RFID Tag Authentication Using Segmented Encryption Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current RFID systems face security issues with sensitive information leakage, particularly in financial transactions, due to the lack of effective methods for protecting PIN numbers and other sensitive data, and existing encryption methods increase system costs and complexity.

Innovation Solution

A method and system for securing an RFID tag using an application code, communication target indicator, and encryption key, combined with a plural authentication process involving an item information table with encoded parameters, to enhance security and prevent eavesdropping, allowing for secure financial transactions and anti-counterfeiting.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption methods are used to protect sensitive information in RFID transactions, then security is improved, but system cost and complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication process is segmented into multiple distinct phases: challenge generation, response computation using encryption key, and verification. The encryption key itself is segmented from other tag data and stored separately in protected memory. This segmentation allows security functions to be isolated and managed independently, reducing overall system complexity while maintaining strong security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The encryption key is pre-loaded into the RFID tag during manufacturing and stored in protected memory before deployment. Authentication challenges and expected responses are pre-computed and stored in the reader system. This preliminary action eliminates the need for complex real-time key distribution and verification algorithms, simplifying the operational system while ensuring security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual authentication methods are used in financial transactions, then security verification is achieved, but convenience deteriorates

Engineering Contradiction:
Improveauthentication securityVSAvoidtransaction convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The RFID tag autonomously performs authentication by automatically generating responses to challenges using its embedded encryption key. The tag self-verifies its identity through the challenge-response protocol without requiring manual intervention. This self-service capability eliminates the need for users to manually present identification documents or remember passwords, greatly improving convenience while maintaining security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Manual authentication mechanisms (physical document verification, password entry, signature collection) are replaced with an automated electronic challenge-response authentication system. The mechanical interaction of manual verification is substituted with wireless electromagnetic communication and cryptographic verification, enabling contactless, rapid authentication that is both secure and convenient.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Speed

If RFID tag information is transmitted without protection, then communication speed is maintained, but information security deteriorates

Engineering Contradiction:
Improvecommunication speedVSAvoidinformation security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system preemptively protects information security by implementing encryption and authentication protocols before any sensitive data transmission. The challenge-response mechanism verifies tag authenticity prior to allowing communication, and all transmitted authentication data is encrypted. This preliminary anti-action prevents eavesdropping and spoofing attacks without requiring slow, complex real-time encryption of all communications, thus maintaining communication speed while ensuring security.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS10515360B2RFID tag and system and method for securing RFID tag
Publication Date: 2019.12.24 TAIWAN DEV & CONSTR
  • US10515360B2 patent drawing
  • US10515360B2 patent drawing
  • US10515360B2 patent drawing

AI summary

An RFID tag to be authenticated in an authentication phase includes a tag memory. The tag memory stores an encryption key and an information table. The information table has a specific storing attribute quantified with a predetermined value, and is read after the authentication phase by using the predetermined value. The encryption key is derived from the predetermined value, and decrypted in the authentication phase to authenticate the RFID tag. A system and method for securing an RFID tag is also provided.