RFID Tag Verification Using Sealed TPM Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing RFID-based supply chain verification systems, particularly those using e-pedigree and discovery services, face challenges in maintaining confidentiality and are vulnerable to disruptions due to reliance on centralized resources, requiring entities to share sensitive information and risking service disruptions when central resources are unavailable.

Innovation Solution

A verification apparatus and system utilizing sealed storage for private and public keys, protected by a Trusted Platform Module, which encrypts and decrypts signatures on RFID tags, allowing entities to verify authenticity without sharing confidential information and minimizing reliance on centralized resources, ensuring resilience and low vulnerability to single-point failures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If e-pedigree and discovery service approaches are used to enable end-to-end visibility of information across different entities, then information accessibility is improved, but confidentiality of sensitive information is compromised and vulnerability to centralized resource failures increases

Engineering Contradiction:
Improveinformation accessibilityVSAvoidconfidentiality and service continuity
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The system segments the centralized e-pedigree information into distributed fragments stored locally at each entity. Each entity maintains its own portion of the pedigree information independently, eliminating the single point of failure while preserving information accessibility through local storage and verification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention extracts sensitive confidential information from the centralized discovery service and e-pedigree database, placing it into sealed storage within each entity's verification apparatus. This extraction removes the vulnerability to centralized resource failures while maintaining the ability to verify information locally.

Inventive Principle:
Principle #2Taking out (Extraction)

2Measurement precision

If centralized EPC information services and discovery services are used to validate e-pedigree information, then verification capability is improved, but service disruption risk increases when central resources are unavailable

Engineering Contradiction:
Improveverification capabilityVSAvoidservice continuity
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system performs preliminary action by pre-storing fragments of e-pedigree information and verification keys in sealed storage at each entity before verification is needed. This allows verification to proceed using locally stored information without requiring real-time access to centralized resources, ensuring service continuity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention creates copies of essential verification data (e-pedigree fragments, public keys, policies) and distributes them to each entity's sealed storage. These copies enable independent verification without relying on the original centralized database, maintaining verification capability even when central resources are unavailable.

Inventive Principle:
Principle #26Copying

3Loss of information

If entities publish and access e-pedigree information through centralized EPC information services, then information sharing is improved, but information security and confidentiality are compromised

Engineering Contradiction:
Improveinformation sharingVSAvoidinformation security risk
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The system segments e-pedigree information into distributed fragments that are stored locally at each entity rather than publishing complete information centrally. This segmentation allows necessary information sharing for verification while preventing unauthorized access to complete sensitive data, thereby improving information security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention introduces sealed storage as an intermediary layer between information sharing and confidentiality protection. The sealed storage mechanism enables entities to share verification information while maintaining confidentiality of sensitive data, acting as a mediator that reconciles the conflicting requirements of information sharing and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2122902B1Verification of movement of items
Publication Date: 2016.12.28 BRITISH TELECOM PLC
  • EP2122902B1 patent drawing
  • EP2122902B1 patent drawing
  • EP2122902B1 patent drawing

AI summary

Apparatus and system for verifying a route taken during movement of an RFID tag, comprising a trusted platform module; sealed storage (80) comprising one or more stores (50, 52) for storing a public key (64), a private key (68) and a policy (62); and processors arranged to: receive data (60) read-out from the RFID tag (4) and comprising an RFID tag identity and an encrypted signature (9); use the public key (64) to decrypt the encrypted signature (9); verify that the decrypted signature (9) corresponds to a first entity from which, according to the policy (62), a second entity is authorised to receive the given RFID tag (4); use the private key (68) to provide an encrypted signature (9); and forward data comprising the encrypted signature (9) to an RFID tag writer (22).