Nova Patents
EP0805575A2

Transponder

Abstract

Novel means of achieving increased security while still obtaining a low cost, manufacturable device are disclosed and claimed. The first mode of operation is the learn mode which provides means for initial checkout with no security. In the learn mode of operation, the interrogator and transponder may be switched to a predetermined error detection algorithm, i.e. CCITT(Start Mask 46, CCITT Mask 42), and certain information is programmed into the transponder memory. During programming, all the bits received from the interrogator are shifted through the preintialized CRC generator. In addition, once the transponder response is sent back to the interrogator, the response is also shifted through a preinitialized CRC generator within the interrogator(which could be a software implementation). Because neither the Cypher Key 58 nor the Function Key 56 are directly readable once programmed, an encryption must be performed to verify the proper Cypher Key 58 and Function Key 56 were programmed into the transponder's memory. In the second and encryption mode of operation, after a special Command/Address is transmitted, a Random Number (which may vary in length but which has a minimum length) is transmitted from the interrogator to the transponder which in turn generates the Signature by shifting the Random Number through the CRC Encryption Generator (initialized with the Cypher 58 and Function Key 56). The Signature along with data, status and address are transmitted back to the interrogator which in the meantime has predetermined the awaited Signature using the same Cypher 58 and Function Key 56. If the received Signature and calculated Signature are equal, validation is positive and then the programmed data must be locked(especially the Cypher Key 58 and Function Key 56) to protect them against reprogramming in the future

EP0805575A2, drawing sheet 1
Sheet 1 of 5

Term

Term ended

Projected expiry passed 2 May 2017, 9.4 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

