RFID Tag Secure Service Access via NFC Key Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies lack a secure and efficient method for an RFID tag to access a service with an access terminal using a cryptographic key, especially when the NFC phone is not operational, and existing solutions are vulnerable to physical and software attacks.
Innovation Solution
An RFID tag with an integrated circuit that enables cryptographic authentication and key updates using an NFC phone, allowing secure access to services even when the phone is off, with key updates managed through the ISO 15693-3 standard, ensuring secure storage and communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the cryptography key is stored in the smart card or SIM card of the phone, then secure storage against physical and side channel attacks is achieved, but the phone cannot be used passively when switched off or running out of battery
Solution Approach 1:
The invention extracts the cryptography key storage function from the phone's smart card/SIM card and relocates it to the RFID tag. This allows the RFID tag to store and use the key independently, enabling passive operation without requiring the phone to be on or have battery power, while maintaining security through the RFID tag's secure storage capabilities
2Ease of operation
If the cryptography key is stored in the application or TEE processor, then the phone can be used passively, but the storage is exposed to software attacks such as reverse engineering, buffer overflow, malware, and viruses
Solution Approach 1:
The invention extracts the cryptography key storage from the phone's application or TEE processor and moves it to the RFID tag. This physical separation removes the key from the vulnerable software environment, protecting it from reverse engineering, buffer overflow, malware, and viruses while enabling passive operation
Solution Approach 2:
The RFID tag acts as an intermediary between the phone and the access terminal. It stores the cryptography key securely and facilitates authentication without requiring the key to reside in the phone's vulnerable software environment, thus mediating the security issue
3Reliability
If the NFC phone is required for authentication and key updates, then secure access is maintained, but the system becomes dependent on the phone's operational status
Solution Approach 1:
The RFID tag is designed to perform authentication and key updates autonomously using the phone's NFC capabilities when available, but can also operate independently when the phone is not operational. The tag maintains its own authentication functionality and key storage, making the system adaptable to phone availability status
4Reliability
If frequent key updates are performed to counter physical vulnerabilities, then security is improved, but the complexity of key management increases
Solution Approach 1:
The RFID tag autonomously manages its own key updates by receiving updated keys from the phone via NFC when available. This self-service approach simplifies key management complexity by eliminating the need for manual intervention or complex management systems, while still enabling frequent updates to maintain security
Data Source
Figure 1~2
Figure 3~4
Figure 5~6
AI summary
The invention relates to an RFID tag adapted to access a service of interest from an access terminal, said RFID tag (1) comprising an integrated circuit (3) configured to: - allow cryptographic authentication of the RFID tag (1) by said access terminal (7) via a current cryptographic key shared by the RFID tag (1) and the access terminal (7), said authentication allowing access to said service of interest, and - allow the RFID tag (1) to retrieve a new current cryptographic key updated by an NFC phone after authentication of the RFID tag (1) by said NFC phone via an initial cryptographic key previously shared by the RFID tag (1) and said phone.