Tamper Credential Reader Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

RFID systems in access control face vulnerabilities due to physical attacks and sophisticated signal mimicking, where similar-looking readers can be swapped or tampered with, leading to unauthorized access.

Innovation Solution

Implementing a tamper credential system where a reader is paired with a tamper mechanism, such as an adhesive tag or physically unclonable function (PUF) tag, that indicates tampering through mechanical and chemical indicators, and operates in a tamper state upon damage or separation, requiring authorized intervention to restart authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If readers are made to appear similar or identical in outward appearance, then ease of operation and manufacturing are improved, but security is worsened because bad actors can swap readers without detection

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies visual indicators (color changes, lighting elements, or visual distinctions) to the reader exterior to enable easy identification of the reader's operational state and authenticity. This allows the reader to maintain a simple, uniform appearance while incorporating security features that prevent unauthorized swapping, as the visual indicators would reveal if a reader has been tampered with or replaced.

Inventive Principle:
Principle #32Color changes

2Reliability

If a tamper credential system is implemented with authentication protocols, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the tamper credential functionality directly into the reader unit, merging the authentication credential and the reading device into a single integrated system. This integration reduces overall system complexity by eliminating separate components while maintaining security, as the tamper credential becomes an inherent part of the reader rather than an external accessory.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The reader performs self-authentication by verifying its own tamper credential status through internal authentication protocols. The system automatically detects tampering and manages its own security state without requiring external verification, thereby improving security while minimizing the complexity of external authentication infrastructure.

Inventive Principle:
Principle #25Self-service

3Reliability

If mechanical and chemical indicators are added to detect tampering, then security is improved, but manufacturing complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidease of manufacture
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent replaces complex mechanical tamper detection indicators with electronic or optical detection mechanisms integrated into the reader. Instead of using mechanical indicators that require physical assembly steps, the system uses electronic sensors, RFID tags, or optical indicators that can be programmed and activated electronically, thereby maintaining security while simplifying the manufacturing process.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9734366B2Tamper credential
Publication Date: 2017.08.15 ASSA ABLOY AB
  • US9734366B2 patent drawing
  • US9734366B2 patent drawing
  • US9734366B2 patent drawing

AI summary

Readers are associated with a number of access credentials and, once authenticated by the reader, may grant the holder of the access credential access to a secured asset. Readers may become the target of attack, such as when an unauthorized party attempts to gain access to the interior of the reader or removes the reader from an installed location. Once removed the reader may be reinstalled in another location or a counterfeit reader used in its place. By providing a paired tamper credential, the reader may deny otherwise authorized access to the secured asset if the tamper credential fails to respond appropriately. The tamper credential may fail to respond due to distance, such as when the reader alone is relocated, or the tamper credential is damaged, such as during an attempt to gain access the interior of the reader and/or remove the reader from its installed location.