RFID Tag Authorization via Ownership Code and Digital Signature
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current RFID systems for loss prevention in retail environments face challenges in efficiently authenticating items to prevent unauthorized removal, particularly due to complexities in database management and susceptibility to unauthorized access, and difficulties in distinguishing between foreign and stolen tags.
Innovation Solution
Implementing an RFID system where an ownership code associated with a facility is stored in the tag, and a digital signature is written based on item identifier, temporal parameters, and a secret key, allowing authorized items to be verified for legitimate exit using a public key verification process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a store database maintains information about all items and checks approval, then item authorization can be verified, but system complexity and cost increase significantly
Solution Approach 1:
The patent extracts the authorization data from the central database and embeds it directly into the RFID tag itself. The tag stores approval bits that indicate whether the item is authorized to leave, eliminating the need for complex database queries during exit verification. This extraction moves the critical authorization information from the centralized system to the decentralized tag, reducing system complexity while maintaining verification reliability.
Solution Approach 2:
The system performs preliminary action by pre-writing authorization approval bits into the RFID tag at the point of sale before the item leaves the store. This advance preparation eliminates the need for real-time database verification at exit, as the authorization status is already determined and stored in the tag. The preliminary authorization write operation simplifies the exit process and reduces system complexity.
2Ease of operation
If tags store approval bits and authorization readers write to tags, then verification is simplified, but security vulnerability to unauthorized access increases
Solution Approach 1:
The patent applies asymmetry by implementing different access rights for different operations. Authorization readers have write access to approval bits, while point-of-exit readers only have read access. This asymmetric permission structure simplifies verification at exit (read-only) while maintaining security by restricting write access to authorized personnel only. The asymmetric access control resolves the contradiction between ease of verification and security protection.
Solution Approach 2:
The system introduces an intermediary layer of password-protected authorization for write operations. Before an authorization reader can write approval bits to a tag, it must authenticate using a password. This intermediary authentication mechanism mediates between the simplicity of tag-based verification and the need for security, allowing easy read verification while preventing unauthorized write access.
3Reliability
If password-based authorization is implemented, then security against unauthorized access improves, but system complexity and susceptibility to attack increases
Solution Approach 1:
The system implements self-service by embedding the password protection mechanism directly within the RFID tag and reader hardware. The password verification is performed automatically by the reader's internal logic without requiring external password management infrastructure. This self-contained approach maintains security while reducing system complexity, as the authentication functionality is integrated into the existing RFID components rather than requiring separate password management systems.
4Measurement precision
If PoE reader checks database for approval, then accurate authorization verification is possible, but response time and system resource usage increase
Solution Approach 1:
The patent extracts the approval verification data from the remote database and places it locally within the RFID tag. The point-of-exit reader can now verify authorization by reading the approval bit directly from the tag without needing to communicate with the central database. This extraction eliminates network latency and database query overhead, significantly reducing verification processing time while maintaining accurate authorization checking.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This solution enhances security and simplifies the authentication process by ensuring only authorized items can leave the facility, reducing the risk of theft and eliminating the need for complex password-based systems, while maintaining the integrity of item ownership and temporal authorization.
Implementation Method 1
The tag generates the transmitted back RF wave either originally, or by reflecting back a portion of the interrogating RF wave in a process known as backscatter.
Data Source
AI summary
In RFID systems employed for loss prevention, an item supplier or an ingress reader writes an ownership code associated with an organization or facility into a tag, indicating that an item to which the tag is attached is associated with the facility and not foreign. At checkout or point-of-sale an authorization reader writes a digital signature into the tag indicating that the tagged item is allowed to leave the facility. At point-of-exit an exit reader determines if the tagged item is allowed to leave the facility by verifying the ownership code and the digital signature. The loss-prevention system may issue an alert or sound an alarm if a facility-associated item is leaving the facility without a proper digital signature indicating that the item is approved to leave.


