RFID Tag Reader Authentication via Inverted Coupon Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing RFID authentication methods are vulnerable to denial of service attacks and do not effectively protect the transmission of sensitive information between radio tags and readers, particularly in constrained devices with limited resources.
Innovation Solution
A method that authenticates a reader to a radio tag using encrypted information and a reversible operation parameterized by the reader's authentication coupon, allowing for secure channel establishment and verification of the reader's authenticity, while also enabling secure transmission of sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the reader retrieves information from the tag spontaneously during authentication, then the authentication process can be completed, but the tag becomes vulnerable to denial of service attacks and exhaustion of authentication resources
Solution Approach 1:
The patent applies preliminary action by having the tag authenticate the reader before the reader authenticates the tag. The tag verifies the reader's authentication coupon in advance, ensuring that only legitimate readers can proceed with authentication. This prevents malicious readers from exhausting tag resources through spontaneous information retrieval attacks, as the tag controls the authentication flow and can reject unauthorized readers before any resource-consuming operations occur.
2Productivity
If the reader and tag transmit information in clear after mutual authentication, then communication is simple and fast, but sensitive information can be intercepted by malicious persons
Solution Approach 1:
The patent applies parameter changes by dynamically switching between clear text transmission and encrypted transmission based on the authentication state. After successful mutual authentication, the system can establish a secure channel using the authenticated credentials to encrypt subsequent communications. This allows the system to maintain fast clear text communication during authentication while protecting sensitive information transmission through encryption when required, thus adapting the transmission parameter to the security context.
3Reliability
If the tag implements additional authentication mechanisms to verify reader authenticity, then security against denial of service attacks is improved, but the complexity of the authentication protocol increases
Solution Approach 1:
The patent applies inversion by reversing the traditional authentication flow where the reader authenticates the tag. Instead, the tag authenticates the reader first by verifying the reader's authentication coupon against pre-stored coupons. This inverted approach enhances security against denial of service attacks because the tag, not the reader, controls the authentication process. The complexity increase is minimal as it primarily involves the tag storing and comparing authentication coupons, which is a straightforward cryptographic operation.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
The invention relates to a method for authenticating a reader (R) with a radio tag (T), including the following operations, performed by the tag: a step (E21-6) of receiving encrypted information (zeta,) using a reversible operation (REV), parameterised by an authentication token (t,) of the reader, and data for determining an identification index (j) of the authentication token of the reader; an operation (E21-7) of calculating a current reader-authenticating token (t,-') in accordance with the index (j); an operation (E21-8) of decrypting the received information encrypted using the reversible operation, parameterised by the calculated current authentication token; and an operation (E21-9) of checking the decrypted information in order to verify that the calculated current token corresponds to the authentication token used by the reader in order to parameterise the reversible operation.