34 claims: 16 independent, 18 dependent

  1. 1
    An encryption generator for encrypting an input serial bit stream signal comprising:a shift register including a plurality of flip flops having set and reset lines for setting the output of at least a respective one of said plurality of flip flops irrespective of said input to said flip flops in response to either a Start Mask or a Cypher Key;a plurality of input AND gates, at least two of said AND gates having a first input connected to either a standard mask or a Function Key and a second input connected to the output of at least a further two input AND gates;a plurality of input XOR gates at least a first two of said input XOR gates having a first input connected to the output of said plurality of flip flops and a second input connected to the output of said plurality of AND gates for inverting or not inverting said shift register output, at least a further two of said plurality of input XOR gates having a first input connected to an input serial bit stream and a second input connected to the output of a last of said plurality of flip flops;and at least a further two input AND gates having a first input connected to the output of said at least further two input XOR gates and a second input connected to said standard mask or said Function Key, and an output connected to the input of said at least two input AND gates for enabling a feedback loop of said shift register generator.
  2. 2
    An encryption generator according to Claim 1, wherein said plurality of flip flops and said plurality of input XOR gates are equal in number.
  3. 3
    An encryption generator according to Claim 2, wherein said number is 16.
  4. 5
    An encryption generator according to Claim 4, wherein said standard mask is the CCITT algorithm.
  5. 8
    An encryption generator according to Claim 7, wherein said adequate number of bits is equal to the number of flip flops in said shift register.
  6. 10
    An RF-ID system comprising:a transponder having a generator for receiving an interrogation signal and transmitting response data;an interrogator having a generator for transmitting an interrogation signal and for receiving said response data wherein said interrogation signal and/or said transponder data are encrypted via an encryption generator comprising: a shift register including a plurality of flip flops having set and reset lines for setting the output of at least a respective one of said plurality of flip flops irrespective of said input to said flip flops in response to either a start mask or a Function Key;a plurality of input AND gates, at least two of said AND gates having a first input connected to either a standard mask or an encrypted cypher key and a second input connected to the output of at least a further two input AND gates;a plurality of input XOR gates, at least two of said XOR gates having a first input connected to the output of said plurality of flip flops and a second input connected to the output of said plurality of AND gates for inverting or not inverting said shift register output, at least a further two of said plurality of input XOR gates having one input connected to an input serial bit stream and a second input connected to the output of a last of said plurality of flip flops;and at least a further two input AND gates having a first input connected to the output of said at leasst further two input XOR gates and a second input connected to said start mask or said Function Key, and an output connected to the input of said at least two input AND gates for enabling a feedback loop of said shift register generator.
  7. 11
    An RF-ID system according to Claim 10 wherein said plurality of flip flops and said plurality of two input XOR gates are equal in number.
  8. 12
    An RF-ID system according to Claim 11, wherein said number is 16.
  9. 13
    An RF-ID system according to any of Claims 10 to 12 wherein said start mask is preprogrammed into a memory during manufacturing and determines which shift registers are set and which are reset.
  10. 14
    An RF-ID system according to Claim 13, wherein said standard mask is the CCITT algorithm.
  11. 15
    An RF-ID system according to any of Claims 10 to 14, wherein said Cypher Key is programmed into a memory post manufacturing by a customer.
  12. 16
    An RF-ID system according to any of Claims 10 to 15, further comprising a control logic for counting the received serial input bits and in response thereto responding if an adequate number of bits is received or not responding if the number of received bits is inadequate.
  13. 17
    An RF-ID system according to Claim 16, wherein said adequate number of bits is equal to the number of flip flops in said shift register.
  14. 18
    An RF-ID system according to Claim 16, wherein not responding entails discharging a charge circuit.
  15. 19
    A method of enhancing the security of the data exchange between an interrogator and a transponder comprising the steps of:programming less secure data which can be read and more secure data which cannot be read into a transponder memory and programming said more secure data into said interrogator;verifying the validity of the transfer of the less secure data by executing a control read of the less secure data;verifying the validity of the transfer of the more secure data by executing an encryption comprising the steps of;transmitting a challenge to the transponder;generating a Signature which is a function of said more secure data;transmitting said signature along with other transponder response data to the interrogator;and verifying said Signature with said more secure data and authorizing a function in response to a verified Signature.
  16. 20
    The method according to Claim 19, wherein said programming step comprises programming said more secure data with a Cypher Key.
  17. 21
    The method according to Claim 19, wherein said programming step comprises programming said more secure data with a Function Key.
  18. 22
    The method according to Claim 19, wherein said programming step comprises programming said more secure data with both a Cypher Key and a Function Key.
  19. 23
    The method according to any of Claims 19 to 22, wherein said step of generating said Signature comprises performing a block check character.
  20. 24
    The method according to any of Claims 19 to 23, wherein said programming step comprises programming less secure data including a frame BCC, identification data, selective address data and status, data.
  21. 25
    The method according to any of Claims 19 to 24, wherein said step of transmitting said challenge comprises transmitting a random number which has a length, at a minimum, of the number of shift registers in a CRC generator of said interrogator or said transponder.
  22. 26
    The method according to any of Claims 19 to 25, further comprising locking said more secure data into a transponder memory such that said more secure data cannot be altered or read.
  23. 27
    The method according to any of Claims 19 to 26, further comprising providing a non-volatile, erasable, electrically programmable memory.
  24. 28
    The method according to any of Claims 19 to 27, wherein said step of generating said Signature comprises the steps of applying said challenge to a CRC generator pre-dispositioned with said more secure data, and with the resulting bits remaining in the shift register comprising said Signature.
  25. 29
    The method according to any of Claims 19 to 28, wherein said step of transmitting said other transponder response data comprises transmitting a frame BCC, identification data, status and address data.
  26. 30
    The method according to any of Claims 19 to 29, wherein said verifying step comprises the steps of;applying said other transponder response data to a CRC generator predispositioned with said more secure data, and with the resulting bits remaining in said register equaling zero.
  27. 31
    The method according to any of Claims 19 to 30, further comprising providing a CRC generator within said transponder, said CRC generator comprising a shift register, having a plurality of flip flops having set and reset inputs, and a plurality of exclusive or gates each having two inputs.
  28. 32
    The method according to Claim 31, further comprising determining from said Cypher Key which of said exclusive or gates will be inverting and which will not be inverting said inputs.
  29. 33
    The method according to Claim 31, further comprising determining from said Function Key which of said flip flops will be set and which of said flip flops will be reset.
  30. 34
    The method according to any of Claims 19 to 33, wherein said verifying step comprises the steps of;comparing said Signature to a predetermined Signature generated by said interrogator.
Independent claims30