UHF RFID Reader Tag Authentication via HMAC
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
RFID systems using the UHF band face issues with data clarity and authenticity during communication, as unauthenticated commands can be falsified, leading to potential counterfeiting and damage in physical distribution and supply chain management.
Innovation Solution
Incorporating a Keyed-Hash Message Authentication Code (HMAC) in the RFID reader and tag communication to authenticate specific commands like 'Kill' and 'ProgramID', ensuring only authenticated commands are executed, thereby preventing unauthorized actions and data falsification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If RFID reader and tag transmit data packets without authentication codes, then communication simplicity is maintained, but data clarity and authenticity cannot be secured
Solution Approach 1:
The patent applies preliminary action by inserting authentication codes into commands before transmission. The reader controller generates authentication codes for specific commands (Kill, ProgramID) and attaches them to the command packets before sending to the tag, ensuring authentication is established in advance rather than requiring complex post-transmission verification
Solution Approach 2:
The patent applies local quality by selectively applying authentication codes only to specific commands that require security (Kill, ProgramID) rather than all commands. The reader controller determines which commands need authentication and inserts authentication codes only for those, maintaining simplicity for non-sensitive operations while ensuring security where needed
2Adaptability or versatility
If RFID tag responds to all kinds of RFID readers without authentication, then compatibility is improved, but vulnerability to falsification and counterfeiting increases
Solution Approach 1:
The patent applies preliminary anti-action by implementing authentication verification as a preliminary step before the tag executes any command. The tag controller checks for the presence and validity of authentication codes in received commands before performing actions, preventing falsified commands from being executed while still accepting commands from legitimate readers
Solution Approach 2:
The patent introduces authentication codes as an intermediary element between the reader and tag communication. The authentication code acts as a mediator that verifies the legitimacy of the command source, allowing the tag to distinguish between authenticated and unauthenticated readers without requiring complex reader identification mechanisms
3Reliability
If authentication codes are inserted for all commands, then data security is maximized, but communication efficiency and simplicity are reduced
Solution Approach 1:
The patent applies local quality by selectively applying authentication codes only to specific commands that require security (Kill, ProgramID) rather than all commands. The reader controller determines which commands need authentication and inserts authentication codes only for those, maintaining simplicity for non-sensitive operations while ensuring security where needed
Solution Approach 2:
The patent applies partial action by implementing authentication only for specific critical commands (Kill, ProgramID) rather than all commands. This partial authentication approach provides sufficient security for critical operations while avoiding the overhead of authenticating every command, thus maintaining communication efficiency
Data Source
AI summary
A radio frequency identification reader and a radio frequency identification tag that use an ultrahigh frequency band, and action methods of the radio frequency identification reader and the radio frequency identification tag. The radio frequency identification reader includes: a data generator generating data to be transmitted to a radio frequency identification tag; if a command to control the radio frequency identification tag has to be authenticated, a reader controller controlling the data generator to generate the data including an authentication code; and a reader transmitter transmitting the data to the radio frequency identification tag. As a result, securing of communications of a specific command between the radio frequency identification reader and the radio frequency identification tag can be reinforced.


