RFID Tag One-Way Authentication via Blockchain and OTP Pad
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Low-power RFID tags lack the capability to perform complex cryptographic operations, making secure one-way authentication challenging, as they cannot digitally sign challenges and verify identities reliably without complex cryptography.
Innovation Solution
Implementing a one-time password pad and a blockchain system where the RFID reader writes and reads from the tag, using cryptographic hash functions to derive access keys and authenticate the tag's identity without requiring onboard complex cryptography, allowing the RFID reader to verify the tag's identity through a blockchain transaction.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If complex cryptographic operations such as digital signing are implemented on the RFID tag, then one-way authentication security is improved, but the device complexity and power consumption exceed the capabilities of low-power RFID tags
Solution Approach 1:
The patent extracts the complex cryptographic operations from the RFID tag and relocates them to the RFID reader. The tag only stores a simple identifier and performs minimal hash computations, while the reader handles digital signing, public key verification, and blockchain interactions. This extraction resolves the contradiction by maintaining security requirements while adapting to the tag's limited computational capabilities.
Solution Approach 2:
The patent introduces a blockchain as an intermediary layer between the RFID tag and the authentication system. The blockchain stores public keys and authentication records, allowing the tag to authenticate without directly performing complex cryptographic operations. The reader mediates between the tag's simple identifier and the blockchain's security requirements, resolving the capability gap.
2Ease of operation
If the RFID tag uses a simple identifier for identification, then ease of operation is improved, but security deteriorates because the identifier can be easily copied or cloned
Solution Approach 1:
The patent applies preliminary action by pre-provisioning each RFID tag with a unique identifier during manufacturing and pre-storing corresponding public keys in the blockchain. This allows the tag to maintain simplicity while the pre-established cryptographic infrastructure enables secure authentication. The security measures are prepared in advance rather than requiring complex operations during tag operation.
Solution Approach 2:
The patent uses cryptographic copying where the tag's simple identifier is transformed into a secure authentication credential through hash functions. The identifier itself remains simple and unchanged, but its cryptographic representation (hash value) provides security. This allows the tag to maintain operational simplicity while the copied/transformed version provides security.
3Reliability
If mutual authentication schemes are used, then authentication reliability is improved, but the RFID tag's power consumption and computational burden increase beyond what low-power tags can sustain
Solution Approach 1:
The patent implements asymmetric authentication where the tag and reader have different authentication responsibilities. The tag performs minimal hash computations on its identifier, while the reader performs digital signing and public key verification. This asymmetric division of labor maintains authentication reliability while adapting to the power and computational constraints of the low-power tag.
Solution Approach 2:
The authentication process is segmented into distinct phases: the tag segment performs simple identifier presentation and hash computation, while the reader segment handles complex cryptographic operations and blockchain interactions. This segmentation allows the tag to remain low-power while the overall system achieves high authentication reliability through the reader's capabilities.
Data Source
AI summary
A radio frequency identification device, or RFID tag, has an antenna attached to or formed on a microchip. The microchip usually comprises low power fixed or programmable logic and a small quantity of persistent memory. As many RFID tags are powered by radio waves transmitted from an RFID tag reader, the low power fixed or programmable logic is often not capable of performing complex cryptographic calculations required for digital signing to provide one-way authentication of the tag. In the present disclosure a system and method are presented for enabling a low overhead challenge and response using a one-time password pad comprising passwords on the RFID tag and a blockchain to record a use of the passwords. Methods are also disclosed for securely replacing the one-time password pad, and using the RFID tag in combination with a blockchain to provide provenance information for the RFID tag.


