RFID Tag Authentication via Code Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
EPC tags lack explicit authentication functionality, making them vulnerable to counterfeiting and cloning attacks, and existing solutions require cryptographic operations that are resource-intensive and not feasible for all RFID devices.
Innovation Solution
The implementation of a code-based authentication system that uses valid and invalid codes to authenticate RFID devices, leveraging kill and access codes without the need for cryptographic operations, allowing RFID devices to confirm the validity of received codes and prevent cloning attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic operations are used for RFID device authentication, then authentication security is improved, but device complexity and resource consumption increase
Solution Approach 1:
The authentication system is segmented into two parts: the RFID tag stores only a simple secret key, while the reader performs the complex cryptographic operations including hash function computations and authentication verification. This segmentation allows strong authentication security without requiring the tag to have high computational resources.
Solution Approach 2:
A challenge-response authentication protocol is introduced as an intermediary mechanism between the tag and reader. The reader sends a challenge, the tag responds using its secret key, and the reader verifies the response using hash functions. This intermediary protocol provides secure authentication without requiring complex cryptographic operations on the resource-constrained tag.
2Reliability
If cryptographic operations are used for RFID device authentication, then authentication security is improved, but energy consumption increases
Solution Approach 1:
The computational workload is segmented such that the energy-intensive cryptographic operations (hash function computations, challenge-response verification) are performed by the reader which has sufficient power supply, while the tag only performs simple operations. This segmentation enables strong authentication security without excessive energy consumption on the tag side.
Solution Approach 2:
The reader serves itself by performing all complex authentication computations locally without requiring the tag to provide computational resources. The tag simply stores its secret key and participates in the challenge-response protocol, minimizing its energy consumption while maintaining authentication security.
3Ease of operation
If EPC tags emit EPC promiscuously to any querying reader, then ease of operation is improved, but vulnerability to counterfeiting increases
Solution Approach 1:
Authentication is performed as a preliminary action before the tag emits its EPC. The reader first sends an authentication challenge, the tag responds using its secret key, and only after successful authentication does the tag emit its EPC. This preliminary authentication step prevents counterfeiting while maintaining ease of operation for legitimate readers.
Solution Approach 2:
The system implements feedback through the challenge-response protocol. The reader sends a challenge, the tag provides a response based on its secret key, and the reader verifies the response. This feedback mechanism allows the system to distinguish between legitimate and counterfeit tags, preventing counterfeiting while allowing promiscuous emission to legitimate readers.
Data Source
AI summary
Methods and apparatus are disclosed for use in an RFID system comprising a plurality of RFID devices and at least one reader which communicates with one or more of the devices. In one aspect of the invention, an identifier transmitted by a given one of the RFID devices is received by a reader or by an associated verifier via the reader. At least first and second codes are determined, by the reader or verifier, with the first code being a valid code for the identifier, and the second code being an invalid code for the identifier. The reader, or verifier via the reader, communicates with the given device to determine if the device is able to confirm that the first code is a valid code and the second code is an invalid code.


