RFID Tag Security Authentication via Mask Code and Local Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current RFID security authentication methods are prone to tag replication, require high hardware specifications, and suffer from reduced system real-time and efficiency, particularly due to database involvement and lack of encryption in air interface transmission.

Innovation Solution

A method and system for RFID security authentication that uses a security authentication control apparatus to send an inventory command with a mask code, generates and encrypts a random number, and performs authentication using locally stored keys, eliminating database interaction and enhancing real-time and flexibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If UID-based encryption is used for security authentication, then security is improved, but tags become easy to replicate due to air interface interception

Engineering Contradiction:
ImprovesecurityVSAvoidtag replication risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the security authentication function from the reader and relocates it to the tag itself. The tag performs authentication operations using its own microprocessor and memory resources, eliminating the need for the reader to handle sensitive authentication data. This extraction prevents replication because the authentication logic remains securely embedded in the tag hardware.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a mask code as an intermediary element in the authentication process. The mask code is used to obfuscate the EPC code during transmission and authentication, adding an additional layer of security. This intermediary prevents direct interception and replication of authentication data by making the transmitted information meaningless without the mask code.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If irreversible logic state conversion is implemented for security, then security is improved, but tag hardware requirements increase and cost rises

Engineering Contradiction:
ImprovesecurityVSAvoidtag hardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables the tag to perform authentication operations independently using its own microprocessor and memory resources. The tag serves itself by executing authentication algorithms locally without requiring external authentication hardware or complex reader-side processing. This self-service approach maintains security while avoiding increased hardware complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent designs the tag with a microprocessor that can perform multiple functions including authentication, data processing, and communication. This multi-functional approach eliminates the need for separate dedicated authentication hardware, reducing overall tag complexity while maintaining security capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If database involvement is added for key authentication, then security is improved, but system real-time performance decreases and efficiency is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidsystem real-time performance
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the authentication data storage and processing from the external database and relocates it to the tag's local memory. The tag stores authentication keys and performs verification locally, eliminating the need for continuous database communication during authentication. This extraction dramatically improves real-time performance by removing database access latency.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs authentication operations in advance and stores results locally in the tag. The tag maintains cached authentication data and can perform rapid verification without real-time database access. This preliminary action allows the system to maintain security while achieving real-time response performance.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8712053B2Method and system for security authentication of radio frequency identification
Publication Date: 2014.04.29 ZTE CORP
  • US8712053B2 patent drawing
  • US8712053B2 patent drawing
  • US8712053B2 patent drawing

AI summary

A method and system for security authentication of radio frequency identification are disclosed. All the security control in this method is completed by the security authentication control apparatus. The reader is for the command transmission and the tag data forwarding, and there is not the security authentication control logic, the security authentication and the non security authentication can be supported at the same time. The key in the tag is unreadable, which ensures that the tag is unable to be replicated; the constant for every security authentication is randomly generated by the control module, and is returned by the tag after being encrypted, which presents the air interface from intercepting the useful information. This method provides the inventory with the mask code before the security authentication, which can have a certain filtering function on the tag data. The mask code can be configured flexibly.