RFID Transponder Security via Intermediary Key Release

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

RFID systems face security challenges due to the ease of accessing and tracking RFID transponder data through radio frequency communications, with existing security mechanisms being susceptible to unauthorized access and privacy violations, particularly due to limitations in low-cost, passive transponder capabilities and large broadcast ranges.

Innovation Solution

Implementing a method where transceivers read encrypted information from RFID transponders, authenticate themselves, and receive decryption information to decrypt the data, using symmetric or public key encryption to ensure secure access and protect data integrity, with a Key Release Agent managing key distribution and authorization within the RFID infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If RFID transponders use simple passive devices with minimal storage, then manufacturing cost and simplicity are improved, but security capability deteriorates

Engineering Contradiction:
Improvetransponder simplicity and costVSAvoidsecurity capability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent introduces an RFID infrastructure as an intermediary between transponders and transceivers. This infrastructure includes a database storing encrypted transponder data and decryption keys, and an authentication server that verifies transceiver credentials. The infrastructure mediates the security functions that would otherwise need to be implemented in the transponder itself, allowing simple passive transponders to achieve secure communication through the supporting infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If transceivers can access transponder data over large broadcast ranges, then operational versatility is improved, but unauthorized access risk increases

Engineering Contradiction:
Improvebroadcast rangeVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary anti-action by requiring authentication before any data access. Transceivers must present valid credentials to the authentication server, which verifies them against stored authentication data. Only after successful authentication does the system provide decryption keys to authorized transceivers. This preliminary verification prevents unauthorized access before it can occur, countering the vulnerability created by large broadcast ranges.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The RFID infrastructure acts as an intermediary that controls access to transponder data. Even though transceivers can broadcast over large ranges and transponders can be read remotely, the infrastructure mediates all data access requests by verifying transceiver credentials and selectively providing decryption keys. This intermediary layer ensures that broad communication capability does not translate to unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If transponders store encrypted information with secure keys, then data security is improved, but access complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidaccess process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the decryption key management from the transponder and places it in the RFID infrastructure database. Transponders store only encrypted data, while the infrastructure stores both the encrypted data copies and the corresponding decryption keys. This extraction separates the security-critical key management function from the simple transponder device, maintaining data security while simplifying transponder access (transponders don't need complex key management circuitry).

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The RFID infrastructure serves as an intermediary that manages the complexity of encrypted data access. Instead of requiring transceivers to directly manage encryption keys and encrypted data stored on transponders, the infrastructure mediates this process by storing decryption keys in its database and selectively providing them to authenticated transceivers. This intermediary approach maintains strong encryption security while simplifying the access process for authorized users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7548152B2RFID transponder information security methods systems and devices
Publication Date: 2009.06.16 ENTRUST CORP
  • US7548152B2 patent drawing
  • US7548152B2 patent drawing
  • US7548152B2 patent drawing

AI summary

Methods, systems and devices for providing RFID system security are provided that involve cryptographically encrypting data on a transponder and managing the release of the decryption information, decryption keys, or the data itself to a transceiver having a transaction with the transponder.