Transponder Key Management via Reader-Side Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current transponder systems face challenges in managing multiple user keys without the need for extensive tag/key tables, which complicates security and data integrity, especially in scenarios where a single key compromise can affect all users' data.

Innovation Solution

Implementing a supervisory algorithm in the reader to manage multiple keys, using a single key in the tag for access control, and generating keys on the fly based on unique tag data, reducing the need for large tag/key tables and minimizing hardware and memory requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple user keys are stored in each tag to protect separate memory spaces, then data security and user-specific access control are improved, but tag memory requirements and hardware complexity increase

Engineering Contradiction:
Improvedata securityVSAvoidtag memory requirements
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts the key management functionality from the tag to the reader. Instead of storing multiple keys in each tag, the system uses a single key in the tag and manages multiple user keys in the reader through a tag/key table. This reduces tag memory requirements while maintaining security through centralized key management.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a tag/key table in the reader as an intermediary structure that maps user keys to tags. This intermediary enables multiple users to access the system with different keys without requiring each tag to store multiple keys, thus resolving the contradiction between security and memory requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If a tag/key table is maintained in each reader to support multiple users, then user-specific access control is improved, but device complexity and key management burden increase

Engineering Contradiction:
Improveuser-specific access controlVSAvoidkey management burden
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal tag/key table structure that can serve multiple users and tags within a single reader. This universal approach allows the reader to manage access control for multiple users without requiring separate key management mechanisms for each user, reducing overall device complexity while maintaining versatility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If each user has separate keys in the tag, then compromising one key does not compromise all data, but the need for large tag/key tables in readers increases

Engineering Contradiction:
Improvedata integrityVSAvoidtag/key table size
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the key management architecture by separating tag-specific keys from user-specific keys. Each tag retains a single unique key for data integrity, while user keys are managed separately in the reader. This segmentation maintains data integrity (each tag's data remains protected by its unique key) while avoiding the need for large tag/key tables in readers.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7928831B1System and method for handling user keys and user passwords in a tagging system where the tag itself is capable of carrying only a single key or password
Publication Date: 2011.04.19 AMTECH SYSTEMS LLC
  • US7928831B1 patent drawing
  • US7928831B1 patent drawing
  • US7928831B1 patent drawing

AI summary

In railroad uses or the like, a transponder having a single key for transactions is accessible through a reader/programmer to multiple users or owners. The reader/programmer receives a transaction request and determines whether the user or owner is authorized for that transaction. If so, the reader/programmer generates the key on the fly and performs the transaction.