RFID Tag Dynamic Challenge-Response Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current RFID technologies are susceptible to cloning and eavesdropping, which compromises their effectiveness in preventing counterfeiting and ensuring authenticity, particularly in the pharmaceutical and other high-value industries, due to their vulnerability to reverse-engineering and lack of secure access control.
Innovation Solution
A method and system that uses an RFID response means to generate a new trigger signal and response after being subjected to a current trigger signal, employing one-way hash functions and a cryptographic scheme to create one-time access passwords, ensuring that even if eavesdropped information is useless and preventing unauthorized cloning, while maintaining compatibility with existing RFID infrastructure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If RFID tags store and transmit identification information using standard protocols, then item identification and tracking can be performed efficiently, but the system becomes vulnerable to cloning and eavesdropping attacks
Solution Approach 1:
The patent implements dynamic challenge-response authentication where the RFID tag and reader engage in multiple challenge-response exchanges. Each challenge requires the tag to compute a response based on a secret key and the challenge value, ensuring that static identification data cannot be cloned. This dynamic interaction prevents replay attacks and cloning while maintaining efficient identification.
Solution Approach 2:
The system changes the authentication parameters by using cryptographic hash functions to generate unique challenge-response pairs. Instead of transmitting static identification data, the system uses variable challenge values that require computational processing, transforming the authentication mechanism from static to cryptographic, thereby preventing cloning while preserving identification efficiency.
2Device complexity
If RFID tags use simple identification protocols, then device complexity and cost are reduced, but security against reverse-engineering and cloning deteriorates
Solution Approach 1:
The patent introduces cryptographic hash functions as an intermediary mechanism between the simple RFID tag hardware and the security requirement. The tag contains a secret key that never leaves the tag, and all authentication is performed through hash-based challenge-response protocols. This intermediary cryptographic layer provides strong security without requiring complex hardware, maintaining simplicity while preventing cloning.
Solution Approach 2:
The system prevents copying by using one-way hash functions and secret keys that cannot be extracted from the tag. Even if an attacker obtains multiple challenge-response pairs, the one-way nature of the hash function makes it computationally infeasible to reverse-engineer the secret key or generate valid responses for new challenges, thus preventing cloning of the authentication mechanism.
3Adaptability or versatility
If RFID systems transmit identification data openly, then compatibility with existing infrastructure is maintained, but susceptibility to eavesdropping and unauthorized access increases
Solution Approach 1:
The patent replaces the traditional mechanical/open RFID communication model with a cryptographic substitution. Instead of openly transmitting identification data, the system uses cryptographic challenge-response protocols where no sensitive information is transmitted in clear text. This substitution maintains compatibility with existing RFID infrastructure while eliminating eavesdropping vulnerabilities through cryptographic protection.
Data Source
AI summary
Methods and devices for enabling a user to obtain item information relating to an item (10), the item having associated therewith an item identification means (12) and an RFID response means (14) arranged to provide a predetermined response on being subjected to a currently applicable trigger signal; the method comprising steps of: establishing from the item identification means (12) item identification information; using the item identification information to determine from an item information source (30) a currently applicable trigger signal for the RFID response means (14); subjecting the RFID response means (14) to the currently applicable trigger signal; receiving a predetermined response from the RFID response means (14); and using the predetermined response to obtain item information from the item information source (30); wherein the RFID response means (14) is arranged to generate a new currently applicable trigger signal and a new predetermined response associated therewith following subjecting of the RFID response means (14) to the currently applicable trigger signal.


