RFID Tag Authentication via Intermediary Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

RFID systems used in product distribution chains lack secure authentication and encryption capabilities, making it difficult for manufacturers to manage and secure transactions effectively due to limited processing power and unauthorized access to sensitive information.

Innovation Solution

An integrated circuit with an RF transceiver, hidden memory for authentication messages, and user memory for readable information, utilizing cryptographic processes to authenticate transactions without requiring significant processing power, allowing for secure actions like activation or deactivation of products.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic processes are implemented in RFID tags, then security is improved, but processing power requirements increase beyond what low-power tags can provide

Engineering Contradiction:
Improvetransaction securityVSAvoidprocessing power requirement
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The patent introduces an intermediary authentication server that performs the computationally intensive cryptographic operations. The RFID tag only needs to perform simple operations (reading authentication information, comparing authentication results) while the server handles the complex encryption/decryption and key management, thus resolving the contradiction between security requirements and tag processing limitations

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication system is segmented into two parts: lightweight authentication information storage in the RFID tag, and heavy cryptographic processing in the external authentication server. This segmentation allows the tag to remain low-power while the system as a whole achieves high security through the server's computational capabilities

Inventive Principle:
Principle #1Segmentation

2Reliability

If more information is stored on RFID tags, then authentication capability is improved, but vulnerability to unauthorized access increases

Engineering Contradiction:
Improveauthentication capabilityVSAvoidunauthorized access risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The authentication server acts as an intermediary that securely manages sensitive cryptographic keys and authentication data. Instead of storing all authentication information in the vulnerable RFID tag, the tag only stores encrypted authentication information that is useless without the corresponding decryption keys held securely by the server, thus improving authentication capability while mitigating unauthorized access risk

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Different types of information are stored in different locations with different security characteristics: authentication information (encrypted) is stored in the RFID tag for portability, while decryption keys and sensitive cryptographic data are stored in the secure authentication server, creating a distributed security architecture that balances accessibility and protection

Inventive Principle:
Principle #3Local quality

3Use of energy by moving object

If RFID tags operate with limited power, then energy consumption is reduced, but computational capability decreases

Engineering Contradiction:
Improveenergy consumptionVSAvoidcomputational capability
Core Design Contradiction:
Use of energy by moving objectVSProductivity

Solution Approach 1:

The authentication server serves as an external computational resource that the low-power RFID tag can leverage. The tag performs only minimal local processing (reading stored authentication information and comparing results) while delegating all computationally intensive cryptographic operations to the powered server, thus maintaining low energy consumption while achieving high computational capability through the intermediary

Inventive Principle:
Principle #24Intermediary (Mediator)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enables highly secure and authenticated transactions even in low-power environments, enabling manufacturers to enforce distribution and use rules, and secure sensitive information within RFID systems.

Implementation Method 1

An RF transceiver in the integrated circuit is capable of establishing communication with an associated reading device

Methodology Applied
Scientific EffectElectromagnetic radiation: Electromagnetic Induction

Data Source

PatentUS7273181B2Device and method for authenticating and securing transactions using RF communication
Publication Date: 2007.09.25 QUOTAINNE ENTERPRISES LLC
  • US7273181B2 patent drawing
  • US7273181B2 patent drawing
  • US7273181B2 patent drawing

AI summary

A system is provided for authenticating and securing product transactions. An integrated circuit is attached to a target, such as an optical disc or electronic device. The integrated circuit has an RF transceiver that is capable of establishing communication with an associated reading device. The integrated circuit also has a hidden memory, which can not be read externally, and a user memory. The hidden memory stores an authentication message, while the user memory stores readable authentication information. The hidden authentication message and the authentication information are related through a cryptographic process. However, even though the integrated circuit benefits from the cryptographic security, the integrated circuit only operates relatively simple logic operations. In this way, a highly secure transaction is enabled without requiring significant processing power or time at the integrated circuit. When the integrated circuit is placed near the reader, the reader reads the authentication information, and with the cooperation of a network operation center, uses the authentication information to derive an activation code. The reader passes the activation code to the integrated circuit, which compares the activation code to its hidden activation message. If they have a proper relationship, the communication has been authenticated, and the integrated circuit proceeds to perform an action.