RFID Tag Authentication via Verification Authority

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

RFID systems face challenges in authenticating the legitimacy of RFID tags and verification authorities, particularly in preventing counterfeiting, as existing methods lack robust verification mechanisms to ensure the authenticity of tags and communication integrity.

Innovation Solution

Implementing a challenge-response authentication protocol between RFID readers and tags, where the reader verifies the tag's response with a verification authority, and also authenticates the authority itself, using cryptographic algorithms and electronic signatures to ensure the authenticity of both the tag and the communication channel.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional RFID authentication methods are used, then the system is simpler to operate, but the security and reliability against counterfeiting deteriorates

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A verification authority is introduced as an intermediary between the RFID reader and tag. The verification authority receives authentication requests from the reader, verifies the tag's responses using cryptographic algorithms, and returns verification results. This mediator enables robust authentication without requiring the reader or tag to independently perform complex verification operations, thus improving reliability while managing complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is divided into distinct functional components: the RFID reader that initiates authentication, the tag that responds to challenges, and the verification authority that performs cryptographic verification. This segmentation allows each component to have specialized, optimized functionality, improving overall system reliability while distributing complexity across multiple entities.

Inventive Principle:
Principle #1Segmentation

2Reliability

If cryptographic verification mechanisms are implemented, then the security against counterfeiting is improved, but the communication complexity increases

Engineering Contradiction:
Improvecommunication securityVSAvoidcommunication protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Cryptographic keys and verification credentials are pre-configured in the tag and verification authority during manufacturing or initial setup. This preliminary action ensures that security credentials are already in place before authentication occurs, eliminating the need for complex key exchange protocols during operation and reducing communication complexity while maintaining high security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If mutual authentication between reader and verification authority is implemented, then the security against illegitimate authorities is improved, but the authentication time increases

Engineering Contradiction:
Improveauthority authenticationVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The verification authority's credentials are pre-configured in the RFID reader during system initialization or manufacturing. This preliminary configuration allows the reader to immediately verify the authority's identity without requiring time-consuming authentication protocols during tag verification operations, thus reducing authentication time while maintaining security against illegitimate authorities.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9501675B1RFID tag and reader authentication by trusted authority
Publication Date: 2016.11.22 IMPINJ
  • US9501675B1 patent drawing
  • US9501675B1 patent drawing
  • US9501675B1 patent drawing

AI summary

A Radio Frequency Identification (RFID) reader containing a reader key authenticates an RFID tag containing a tag key by receiving a tag identifier from the tag; challenging the tag with a tag challenge; receiving a tag response based at least on the tag challenge and the tag key but not including the tag key; sending a second message including at least the tag identifier and the tag response to a verification authority; and receiving a reply from the verification authority. The reader and the verification authority may mutually authenticate each other before, during, or after the tag authentication process. The verification authority may notify a designated party if a response is incorrect.