RFID Tag One-Way Authentication via Blockchain and OTP Pad

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Low-power RFID tags lack the capability to perform complex cryptographic operations, making secure one-way authentication challenging, as they cannot digitally sign challenges and verify identities reliably without complex cryptography.

Innovation Solution

Implementing a one-time password pad and a blockchain system where the RFID reader writes and reads from the tag, using cryptographic hash functions to derive access keys and authenticate the tag's identity without requiring onboard complex cryptography, allowing the RFID reader to verify the tag's identity through a blockchain transaction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If complex cryptographic operations such as digital signing are implemented on the RFID tag, then one-way authentication security is improved, but the device complexity and power consumption exceed the capabilities of low-power RFID tags

Engineering Contradiction:
Improveauthentication securityVSAvoidcryptographic computation capability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex cryptographic operations from the RFID tag and relocates them to the RFID reader. The tag only stores a simple identifier and performs minimal hash computations, while the reader handles digital signing, public key verification, and blockchain interactions. This extraction resolves the contradiction by maintaining security requirements while adapting to the tag's limited computational capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a blockchain as an intermediary layer between the RFID tag and the authentication system. The blockchain stores public keys and authentication records, allowing the tag to authenticate without directly performing complex cryptographic operations. The reader mediates between the tag's simple identifier and the blockchain's security requirements, resolving the capability gap.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the RFID tag uses a simple identifier for identification, then ease of operation is improved, but security deteriorates because the identifier can be easily copied or cloned

Engineering Contradiction:
Improveidentification simplicityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-provisioning each RFID tag with a unique identifier during manufacturing and pre-storing corresponding public keys in the blockchain. This allows the tag to maintain simplicity while the pre-established cryptographic infrastructure enables secure authentication. The security measures are prepared in advance rather than requiring complex operations during tag operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses cryptographic copying where the tag's simple identifier is transformed into a secure authentication credential through hash functions. The identifier itself remains simple and unchanged, but its cryptographic representation (hash value) provides security. This allows the tag to maintain operational simplicity while the copied/transformed version provides security.

Inventive Principle:
Principle #26Copying

3Reliability

If mutual authentication schemes are used, then authentication reliability is improved, but the RFID tag's power consumption and computational burden increase beyond what low-power tags can sustain

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidtag power consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements asymmetric authentication where the tag and reader have different authentication responsibilities. The tag performs minimal hash computations on its identifier, while the reader performs digital signing and public key verification. This asymmetric division of labor maintains authentication reliability while adapting to the power and computational constraints of the low-power tag.

Inventive Principle:
Principle #4Asymmetry

Solution Approach 2:

The authentication process is segmented into distinct phases: the tag segment performs simple identifier presentation and hash computation, while the reader segment handles complex cryptographic operations and blockchain interactions. This segmentation allows the tag to remain low-power while the overall system achieves high authentication reliability through the reader's capabilities.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10938579B2Radio frequency identification tag one-way authentication using a one-time password pad and a blockchain
Publication Date: 2021.03.02 FINLOW BATES KEIR
  • US10938579B2 patent drawing
  • US10938579B2 patent drawing
  • US10938579B2 patent drawing

AI summary

A radio frequency identification device, or RFID tag, has an antenna attached to or formed on a microchip. The microchip usually comprises low power fixed or programmable logic and a small quantity of persistent memory. As many RFID tags are powered by radio waves transmitted from an RFID tag reader, the low power fixed or programmable logic is often not capable of performing complex cryptographic calculations required for digital signing to provide one-way authentication of the tag. In the present disclosure a system and method are presented for enabling a low overhead challenge and response using a one-time password pad comprising passwords on the RFID tag and a blockchain to record a use of the passwords. Methods are also disclosed for securely replacing the one-time password pad, and using the RFID tag in combination with a blockchain to provide provenance information for the RFID tag.