Method for tuning an oscillating receiver circuit of a transponder built into a rfid system
Abstract
THE PROCEDURE FOR CRYPTOLOGICAL AUTHENTICATION APPLIED IN A RADIO FREQUENCY IDENTIFICATION SYSTEM WITH A BASE STATION, WHICH FEEDS A TRANSPONDER ASSOCIATED WITH THE OBJECT TO IDENTIFY THROUGH THE ALTERNATE FIELD OF A SEARCH SIGNAL, INCLUDES THE FOLLOWING. FOR PRACTICALLY THE JOINT OF COMMUNICATIONS BETWEEN THE BASE STATION AND THE TRANSPONDER, THE BASE STATION ISSUES A SEARCH SIGNAL. THE TRANSPONDER RESPONSES TO THE RECEIPT OF THE SEARCH SIGNAL ISSUED BY THE BASE STATION THROUGH AN IDENTIFICATION NUMBER STORED IN ITS MEMORY. THE BASE STATION THEN CODES A FIRST BINARY SEQUENCE THAT GENERATES ITSELF USING A BINARY KEY SEQUENCE ATTRIBUTED TO THE TRANSPONDER ID NUMBER AND SENDS TO THIS LAST THE SECOND BINARY SEQUENCE OBTAINED. AT THE RECEPTION OF THE SECOND BINARY SEQUENCE, THE TRANSPONDER GENERATES FROM IT A BINARY CONTROL SEQUENCE THAT SENDS TO THE BASE STATION, AFTER THE COMPLETE RECEPTION OF THE SECOND BINARY SEQUENCE. THIS BINARY CONTROL SEQUENCE SERVES TO VERIFY THE GOOD RECEPTION OF THE SECOND BINARY SEQUENCE. IN ACCORDANCE WITH THE PURPOSES OF CRYPTOGRAPHIC AUTHENTICATION, THE TRANSPONDER CODES THE FIRST BINARY SEQUENCE RECONSTITUTED FROM THE SECOND BINARY SEQUENCE WITH THE KEY BINARY SEQUENCE ATTRIBUTED TO THE INDICATED TRANSPONDER, AND IT SENDS THE TRANSPONDER, AND SENDS IT TO THE INDICATED TRANSPONDER. WHILE THE TRANSPONDER CODES THE SECOND BINARY SEQUENCE AND SO MAKES IT A THIRD BINARY SEQUENCE, THE BASE STATION VERIFIES, WITH THE AID OF THE BINARY CONTROL SEQUENCE, IF AN ERROR OCCURRED WITH THE SECONDARY TRANSFER, EVENTUALLY DISCONTINUING THE CODING IN PROGRESS IN THE TRANSPONDER. AN INTERRUPTION OF AUTHENTICATION OPERATION IN PROGRESS MAY RESULT TO THE EXTENT WHERE THE RESULT OBTAINED CANNOT BE MORE THAN WRONG. THIS ALLOWS YOU TO GAIN TIME TO RELAIN THE AUTHENTICATION PROCEDURE AGAIN.

Term
Term ended
Projected expiry passed 13 September 2017, 9 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
3 claims: 2 independent, 1 dependent
- 1ES 2 172 769 T3 REIVINDICACIONES 1. Procedimiento para la autentificacion criptológica en un sistema de identificación de radiofrecuencia con una estacion base que suministra energía a un respondedor, comunicado con el objeto a identificar, a travóes del campo alterno, con las siguientes fases de procedimiento:- la estacion base genera una senal interrogadora;- el respondedor contesta a la recepcióon de la senal interrogadora enviada por la estación base con un nuómero de identificacióon almacenado en su memoria;- la estacióon base codifica una primera secuencia de bits generada por ella mediante una secuencia de bits clave asignada al nuómero de identificacióon del respondedor y envóa la segunda secuencia de bits asó obtenida al respondedor;- el respondedor reconstruye la primera secuencia de bits a partir de la segunda secuencia de bits y la codifica mediante la secuencia de bits clave asignada al respondedor y envóa la tercera secuencia de bits asó obtenida a la estacióon base;- la estacióon base comprueba la validez de la tercera secuencia de bits recibida;caracterizado porque - al recibir la segunda secuencia de bits, el respondedor genera a partir de la segunda secuencia de bits una secuencia de bits de control y la envóa despuóes de la recepcióon completa de la segunda secuencia de bits a la estacióon base y - porque mientras el respondedor auón estaó codificando la segunda secuencia de bits convirtióendola en la tercera secuencia de bits, la estacioón base comprueba con ayuda de la secuencia de bits de control, si en la transmisióon de la segunda secuencia de bits ha aparecido un fallo y, en su caso, interrumpe la codificacióon en curso en el respondedor.
