RFID Transponder Security via Intermediary Key Release
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
RFID systems face security challenges due to the ease of accessing and tracking RFID transponder data through radio frequency communications, with existing security mechanisms being susceptible to unauthorized access and privacy violations, particularly due to limitations in low-cost, passive transponder capabilities and large broadcast ranges.
Innovation Solution
Implementing a method where transceivers read encrypted information from RFID transponders, authenticate themselves, and receive decryption information to decrypt the data, using symmetric or public key encryption to ensure secure access and protect data integrity, with a Key Release Agent managing key distribution and authorization within the RFID infrastructure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If RFID transponders use simple passive devices with minimal storage, then manufacturing cost and simplicity are improved, but security capability deteriorates
Solution Approach 1:
The patent introduces an RFID infrastructure as an intermediary between transponders and transceivers. This infrastructure includes a database storing encrypted transponder data and decryption keys, and an authentication server that verifies transceiver credentials. The infrastructure mediates the security functions that would otherwise need to be implemented in the transponder itself, allowing simple passive transponders to achieve secure communication through the supporting infrastructure.
2Adaptability or versatility
If transceivers can access transponder data over large broadcast ranges, then operational versatility is improved, but unauthorized access risk increases
Solution Approach 1:
The patent implements preliminary anti-action by requiring authentication before any data access. Transceivers must present valid credentials to the authentication server, which verifies them against stored authentication data. Only after successful authentication does the system provide decryption keys to authorized transceivers. This preliminary verification prevents unauthorized access before it can occur, countering the vulnerability created by large broadcast ranges.
Solution Approach 2:
The RFID infrastructure acts as an intermediary that controls access to transponder data. Even though transceivers can broadcast over large ranges and transponders can be read remotely, the infrastructure mediates all data access requests by verifying transceiver credentials and selectively providing decryption keys. This intermediary layer ensures that broad communication capability does not translate to unauthorized access.
3Reliability
If transponders store encrypted information with secure keys, then data security is improved, but access complexity increases
Solution Approach 1:
The patent extracts the decryption key management from the transponder and places it in the RFID infrastructure database. Transponders store only encrypted data, while the infrastructure stores both the encrypted data copies and the corresponding decryption keys. This extraction separates the security-critical key management function from the simple transponder device, maintaining data security while simplifying transponder access (transponders don't need complex key management circuitry).
Solution Approach 2:
The RFID infrastructure serves as an intermediary that manages the complexity of encrypted data access. Instead of requiring transceivers to directly manage encryption keys and encrypted data stored on transponders, the infrastructure mediates this process by storing decryption keys in its database and selectively providing them to authenticated transceivers. This intermediary approach maintains strong encryption security while simplifying the access process for authorized users.
Data Source
AI summary
Methods, systems and devices for providing RFID system security are provided that involve cryptographically encrypting data on a transponder and managing the release of the decryption information, decryption keys, or the data itself to a transceiver having a transaction with the transponder.


