RFID Tag Authentication via Reader-Tag Cryptographic Protocol

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional EPC RFID tags lack explicit authentication mechanisms, making them vulnerable to counterfeiting and cloning attacks, and existing security features are not adequately supported in the EPCglobal Class-1 Gen-2 standard, limiting their ability to resist eavesdropping and other attacks.

Innovation Solution

Implementing a cryptographic protocol using standard-compliant read and write commands, such as BlockWrite and Read, to facilitate challenge-response authentication between RFID devices and readers, which includes using one-time passwords generated by the device based on internal elements like a real-time clock, and optionally compressing command structures to reduce overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic authentication protocols are implemented in EPC tags, then security and authentication capability are improved, but device complexity and cost increase

Engineering Contradiction:
Improveauthentication capabilityVSAvoidtag complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses the reader as an intermediary to perform cryptographic operations that would otherwise require tag resources. The reader generates challenges and processes responses, allowing the tag to authenticate without having full cryptographic functionality embedded, thus reducing tag complexity while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The implementation uses lightweight cryptographic functions and selective authentication mechanisms rather than full cryptographic suites. This partial implementation provides sufficient security for the application while minimizing the complexity and resource requirements of the tag

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If cryptographic operations are added to EPC tags, then resistance to counterfeiting and eavesdropping is improved, but manufacturing cost increases

Engineering Contradiction:
Improveresistance to counterfeitingVSAvoidmanufacturing cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

By offloading cryptographic processing to the reader (intermediary), the tag requires minimal cryptographic hardware, keeping manufacturing costs low while still achieving strong authentication and protection against counterfeiting through the collaborative reader-tag protocol

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The reader is designed to handle multiple functions including cryptographic operations for multiple tags, making the system cost-effective by concentrating expensive cryptographic capabilities in the reader rather than duplicating them in every tag

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If authentication mechanisms are integrated into Class-1 Gen-2 EPC tags, then security against cloning attacks is improved, but compatibility with existing standards may be compromised

Engineering Contradiction:
Improveresistance to cloning attacksVSAvoidstandard compliance
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The authentication protocol is designed to be dynamically compatible with Class-1 Gen-2 standards, allowing tags to operate in both authenticated and non-authenticated modes depending on reader capabilities and application requirements, thus maintaining standard compliance while providing enhanced security when needed

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The authentication functionality is segmented as an optional enhancement rather than a mandatory requirement, allowing the system to maintain compatibility with basic Class-1 Gen-2 tags while providing advanced authentication capabilities when the reader and application require them

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8378786B2Security provision in standards-compliant RFID systems
Publication Date: 2013.02.19 EMC IP HLDG CO LLC
  • US8378786B2 patent drawing
  • US8378786B2 patent drawing
  • US8378786B2 patent drawing

AI summary

Enhanced security is provided in an RFID system comprising a plurality of RFID devices and at least one reader which communicates with one or more of the devices. In one aspect of the invention, a first command is transmitted from the reader to write a first data unit to a memory of given one of the RFID devices. A reply is received in the reader from the given RFID device indicating that a second data unit determined based on contents of the first data unit is available in the memory to be accessed by the reader. A second command is transmitted from the reader to the given RFID device to allow the reader to read the memory to thereby obtain the second data unit. The first and second data units comprise information exchanged as part of a cryptographic protocol carried out between the reader and the given RFID device. In an illustrative embodiment, the cryptographic protocol may comprise a challenge-response authentication protocol.