Secure Tag Authentication via Trusted Authority Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional electronic tag systems are not robust, making them vulnerable to theft, counterfeiting, and require significant security measures, which increases costs and limits their adoption, as they struggle to securely authenticate tags and verify their presence in real-time.

Innovation Solution

The use of secure electronic tags that store secret information provisioned by a trusted authority, where authentication is verified through a challenge-response mechanism between the tag, a tag authentication device, and the trusted authority, reducing the need for security in the tag and reader, and allowing for low-cost authentication devices like smartphones to be used.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional electronic tags are used to store value information, then the system is simple and easy to implement, but the system becomes vulnerable to theft and counterfeiting, requiring significant security hardening that increases costs

Engineering Contradiction:
Improvesecurity against theft and counterfeitingVSAvoidsecurity hardening of readers and communication channels
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a trusted authority as an intermediary between the electronic tag and the reader. The trusted authority provisions secret information to the tag and verifies authentication responses, eliminating the need for complex security hardening in the reader device. This mediator approach allows simple readers to securely authenticate tags through the trusted authority's verification process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the security-critical functions from the reader device and concentrates them in the trusted authority. The reader is simplified to only performing basic challenge transmission and response verification, while the trusted authority handles secret information management and authentication verification, removing the burden of security hardening from the reader.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If sophisticated and expensive security techniques are used in electronic tags, then security against copying is improved, but the cost and complexity of the system increases

Engineering Contradiction:
Improvesecurity against copyingVSAvoidcomplexity of security techniques in tags
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trusted authority acts as an intermediary that manages the secret information provisioning and verification process. The tag itself remains relatively simple, storing only secret information provisioned by the trusted authority. The complex authentication logic resides in the trusted authority, not in the tag, thereby reducing tag complexity while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of placing complex security mechanisms within the tag, the patent inverts the approach by placing the secret information management and verification logic in the trusted authority. The tag's role is simplified to storing secret information and computing responses, while the trusted authority performs the heavy lifting of security verification.

Inventive Principle:
Principle #13The other way round (Inversion)

3Reliability

If conventional electronic tags are used without server-side authentication, then the system is simpler and cheaper, but the ability to securely prove authenticity and verify tag presence is limited

Engineering Contradiction:
Improveability to securely prove authenticityVSAvoidserver-side authentication infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trusted authority serves as a server-side intermediary that provides authentication services. It provisions secret information to tags and verifies authentication responses, enabling secure proof of authenticity and presence without requiring complex security infrastructure in the readers or tags themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a challenge-response feedback mechanism where the trusted authority sends challenges to tags and verifies responses. This feedback loop enables secure authentication by requiring tags to prove knowledge of secret information through cryptographic verification performed by the trusted authority.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10412071B2Secure transaction systems and methods
Publication Date: 2019.09.10 INTERTRUST TECH CORP
  • US10412071B2 patent drawing
  • US10412071B2 patent drawing
  • US10412071B2 patent drawing

AI summary

Systems and methods are described that use tag authentication and presence verification techniques in connection with a variety of transactions. In certain embodiments, an authentication device may verify the authenticity of a secure tag by determining whether the secure tag stores secret information provisioned by a trusted authority. In some embodiments, such an authentication process may be performed without exposing the secret information to the authentication device, thereby maintaining integrity of the secure tag. In other embodiments, insecure tags and/or tags that do not include secret information are used.