- 2Procedimiento para la autentificacioón criptoloógica seguón la reivindicacioón 1, caracterizado porque el respondedor parte por la mitad la longitud de la tercera secuencia de bits antes de su envóo a la estacióon base.
- 3Procedimiento para la autentificacioón criptoloógica seguón las reivindicaciones 1 óo 2, caracterizado porque la estacióon base codifica inmediatamente al inicio del procedimiento una primera secuencia de bits generada por ella con ayuda de una secuencia de bits clave asignada a ella y al respondedor, y envóa la segunda secuencia de bits asó obtenida al respondedor, en lugar de esperar a que se produzca la recepcióon del nuómero de identificacioón del respondedor. NOTA INFORMATIVA:Conforme a la reserva del art. 167.2 del Convenio de Patentes Europeas (CPE) y a la Disposición Transitoria del RD 2424/1986, de 10 de octubre, relativo a la aplicacion del Convenio de Patente Europea, las patentes europeas que designen a España y solicitadas antes del 7-10-1992, no producirán ningún efecto en Espana en la medida en que confieran proteccián a productos quámicos y farmaceuticos como tales. Esta informacioán no prejuzga que la patente estáeo no incluáda en la mencionada reserva.
Independent claims3
98 paragraphs in 2 sections, as filed
IS 2 172 769 T3
DESCRIPTION
Procedure for cryptological authentication in a radio frequency identification system.
The invention relates to a procedure for cryptological authentication in a radio frequency identification system.
In recent years, a system for the identification of people, animals and objects has proven its effectiveness, in which a reading machine, also called a reader or base station, supplies energy to a responder, communicated with the object to be identified, through a alternate field, answering the responder with the emission of the data stored in it. Due to the range of frequencies used, there is also talk of radio frequency or RFID identification systems.
In general, an RFID transponder consists of a coil-shaped antenna and an integrated switch circuit, which contains all the necessary electronic circuit blocks, such as for the supply of current, for the generation of pulses, for the control of sequence and for storing the data necessary for identification. The capacitor connected in parallel to the coil-shaped antenna is often also part of the integrated switch circuit. However, it can also be made up of a discrete component.
The RFID reader is composed of an amplifier circuit tuned with an emitter coil and a capacitor, which is controlled by an exciter stage by means of a signal with a generally fixed frequency (eg 125 kHz). The reader also contains electronic circuit blocks, to recognize the data sent by the transponder through absorption modulation and to send data and commands, eg by field modulation, to the transponder.
The reader machine and the transponder form a loose coupled transformer in the transmission of data or power. Therefore, the transmission of energy is relatively low.
The achievable range for non-contact transmission of power and data was influenced by the following limit conditions:
- Emission energy (limited by legal provisions)
- Coil measurements
- Environmental interference level
- Matching of resonance frequencies
- Amplitude of modulation
- Loss of tension through the rectifier
- Transmission procedures used
In use in the form of an electronic immobilizer, due to the small transmitter coil arranged around the ignition lock, extremely unfavorable transmission conditions result. Therefore, it is necessary to optimize the system so that losses are minimal. In this sense it is decisive:
- Same resonance frequency of the base station and the transponder
- Time-optimized transmission protocols
- Minimal losses in the transmission of energy
- Maximum modulation amplitude in the data transmission to the base station (reader)
- Data transmission to the responder (sender) optimized
Document EP-0683293A1 has disclosed a procedure for authentication in a radio frequency identification system, in which an interrogation and response emission protocol is used for cryptological authentication.
When starting a vehicle, the user perceives a delay of more than 150 ms, from turning the ignition key until the engine starts. It follows that the entire transmission protocol must have elapsed in this very short period of time. Several points should be taken into account. On the one hand, a single data transmission must provide the correct result, on the other, additional functions such as algorithmic authentication must occur in as short a time as possible.
The object of the invention is to indicate a procedure for cryptological authentication in a radiofrequency identification system, which takes place in the shortest possible time.
This objective is achieved by means of a method for cryptological authentication in a radiofrequency identification system with the characteristics of claim 1. The advantageous configuration of the invention is carried out according to the characteristics of the dependent claims.
The procedure for cryptological authentication in a radio frequency identification system with a base station, which supplies power to a responder, communicated to the object to be identified, through the alternate field of an interrogation signal, presents the following steps.
