RFID Tag Secure Service Access via NFC Key Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies lack a secure and efficient method for an RFID tag to access a service with an access terminal using a cryptographic key, especially when the NFC phone is not operational, and existing solutions are vulnerable to physical and software attacks.

Innovation Solution

An RFID tag with an integrated circuit that enables cryptographic authentication and key updates using an NFC phone, allowing secure access to services even when the phone is off, with key updates managed through the ISO 15693-3 standard, ensuring secure storage and communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the cryptography key is stored in the smart card or SIM card of the phone, then secure storage against physical and side channel attacks is achieved, but the phone cannot be used passively when switched off or running out of battery

Engineering Contradiction:
Improvesecurity of cryptography key storageVSAvoidpassive use of phone
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The invention extracts the cryptography key storage function from the phone's smart card/SIM card and relocates it to the RFID tag. This allows the RFID tag to store and use the key independently, enabling passive operation without requiring the phone to be on or have battery power, while maintaining security through the RFID tag's secure storage capabilities

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of operation

If the cryptography key is stored in the application or TEE processor, then the phone can be used passively, but the storage is exposed to software attacks such as reverse engineering, buffer overflow, malware, and viruses

Engineering Contradiction:
Improvepassive use of phoneVSAvoidsoftware attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The invention extracts the cryptography key storage from the phone's application or TEE processor and moves it to the RFID tag. This physical separation removes the key from the vulnerable software environment, protecting it from reverse engineering, buffer overflow, malware, and viruses while enabling passive operation

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The RFID tag acts as an intermediary between the phone and the access terminal. It stores the cryptography key securely and facilitates authentication without requiring the key to reside in the phone's vulnerable software environment, thus mediating the security issue

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the NFC phone is required for authentication and key updates, then secure access is maintained, but the system becomes dependent on the phone's operational status

Engineering Contradiction:
Improvesecure accessVSAvoidsystem dependency on phone
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The RFID tag is designed to perform authentication and key updates autonomously using the phone's NFC capabilities when available, but can also operate independently when the phone is not operational. The tag maintains its own authentication functionality and key storage, making the system adaptable to phone availability status

Inventive Principle:
Principle #25Self-service

4Reliability

If frequent key updates are performed to counter physical vulnerabilities, then security is improved, but the complexity of key management increases

Engineering Contradiction:
Improvesecurity against physical attacksVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The RFID tag autonomously manages its own key updates by receiving updated keys from the phone via NFC when available. This self-service approach simplifies key management complexity by eliminating the need for manual intervention or complex management systems, while still enabling frequent updates to maintain security

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3468143B1RFID tag for securely accessing a service from an access terminal
Publication Date: 2020.07.15 COMMISSARIAT A LENERGIE ATOMIQUE ET AUX ENERGIES ALTERNATIVES
  • EP3468143B1 patent drawingFigure 1~2
  • EP3468143B1 patent drawingFigure 3~4
  • EP3468143B1 patent drawingFigure 5~6

AI summary

The invention relates to an RFID tag adapted to access a service of interest from an access terminal, said RFID tag (1) comprising an integrated circuit (3) configured to: - allow cryptographic authentication of the RFID tag (1) by said access terminal (7) via a current cryptographic key shared by the RFID tag (1) and the access terminal (7), said authentication allowing access to said service of interest, and - allow the RFID tag (1) to retrieve a new current cryptographic key updated by an NFC phone after authentication of the RFID tag (1) by said NFC phone via an initial cryptographic key previously shared by the RFID tag (1) and said phone.