification apparatus and system utilizing sealed storage for private and public keys, protected by a Trusted Platform Module, which encrypts and decrypts signatures on RFID tags, allowing entities to verify authenticity without sharing confidential information and minimizing reliance on centralized resources, ensuring resilience and low vulnerability to single-point failures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If e-pedigree and discovery service approaches are used to enable end-to-end visibility of information across different entities, then information accessibility is improved, but confidentiality of sensitive information is compromised and vulnerability to centralized resource failures increases
Solution Approach 1:
The system segments the centralized e-pedigree information into distributed fragments stored locally at each entity. Each entity maintains its own portion of the pedigree information independently, eliminating the single point of failure while preserving information accessibility through local storage and verification.
Solution Approach 2:
The invention extracts sensitive confidential information from the centralized discovery service and e-pedigree database, placing it into sealed storage within each entity's verification apparatus. This extraction removes the vulnerability to centralized resource failures while maintaining the ability to verify information locally.
2Measurement precision
If centralized EPC information services and discovery services are used to validate e-pedigree information, then verification capability is improved, but service disruption risk increases when central resources are unavailable
Solution Approach 1:
The system performs preliminary action by pre-storing fragments of e-pedigree information and verification keys in sealed storage at each entity before verification is needed. This allows verification to proceed using locally stored information without requiring real-time access to centralized resources, ensuring service continuity.
Solution Approach 2:
The invention creates copies of essential verification data (e-pedigree fragments, public keys, policies) and distributes them to each entity's sealed storage. These copies enable independent verification without relying on the original centralized database, maintaining verification capability even when central resources are unavailable.
3Loss of information
If entities publish and access e-pedigree information through centralized EPC information services, then information sharing is improved, but information security and confidentiality are compromised
Solution Approach 1:
The system segments e-pedigree information into distributed fragments that are stored locally at each entity rather than publishing complete information centrally. This segmentation allows necessary information sharing for verification while preventing unauthorized access to complete sensitive data, thereby improving information security.
Solution Approach 2:
The invention introduces sealed storage as an intermediary layer between information sharing and confidentiality protection. The sealed storage mechanism enables entities to share verification information while maintaining confidentiality of sensitive data, acting as a mediator that reconciles the conflicting requirements of information sharing and security.
Data Source
AI summary
Apparatus and system for verifying a route taken during movement of an RFID tag, comprising a trusted platform module; sealed storage (80) comprising one or more stores (50, 52) for storing a public key (64), a private key (68) and a policy (62); and processors arranged to: receive data (60) read-out from the RFID tag (4) and comprising an RFID tag identity and an encrypted signature (9); use the public key (64) to decrypt the encrypted signature (9); verify that the decrypted signature (9) corresponds to a first entity from which, according to the policy (62), a second entity is authorised to receive the given RFID tag (4); use the private key (68) to provide an encrypted signature (9); and forward data comprising the encrypted signature (9) to an RFID tag writer (22).