Essentially, for all communication between the base station and the responder, the base station generates an interrogation signal. The responder, upon receiving the interrogation signal issued by the base station, replies with an identification number stored in its memory. The base station then encodes a first sequence of bits generated by it with the help of a key bit sequence, which is assigned to the responder's identification number and sends the second sequence of bits thus obtained to the responder.
Upon receiving the second sequence of bits, the responder generates from the second sequence of bits a sequence of control bits and sends this to the base station after the complete reception of the second sequence of bits. This sequence of control bits is used to check the correct reception of the second sequence of bits. For cryptological authentication, the responder encodes the first sequence of bits reconstructed from the second sequence of bits, with the help of the key sequence of bits assigned to the responder, and sends the third sequence of bits thus obtained to the base station.
While the responder is still encoding the second sequence of bits, converting it into the third sequence of bits, the base station checks by means of the sequence of control bits whether in the transmission of the second sequence of bits.
ES 2 172 769 T3 a failure has occurred, in which case the encoding in progress at the responder is interrupted. This may interrupt the authentication in progress, as a correct result cannot be expected. You save time by restarting the authentication process.
In the other case, the base station checks the validity of the third sequence of bits received.
Another way to reduce the authentication duration is for the responder to halve the length of the third sequence of bits before it is broadcast to the base station.
In one configuration of the procedure, the base station immediately encodes at the beginning of the process a first sequence generated by it by means of a sequence of key bits assigned to it and the responder and sends the second sequence of even bits obtained to the responder immediately, instead of waiting first the reception of the responder's identification number. In this way it is possible to reduce even more the duration of the authentication.
Brief description of the figures
Figure 1: shows a sequence diagram of the procedure for cryptological authentication in a radiofrequency identification system on the transponder side;
Figure 2: shows the development of the procedure in an electronic immobilizer of a vehicle;
Figure 3: shows different signal paths in the communication between the base station and the responder;
Figure 4: shows a detailed sequence diagram of an RFID system with cryptologic authentication.
The procedure according to the invention is explained below with the help of the figures through an embodiment example. For a clearer explanation of the principle of a cryptological authentication, the TIME procedure (TEMIC immobilizer encryption) developed and optimized by TEMIC for particularly high security requirements, such as the electronic immobilizer, is detailed, which stands out for the following characteristics:
- Fast and secure authentication (<100 ms)
- High security algorithm optimized for the application
- Customer-specific generation of uonic keys
In this way, a high degree of security is achieved, both in the data transmission and in the encryption itself, in relation to an extremely short authentication time. Figure 1 shows the development of the authentication optimized by TEMIC in terms of a minimum duration. The particularities are, firstly, the short duration required for the calculation of the algorithm (encryption time 30 ms), secondly the reduction of the response from eight to four bytes by means of a special procedure and, thirdly, the possibility of interrupt the process at any time during the detection of a failure case.
At the start of the RFID system, a specially generated 120-bit long cryptological key is transmitted to the responder and base station, which determines the function of the cryptological algorithm. This key is unique throughout the system. No other RFID system, that is, no other base station or other responder will have that key.
In operation and once synchronized with the base station, the responder sends a sequence of bits determined in a unique way with a fixed length (depending on the application, eg 64 bits), the so-called ID code or simply ID. This ID is generally used for key identification. This is necessary when different responders (with different cryptographic keys) must operate with a base station.
The authentication protocol used is an interrogation and response emission protocol, as represented in figure 2, with the characteristic that "known clear text" and "selected clear text" attacks are innocuous.
The base station generates a first sequence of bits in the form of a 64-bit random Z number and encodes this by means of a 32-bit partial key, which is generated from the cryptological key. The second sequence of bits received in the form of a 64-bit random result - the so-called polling broadcast - is sent to the responder. Only the responder with the same partial key will be able to reconstruct the random value. Thus, a protocol observer could not figure out the random Z number. The responder and base station encrypt the interrogation broadcast using the 120-bit cryptographic key, using a specially developed AUT 64 algorithm. From the result of each 64-bit encoding, a third sequence of bits is generated in the form of a 32-bit sign sequence. The responder transmits this sequence of signs - the so-called response to the base station. In the event of a match between the transmitted response and the generated bit sequence, the base station accepts the authenticity of the responder.
The AUT 64 algorithm used is a byte-oriented block cipher, which generates output bit sequences from 64 bits using a 120-bit cryptologic key. A 64-bit input sequence (in this case the random Z number) is transformed by encoding - in 24 turns - into a 64-bit output sequence (here, the encoding result). In each round a different key is used, generated from the cryptographic key. Thanks to this way of proceeding, a high degree of safety is achieved. Statistical analyzes confirm this conclusively. The reason for this is, mainly, the non-linear coding, which is chosen differently in each turn (controlled by key).
