RFID Tag Authentication via Intermediary Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
RFID systems used in product distribution chains lack secure authentication and encryption capabilities, making it difficult for manufacturers to manage and secure transactions effectively due to limited processing power and unauthorized access to sensitive information.
Innovation Solution
An integrated circuit with an RF transceiver, hidden memory for authentication messages, and user memory for readable information, utilizing cryptographic processes to authenticate transactions without requiring significant processing power, allowing for secure actions like activation or deactivation of products.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic processes are implemented in RFID tags, then security is improved, but processing power requirements increase beyond what low-power tags can provide
Solution Approach 1:
The patent introduces an intermediary authentication server that performs the computationally intensive cryptographic operations. The RFID tag only needs to perform simple operations (reading authentication information, comparing authentication results) while the server handles the complex encryption/decryption and key management, thus resolving the contradiction between security requirements and tag processing limitations
Solution Approach 2:
The authentication system is segmented into two parts: lightweight authentication information storage in the RFID tag, and heavy cryptographic processing in the external authentication server. This segmentation allows the tag to remain low-power while the system as a whole achieves high security through the server's computational capabilities
2Reliability
If more information is stored on RFID tags, then authentication capability is improved, but vulnerability to unauthorized access increases
Solution Approach 1:
The authentication server acts as an intermediary that securely manages sensitive cryptographic keys and authentication data. Instead of storing all authentication information in the vulnerable RFID tag, the tag only stores encrypted authentication information that is useless without the corresponding decryption keys held securely by the server, thus improving authentication capability while mitigating unauthorized access risk
Solution Approach 2:
Different types of information are stored in different locations with different security characteristics: authentication information (encrypted) is stored in the RFID tag for portability, while decryption keys and sensitive cryptographic data are stored in the secure authentication server, creating a distributed security architecture that balances accessibility and protection
3Use of energy by moving object
If RFID tags operate with limited power, then energy consumption is reduced, but computational capability decreases
Solution Approach 1:
The authentication server serves as an external computational resource that the low-power RFID tag can leverage. The tag performs only minimal local processing (reading stored authentication information and comparing results) while delegating all computationally intensive cryptographic operations to the powered server, thus maintaining low energy consumption while achieving high computational capability through the intermediary
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enables highly secure and authenticated transactions even in low-power environments, enabling manufacturers to enforce distribution and use rules, and secure sensitive information within RFID systems.
Implementation Method 1
An RF transceiver in the integrated circuit is capable of establishing communication with an associated reading device
Data Source
AI summary
A system is provided for authenticating and securing product transactions. An integrated circuit is attached to a target, such as an optical disc or electronic device. The integrated circuit has an RF transceiver that is capable of establishing communication with an associated reading device. The integrated circuit also has a hidden memory, which can not be read externally, and a user memory. The hidden memory stores an authentication message, while the user memory stores readable authentication information. The hidden authentication message and the authentication information are related through a cryptographic process. However, even though the integrated circuit benefits from the cryptographic security, the integrated circuit only operates relatively simple logic operations. In this way, a highly secure transaction is enabled without requiring significant processing power or time at the integrated circuit. When the integrated circuit is placed near the reader, the reader reads the authentication information, and with the cooperation of a network operation center, uses the authentication information to derive an activation code. The reader passes the activation code to the integrated circuit, which compares the activation code to its hidden activation message. If they have a proper relationship, the communication has been authenticated, and the integrated circuit proceeds to perform an action.


