RFID Tag Authentication via Code Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

EPC tags lack explicit authentication functionality, making them vulnerable to counterfeiting and cloning attacks, and existing solutions require cryptographic operations that are resource-intensive and not feasible for all RFID devices.

Innovation Solution

The implementation of a code-based authentication system that uses valid and invalid codes to authenticate RFID devices, leveraging kill and access codes without the need for cryptographic operations, allowing RFID devices to confirm the validity of received codes and prevent cloning attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic operations are used for RFID device authentication, then authentication security is improved, but device complexity and resource consumption increase

Engineering Contradiction:
Improveauthentication securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into two parts: the RFID tag stores only a simple secret key, while the reader performs the complex cryptographic operations including hash function computations and authentication verification. This segmentation allows strong authentication security without requiring the tag to have high computational resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A challenge-response authentication protocol is introduced as an intermediary mechanism between the tag and reader. The reader sends a challenge, the tag responds using its secret key, and the reader verifies the response using hash functions. This intermediary protocol provides secure authentication without requiring complex cryptographic operations on the resource-constrained tag.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic operations are used for RFID device authentication, then authentication security is improved, but energy consumption increases

Engineering Contradiction:
Improveauthentication securityVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The computational workload is segmented such that the energy-intensive cryptographic operations (hash function computations, challenge-response verification) are performed by the reader which has sufficient power supply, while the tag only performs simple operations. This segmentation enables strong authentication security without excessive energy consumption on the tag side.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The reader serves itself by performing all complex authentication computations locally without requiring the tag to provide computational resources. The tag simply stores its secret key and participates in the challenge-response protocol, minimizing its energy consumption while maintaining authentication security.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If EPC tags emit EPC promiscuously to any querying reader, then ease of operation is improved, but vulnerability to counterfeiting increases

Engineering Contradiction:
Improveease of operationVSAvoidvulnerability to counterfeiting
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

Authentication is performed as a preliminary action before the tag emits its EPC. The reader first sends an authentication challenge, the tag responds using its secret key, and only after successful authentication does the tag emit its EPC. This preliminary authentication step prevents counterfeiting while maintaining ease of operation for legitimate readers.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback through the challenge-response protocol. The reader sends a challenge, the tag provides a response based on its secret key, and the reader verifies the response. This feedback mechanism allows the system to distinguish between legitimate and counterfeit tags, preventing counterfeiting while allowing promiscuous emission to legitimate readers.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7750793B2Methods and apparatus for RFID device authentication
Publication Date: 2010.07.06 EMC IP HLDG CO LLC
  • US7750793B2 patent drawing
  • US7750793B2 patent drawing
  • US7750793B2 patent drawing

AI summary

Methods and apparatus are disclosed for use in an RFID system comprising a plurality of RFID devices and at least one reader which communicates with one or more of the devices. In one aspect of the invention, an identifier transmitted by a given one of the RFID devices is received by a reader or by an associated verifier via the reader. At least first and second codes are determined, by the reader or verifier, with the first code being a valid code for the identifier, and the second code being an invalid code for the identifier. The reader, or verifier via the reader, communicates with the given device to determine if the device is able to confirm that the first code is a valid code and the second code is an invalid code.