Key generation
For the generation of the 120-bit cryptographic key, TEMIC makes available a program that uses as a random generator, among others, the Data Encryption Standard (DES). In this way it is guaranteed that only the user knows the cryptological key.
The 120-bit cryptologic key used for the AUT 64 is made up of the components3
ES 2 172 769 T3 tes family key (24 bits), user key (64 bits) and random key (32 bits). The user key is generated by the manufacturer using a sequential key.
Random key
The random key is generated by the
DES. The user determines the corresponding 56-bit DES key, as well as the DES input, so that TEMIC does not have any information about the DES output and thus about the generated random key.
Family key
Each of the keys is generated by a special program, thus ensuring especially that different users receive different sets of family keys with the length of 24 bits. Each user is assigned 12 bits so that they can choose from a range of 16 numbers. AND<sup>í</sup> This is the only knowledge that TEMIC has about the keys that would later be used.
User Keys
Through a special procedure, a unique 64-bit random number is generated, that is, each user key is generated only once. A repeat would only take place after 20.9 * 10<sup>12</sup> generated user keys.
Transmission protocol reduction by
- Do not wait for the complete ID code transmission (identification), but the interrogation emission could be transmitted already after the reset connection -> saving of 20 ms.
- During the calculation of the algorithm (encryption, coding of the interrogation emission) a checksum is transmitted to the base station. In this way it is checked whether the interrogation broadcast has been correctly transmitted. If this transmission is not correct, the encryption can be interrupted immediately by sending an interval and a new interrogation emission is sent. Thus, one should not necessarily wait to receive the wrong and therefore useless answer.
- The result of the encryption is composed, like the input (the interrogation emission) of 8 bytes. These 64 bits are linked for example through an XOR function, so that only 4 bytes need to be retransmitted as a result (response) to the base station. -> Reduction in 50% of the time (in this example from 20 ms to 10 ms).
High security algorithm
- The random number, that is, the input for the AUT 64 algorithm is not sent directly, but is previously encoded (result = interrogation emission) -> selected plaintext attacks are not possible.
- The AUT 64 algorithm is traversed 24 times and varied in each turn, that is, the non-linear encoding is chosen differently in each turn (controlled by key) -> difficult algorithm to “break”.
Key generation
- A partial key - the user key - is produced through a special procedure so that it is unique. A single repeat will occur after 20.9 * 10<sup>12</sup> generated user keys.
-Only the user has influence on the generation of the random key - neither TEMIC nor others have this information.
- In the family key, TEMIC assigns a partial interval to each user. This user, eg. A car manufacturer can choose 16 numbers from a range and thus assign each car series (eg each VW Golf) a specific partial family key key. -> Each user receives a certain partial key interval, which also differs in the algorithm that accesses the keys (eg VW and Opel have different keys).
Data transmission in the procedure described here can be divided into three areas:
- Reading mode = Transmitting data from the responder to the base station
- Send mode - Base station data transmission to the responder
- Write mode - Data transmission from the base station to the responder with subsequent programming
In order to guarantee data integrity, that is, transmission free of manipulation and thus unaltered in each mode, there are different possibilities.
In read mode, data (ID code) is read from the transponder's EEPROM memory and sent to the base station. The first 8 bits represent a client-specific header, which is programmed by TEMIC and secured against tampering. The other bits are freely programmable by the client and normally contain a correlative number including the checksum, so that a faulty transmission of the code can be detected.
Advantage
The header and checksum are checked.
The send mode is used in the transmission of the start value (interrogation emission) for authentication. The responder checks the correct amount of the transmitted bits as well as the field pulses between the field gaps. It then sends a checksum formed from the number of “ones” numbers transmitted to verify the correct transmission to the base station (figure 4). If the checksum is not correct, there is a possibility to interrupt the authentication process and start it again.
Advantage
The number of bits and pulses between the change gaps as well as the sending of the checksum is checked.
The TEMIC writing procedure is based on the On / Off pulsation of the radio frequency field generated by the reading machine. The information is contained in the quantity of the field pulses between two field gaps (figure 3). The sent bits are recognized by decoding the count indication reached between two pauses. It is also possible to transmit control signals together with the data information. For this, other counting indications are defined. The transition from read mode to send mode is
ES 2 172 769 T3 directed through a field gap, switching the chip card to "send mode" and collecting the data that follows. The data transmission is checked for the validity and quantity of the data bits. Send mode is exited when no pause is detected after maximum 64 field pulses.
