UHF RFID Reader Tag Authentication via HMAC

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

RFID systems using the UHF band face issues with data clarity and authenticity during communication, as unauthenticated commands can be falsified, leading to potential counterfeiting and damage in physical distribution and supply chain management.

Innovation Solution

Incorporating a Keyed-Hash Message Authentication Code (HMAC) in the RFID reader and tag communication to authenticate specific commands like 'Kill' and 'ProgramID', ensuring only authenticated commands are executed, thereby preventing unauthorized actions and data falsification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If RFID reader and tag transmit data packets without authentication codes, then communication simplicity is maintained, but data clarity and authenticity cannot be secured

Engineering Contradiction:
Improvedata authenticityVSAvoidcommunication protocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by inserting authentication codes into commands before transmission. The reader controller generates authentication codes for specific commands (Kill, ProgramID) and attaches them to the command packets before sending to the tag, ensuring authentication is established in advance rather than requiring complex post-transmission verification

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies local quality by selectively applying authentication codes only to specific commands that require security (Kill, ProgramID) rather than all commands. The reader controller determines which commands need authentication and inserts authentication codes only for those, maintaining simplicity for non-sensitive operations while ensuring security where needed

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If RFID tag responds to all kinds of RFID readers without authentication, then compatibility is improved, but vulnerability to falsification and counterfeiting increases

Engineering Contradiction:
Improvereader-tag compatibilityVSAvoidvulnerability to falsification
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by implementing authentication verification as a preliminary step before the tag executes any command. The tag controller checks for the presence and validity of authentication codes in received commands before performing actions, preventing falsified commands from being executed while still accepting commands from legitimate readers

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent introduces authentication codes as an intermediary element between the reader and tag communication. The authentication code acts as a mediator that verifies the legitimacy of the command source, allowing the tag to distinguish between authenticated and unauthenticated readers without requiring complex reader identification mechanisms

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If authentication codes are inserted for all commands, then data security is maximized, but communication efficiency and simplicity are reduced

Engineering Contradiction:
Improvecommand authenticationVSAvoidcommunication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by selectively applying authentication codes only to specific commands that require security (Kill, ProgramID) rather than all commands. The reader controller determines which commands need authentication and inserts authentication codes only for those, maintaining simplicity for non-sensitive operations while ensuring security where needed

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent applies partial action by implementing authentication only for specific critical commands (Kill, ProgramID) rather than all commands. This partial authentication approach provides sufficient security for critical operations while avoiding the overhead of authenticating every command, thus maintaining communication efficiency

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS7978077B2RFID reader and RFID tag using UHF band and action methods thereof
Publication Date: 2011.07.12 SAMSUNG ELECTRONICS CO LTD
  • US7978077B2 patent drawing
  • US7978077B2 patent drawing
  • US7978077B2 patent drawing

AI summary

A radio frequency identification reader and a radio frequency identification tag that use an ultrahigh frequency band, and action methods of the radio frequency identification reader and the radio frequency identification tag. The radio frequency identification reader includes: a data generator generating data to be transmitted to a radio frequency identification tag; if a command to control the radio frequency identification tag has to be authenticated, a reader controller controlling the data generator to generate the data including an authentication code; and a reader transmitter transmitting the data to the radio frequency identification tag. As a result, securing of communications of a specific command between the radio frequency identification reader and the radio frequency identification tag can be reinforced.