RFID Tag Encryption for Building Control System Configuration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern building control systems face security vulnerabilities due to the exchange of configuration data between configuration devices and host devices, which can be accessed by unauthorized parties, leading to potential network breaches and control over the system.
Innovation Solution
A configuration method that encrypts and secures configuration data on radio frequency identification (RFID) tags, ensuring only authorized devices can access and modify the data, and includes measures like encryption, secure key exchange, and data deletion to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If configuration data is exchanged between configuration device and host device via RFID connection, then configuration operation can be performed, but unauthorized parties can access the configuration data and compromise system security
Solution Approach 1:
The patent applies preliminary action by encrypting the configuration data on the RFID tag before the configuration operation takes place. The encryption is performed in advance during manufacturing or initial setup, so that when the configuration device reads the data via RFID, it automatically receives encrypted content. This preliminary encryption step ensures that even if unauthorized parties intercept the RFID communication, they cannot access the plaintext configuration data without the decryption key.
Solution Approach 2:
The patent introduces an intermediary element - the encryption key - that mediates between the configuration data and any device attempting to access it. The configuration data is stored in encrypted form, and only the authorized configuration device possessing the correct decryption key can decrypt and use the data. This intermediary encryption mechanism blocks unauthorized access while allowing legitimate configuration operations to proceed.
2Adaptability or versatility
If network parameters are written to RFID tag by installation device, then host device can join network, but network parameters can be read by unauthorized persons and network security is compromised
Solution Approach 1:
The patent applies preliminary action by encrypting the network parameters on the RFID tag before the host device attempts to join the network. The encryption is performed in advance, so when the installation device writes network parameters to the RFID tag, they are stored in encrypted form. This ensures that even though the network parameters are accessible via RFID reading, they remain secure as unauthorized devices cannot decrypt them without the proper key.
Solution Approach 2:
The patent changes the state of the network parameters from plaintext to encrypted form. By transforming the network parameters into an encrypted state on the RFID tag, the system maintains the adaptability of network joining while improving reliability through enhanced security. The encrypted parameters can still be read and processed by authorized devices, but unauthorized reading becomes meaningless without decryption capability.
3Ease of operation
If RFID tag stores configuration data in plaintext, then configuration device can easily read and use the data, but malicious visitors can read and exploit the configuration data
Solution Approach 1:
The patent applies preliminary action by encrypting the configuration data on the RFID tag before any reading operation occurs. This encryption is performed in advance during manufacturing or initial configuration, so that when any device reads the RFID tag, it receives encrypted data rather than plaintext. This preliminary security measure ensures that even malicious visitors who can physically access and read the RFID tag cannot exploit the configuration data without the decryption key.
Solution Approach 2:
The patent converts the potential harm of RFID data readability into a benefit by using encryption. The fact that RFID data can be easily read is transformed from a security vulnerability into a secure feature - the readability is maintained for authorized devices that have the decryption key, while unauthorized reading becomes useless. The harmful potential of plaintext exposure is converted into the beneficial property of encrypted accessibility.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Enhances the security of configuration data, preventing unauthorized access and ensuring that only authorized devices can configure host devices, thereby protecting the integrity and security of the building control system.
Implementation Method 1
an authorized configuration device exchanges confidential configuration data with a radio frequency identification tag coupled to the host device
Data Source
AI summary
According to an aspect of the invention a configuration method for configuring a host device in a control system is conceived, in particular a building control system, wherein an authorized configuration device exchanges confidential configuration data with a radio frequency identification tag coupled to the host device, wherein, after the confidential configuration data have been exchanged and a corresponding configuration operation has been performed, access to the confidential configuration data by an unauthorized configuration device is precluded. According to further aspects of the invention a corresponding configuration device, a corresponding computer program product and a corresponding control system are conceived.


