RFID Tag Privacy Protection via Dynamic ID Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional RFID systems face issues in preventing the tracing of tag device distribution processes, as attackers can exploit hash values or privileged IDs to trace the history of communications and identify the tag device.

Innovation Solution

The implementation of a tag device with a confidential value memory that updates privileged information using a difficult-to-invert function, making it challenging for attackers to associate past and updated information, and an external updater system that changes privileged IDs, preventing tracing by third parties.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hash values are transmitted from tag devices to readers to prevent direct exposure of tag ID information, then information leakage to third parties is prevented, but the distribution process can still be traced by attackers who collect and analyze historical communication data

Engineering Contradiction:
Improveinformation securityVSAvoidtracing capability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies dynamics by making the privileged ID changeable rather than fixed. The tag device can update its privileged ID in response to reader requests, transforming the static identification mechanism into a dynamic one that prevents traceability while maintaining security

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of the privileged ID from a constant value to a variable value that can be updated. By changing the ID parameter dynamically, the system prevents attackers from establishing permanent tracking correlations while preserving information security

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If a fixed privileged ID is stored in the tag device to maintain consistent identification, then the tag device can be reliably identified, but the distribution process becomes traceable through historical data analysis

Engineering Contradiction:
Improveidentification accuracyVSAvoidtracing capability
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The system transitions from a static identification model to a dynamic one where the privileged ID can be updated. This allows the tag device to maintain reliable identification during each communication session while preventing long-term traceability through historical data

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements periodic action by allowing the privileged ID to be updated at specific intervals or in response to communication history. This periodic renewal of the identification parameter prevents accumulation of traceable patterns while maintaining identification functionality

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS7661132B2Tag privacy protection method, tag device, backend apparatus, updater, update solicitor and record medium carrying such programs in storage
Publication Date: 2010.02.09 NIPPON TELEGRAPH & TELEPHONE CORP
  • US7661132B2 patent drawing
  • US7661132B2 patent drawing
  • US7661132B2 patent drawing

AI summary

A tag device causes a second calculator to read a confidential value from a confidential value memory and to apply a second function F2 which disturbs a relationship between elements of a definition domain and a mapping thereof to generate tag output information. The tag device delivers the tag output information to a backend apparatus. Subsequently, a first calculator reads out at least part of elements of the confidential value from the confidential value memory, and applies a first function F1, an inverse image of which is difficult to obtain, and a result of such calculation is used to update a confidential value in the confidential value memory by overwriting.