Wireless Tag Security via Sequence Number Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing wireless tags used in proximity communication, such as IC cards or IC chips, face challenges in reducing size and cost while maintaining security, particularly for short-term services where strong security is not always necessary, and the inclusion of a random number generating circuit hinders these goals.
Innovation Solution
A communication device and method that employs a sequence number stored in a non-volatile memory, updated regularly, to perform authentication and data encryption, allowing the wireless tag to verify the reader/writer without a random number generating circuit, using a simplified authentication method to ensure security without increasing size or cost.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a random number generating circuit is included in the wireless tag to perform mutual authentication, then security is improved, but device size and manufacturing cost increase
Solution Approach 1:
The random number generating circuit is extracted from the wireless tag and relocated to the reader/writer. The wireless tag only needs to store and transmit the sequence number, while the reader/writer performs random number generation and authentication calculations, thereby reducing tag complexity while maintaining security
Solution Approach 2:
A sequence number stored in the wireless tag serves as an intermediary element that enables authentication without requiring the tag to have random number generation capabilities. The sequence number acts as a reference that the reader/writer uses to verify authentication data
2Reliability
If a random number generating circuit is included in the wireless tag to perform mutual authentication, then security is improved, but manufacturing cost increases
Solution Approach 1:
The random number generating circuit is extracted from the wireless tag and relocated to the reader/writer. The wireless tag only needs to store and transmit the sequence number, while the reader/writer performs random number generation and authentication calculations, thereby reducing tag complexity while maintaining security
Solution Approach 2:
The wireless tag is designed as a low-cost, simple device that does not require expensive random number generation circuitry. The authentication security is provided by the reader/writer's more sophisticated processing, allowing the tag to be manufactured at lower cost
3Reliability
If mutual authentication using symmetrical cipher algorithm is implemented, then data security is improved, but device complexity increases
Solution Approach 1:
The authentication system is segmented into two parts: the wireless tag handles only simple sequence number storage and transmission, while the reader/writer handles the complex random number generation, encryption, and authentication verification, dividing the computational burden appropriately
Solution Approach 2:
The random number generating circuit is extracted from the wireless tag and relocated to the reader/writer. The wireless tag only needs to store and transmit the sequence number, while the reader/writer performs random number generation and authentication calculations, thereby reducing tag complexity while maintaining security
Data Source
AI summary
Provided is a communication device including: a communication section performing proximity communication with a reader/writer; a storage section storing data and a sequence number; and a control section controlling the writing of the data to the storage section in accordance with a command from the reader/writer. The communication section sends the sequence number to the reader/writer and receives first encryption data, which is generated by the reader/writer using a value based on the sequence number and writing target data which is target data which is written into the storage section, and the writing target data from the reader/writer, and the control section generates second encryption data using the value based on the sequence number and the writing target data, writes the writing target data into the storage section, and updates the sequence number in a case where the first encryption data and the second encryption data match.