In write mode, data is first transmitted from the base station to the responder and then programmed into the EEPROM.
As in the send mode, the correct transmission of the data bits is also checked here. If the memory area to be described is secured against manipulation by programming the corresponding blocking bit, it is registered by the IDIC and a programming is prevented (figure 4). If all the logical checks described are positive, the necessary programming voltage of approx. 16 V internally and is measured analogously. This transmission also takes place during the entire programming process. In the event of a fault, the IDIC immediately interrupts the programming and goes into read mode, in which it transmits the ID code. This special behavior is registered by the base station. In a successful process, the block that has just been programmed is retransmitted to the base station for verification.
Advantage
Checks are carried out prior to programming.
- The data transmission must be correct, that is, the number of transmitted bits and the pulses between the field gaps must be correct.
- The password protection must not be programmed.
- The blocking bit must not be programmed.
- The maximum voltage must be sufficient (to program the EEPROMs, approx. 16 V is required). It is checked before and after programming.
In case of failure, the IC goes immediately, that is, prematurely, to read mode and sends data. The base station can detect this fact.
To protect the stored data, several mechanisms have been installed:
- lock function
- User password protection
- UV protection
Different memory areas can be protected against tampering by separately programming lock bits. This lock function cannot be canceled.
If passcode protection is enabled, certain data can only be programmed into memory or read from memory after the correct passcode is sent. For example, only a password known to the corresponding client is programmed before the responder is delivered, so that an unauthorized user does not have access to the memory.
If an attacker tries to evade the password protection or the blocking function by erasing the EEPROM, for example by ultraviolet radiation, the ultraviolet protection is activated. AND<sup>or</sup>This prevents a memory that has been completely erased once from being reprogrammed.
Contents2
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
29 members in 7 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 19637319 | Germany | A | |
| 19637319 | Germany | A | |
| 19961037319 | Germany | – | |
| 19637319 | – | – | – |
| DE1996137319 | – | – | – |
Members29
| Document | Office | Kind | |
|---|---|---|---|
| WO9811496A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO9811505A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO9811553A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO9811689A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU4458297A | Australia | A | |
| AU4458397A | Australia | A | |
| AU4622897A | Australia | A | |
| AU4702997A | Australia | A | |
| WO9811689A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP0925548A1 | European Patent Office (EPO) | A1 | |
| EP0925551A1 | European Patent Office (EPO) | A1 | |
| EP0925665A2 | European Patent Office (EPO) | A2 | |
| JP2001500685A | Japan | A | |
| JP2001501051A | Japan | A | |
| JP2001501391A | Japan | A | |
| EP0925548B1 | European Patent Office (EPO) | B1 | |
| DE59703244D1 | Germany | D1 | |
| ES2157089T3 | Spain | T3 | |
| US6272321B1 | United States of America | B1 | |
| EP0925665B1 | European Patent Office (EPO) | B1 | |
| DE59706402D1 | Germany | D1 | |
| EP0925551B1 | European Patent Office (EPO) | B1 | |
| US6426692B1 | United States of America | B1 | |
| DE59707804D1 | Germany | D1 | |
| ES2172769T3This record | Spain | T3 | |
| ES2179369T3 | Spain | T3 | |
| US6510517B1 | United States of America | B1 | |
| JP3867251B2 | Japan | B2 | |
| JP3890510B2 | Japan | B2 |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Definitive protectionFG2A | FG2A |
Numbers
- Publication
- 2172769
- Publication, DOCDB
- 2172769
- Publication, EPODOC
- ES2172769T
- Application
- 97909259
- Application, DOCDB
- 97909259
- Application, EPODOC
- ES19970909259T
Titles2
- Spanish
- PROCEDIMIENTO PARA LA AUTENTIFICACION CRIPTOLOGICA EN UN SISTEMA DE IDENTIFICACION DE RADIOFRECUENCIA.
- English
- PROCEDURE FOR CRYPTOLOGICAL AUTHENTICATION IN A RADIO FREQUENCY IDENTIFICATION SYSTEM.
Classification
- CPC, 9
- G07F7/1008
- G06K7/0008
- G06K19/0723
- G06K19/0726
- G06Q20/341
- G06Q20/40975
- G11C7/1048
- G11C7/1051
- G11C11/419
- IPC, 13
- E05B49 00
- G01S13 75
- G01S13 76
- G01S13 79
- G06K7 00
- G06K19 07
- G07F7 10
- G11C7 10
- G11C11 419
- H04B1 59
- H04B5 48
- H04L1 12
- H04L9 32