RFID Tag Security Authentication via Mask Code and Local Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current RFID security authentication methods are prone to tag replication, require high hardware specifications, and suffer from reduced system real-time and efficiency, particularly due to database involvement and lack of encryption in air interface transmission.
Innovation Solution
A method and system for RFID security authentication that uses a security authentication control apparatus to send an inventory command with a mask code, generates and encrypts a random number, and performs authentication using locally stored keys, eliminating database interaction and enhancing real-time and flexibility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If UID-based encryption is used for security authentication, then security is improved, but tags become easy to replicate due to air interface interception
Solution Approach 1:
The patent extracts the security authentication function from the reader and relocates it to the tag itself. The tag performs authentication operations using its own microprocessor and memory resources, eliminating the need for the reader to handle sensitive authentication data. This extraction prevents replication because the authentication logic remains securely embedded in the tag hardware.
Solution Approach 2:
The patent introduces a mask code as an intermediary element in the authentication process. The mask code is used to obfuscate the EPC code during transmission and authentication, adding an additional layer of security. This intermediary prevents direct interception and replication of authentication data by making the transmitted information meaningless without the mask code.
2Reliability
If irreversible logic state conversion is implemented for security, then security is improved, but tag hardware requirements increase and cost rises
Solution Approach 1:
The patent enables the tag to perform authentication operations independently using its own microprocessor and memory resources. The tag serves itself by executing authentication algorithms locally without requiring external authentication hardware or complex reader-side processing. This self-service approach maintains security while avoiding increased hardware complexity.
Solution Approach 2:
The patent designs the tag with a microprocessor that can perform multiple functions including authentication, data processing, and communication. This multi-functional approach eliminates the need for separate dedicated authentication hardware, reducing overall tag complexity while maintaining security capabilities.
3Reliability
If database involvement is added for key authentication, then security is improved, but system real-time performance decreases and efficiency is reduced
Solution Approach 1:
The patent extracts the authentication data storage and processing from the external database and relocates it to the tag's local memory. The tag stores authentication keys and performs verification locally, eliminating the need for continuous database communication during authentication. This extraction dramatically improves real-time performance by removing database access latency.
Solution Approach 2:
The patent performs authentication operations in advance and stores results locally in the tag. The tag maintains cached authentication data and can perform rapid verification without real-time database access. This preliminary action allows the system to maintain security while achieving real-time response performance.
Data Source
AI summary
A method and system for security authentication of radio frequency identification are disclosed. All the security control in this method is completed by the security authentication control apparatus. The reader is for the command transmission and the tag data forwarding, and there is not the security authentication control logic, the security authentication and the non security authentication can be supported at the same time. The key in the tag is unreadable, which ensures that the tag is unable to be replicated; the constant for every security authentication is randomly generated by the control module, and is returned by the tag after being encrypted, which presents the air interface from intercepting the useful information. This method provides the inventory with the mask code before the security authentication, which can have a certain filtering function on the tag data. The mask code can be configured flexibly.


