RFID Tag Authentication Using Segmented Encryption Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current RFID systems face security issues with sensitive information leakage, particularly in financial transactions, due to the lack of effective methods for protecting PIN numbers and other sensitive data, and existing encryption methods increase system costs and complexity.
Innovation Solution
A method and system for securing an RFID tag using an application code, communication target indicator, and encryption key, combined with a plural authentication process involving an item information table with encoded parameters, to enhance security and prevent eavesdropping, allowing for secure financial transactions and anti-counterfeiting.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption methods are used to protect sensitive information in RFID transactions, then security is improved, but system cost and complexity increase
Solution Approach 1:
The authentication process is segmented into multiple distinct phases: challenge generation, response computation using encryption key, and verification. The encryption key itself is segmented from other tag data and stored separately in protected memory. This segmentation allows security functions to be isolated and managed independently, reducing overall system complexity while maintaining strong security.
Solution Approach 2:
The encryption key is pre-loaded into the RFID tag during manufacturing and stored in protected memory before deployment. Authentication challenges and expected responses are pre-computed and stored in the reader system. This preliminary action eliminates the need for complex real-time key distribution and verification algorithms, simplifying the operational system while ensuring security.
2Reliability
If manual authentication methods are used in financial transactions, then security verification is achieved, but convenience deteriorates
Solution Approach 1:
The RFID tag autonomously performs authentication by automatically generating responses to challenges using its embedded encryption key. The tag self-verifies its identity through the challenge-response protocol without requiring manual intervention. This self-service capability eliminates the need for users to manually present identification documents or remember passwords, greatly improving convenience while maintaining security.
Solution Approach 2:
Manual authentication mechanisms (physical document verification, password entry, signature collection) are replaced with an automated electronic challenge-response authentication system. The mechanical interaction of manual verification is substituted with wireless electromagnetic communication and cryptographic verification, enabling contactless, rapid authentication that is both secure and convenient.
3Speed
If RFID tag information is transmitted without protection, then communication speed is maintained, but information security deteriorates
Solution Approach 1:
The system preemptively protects information security by implementing encryption and authentication protocols before any sensitive data transmission. The challenge-response mechanism verifies tag authenticity prior to allowing communication, and all transmitted authentication data is encrypted. This preliminary anti-action prevents eavesdropping and spoofing attacks without requiring slow, complex real-time encryption of all communications, thus maintaining communication speed while ensuring security.
Data Source
AI summary
An RFID tag to be authenticated in an authentication phase includes a tag memory. The tag memory stores an encryption key and an information table. The information table has a specific storing attribute quantified with a predetermined value, and is read after the authentication phase by using the predetermined value. The encryption key is derived from the predetermined value, and decrypted in the authentication phase to authenticate the RFID tag. A system and method for securing an RFID tag is also provided.


