Method of cryptological authentification in a scanning identification system
Abstract
The inventive method of cryptological authentification, applied in a scanning identification system with a station base which powers a transponder connected to the object to be identified across the alternating field of an enquiry signal, includes the following steps. For virtually all communications from the base station to the transponder, the base station transmits an enquiry signal. Upon receiving the enquiry signal from the base station, the transponder indicates an identification number stored therein. The base station then encodes a base station generated first bit sequence using a key bit sequence allocated to the transponder identification number and transmits to the transponder the second bit sequence thus obtained. Upon reception of the second bit sequence, the transponder generates from the second bit sequence a supervisory bit sequence which it sends to the base station once it has received the complete second bit sequence. The supervisory bit sequence is intended to check whether the second bit sequence was correctly received. For the purpose of cryptographic authentification, the transponder encodes the first bit sequence reconstructed from the second bit sequence using the key bit sequence allocated to said transponder and transmits to the base station the third bit sequence thus obtained. While the transponder encodes the second bit sequence and converts it to a third bit sequence, the base station verifies using the checking bit sequence, whether a mistake has occured when transferring the second bit sequence, and possibly interrupts the on-going encoding process in the transponder. This may abort the authentification process as no valid result can be reckoned with and allows for time to be saved for relaunching the whole authentification process.

Term
No projected expiry on record.
- Priority and filed
- Published
- Today
6 claims: 2 independent, 4 dependent
- 1Patentansorüche 1. verfahren zur kryptologischen Authentifizierung in einem Radiofrequenz- Identifikations-system mit einer Basisstation und einem Transponder, wobei die Basisstation eine erste Bitfolge generiert und an den Transponder sendet, der Transponder aus der ersten Bitfolge mittels eines Kryptographischen Schlüssels eine zweite Bitfolge generiert und diese als Antwort zur Basis zurücksendet, woraufhin die Basis aufgrund dieser Antwort die Nutzungsberechtigung überprüft, dadurch gekennzeichnet, daß der Transponder sofort nach Erhalt der ersten Bitfolge eine Antwort generiert, aus der die Basisstation erkennt, ob bei der Übertragung der ersten Bitfolge ein Fehler aufgetreten ist.
- 2Verfahren zum überprüfen einer Nutzungsberechtigung nach Anspruch 1, dadurch gekennzeichnet, daß die Basisstation den laufenden Vorgang des Generierens der zweiten Bitfolge durch den Transponder abbricht, wenn bei der Übertragung der ersten Bitfolge ein Fehler aufgetreten ist.
- 3Verfahren zum Überprüfen einer Nutzungsberechtigung nach Anspruch 1 oder 2, dadurch gekennzeichnet, daß die Länge der zweiten Bitfolge die Hälfte der Länge der ersten Bitfolge beträgt.
- 4Verfahren zur kryptologischen Authentifizierung in einem Radiofrequenz- Identifikations-System mit einer Basisstation, die einen mit dem zu identifizierenden Objekt verbundenen Transponder über das Wechselfeld eines Abfragesignals mit Energie versorgt, mit folgenden Verfahrensschritten:die Basisstation erzeugt ein Abfragesignal;• der Transponder antwortet bei Empfang des von der Basisstation gesendeten Abfragesignals mit einer in seinem Speicher abgelegten Identifikationsnummer;• die Basisstation verschlüsselt eine von ihr generierte ersten Bitfolge anhand einer der Identifikationsnummer des Transponders zugeordneten Schlüsselbitfolge und sendet die so erhaltene zweite Bitfolge zum Transponder;beim Empfang der zweiten Bitfolge generiert der Transponder aus der zweiten Bitfolge eine Kontrollbitfolge und sendet diese nach vollständigen Empfang der zweiten Bitfolge an die Basisstation der Transponder rekonstruiert aus der zweiten Bitfolge die erste Bitfolge und verschlüsselt diese anhand der dem Transponders zugeordneten schlusselbitfolge und sendet die so erhaltene dritte Bitfolge zur Basisstation;• noch während der Transponder die zweite Bitfolge zur dritten Bitfolge verschlüsselt überprüft die Basisstation anhand der Kontrollbitfolge ob bei der Übertragung der zweiten Bitfolge ein Fehler aufgetreten ist, unterbricht gegebenenfalls die laufende Verschlüsselung im Transponder • die Basisstation prüft die Gültigkeit der empfangenen dritten Bitfolge.
- 5Verfahren zur kryptologischen Authentifizierung nach Anspruch 4, dadurch gekennzeichnet, daß der Transponder die Länge der dritten Bitfolge vor dem Senden an die Basisstation halbiert.
- 6Verfahren zur kryptologischen Authentifizierung nach Anspruch 4 oder 5, dadurch gekennzeichnet, daß die Basisstation zu Beginn des Verfahrens sofort eine von ihr generierte ersten Bitfolge anhand einer Ihr und dem Transponder zugeordneten Schlüsselbitfolge verschlüsselt und die so erhaltene zweite Bitfolge zum Transponderder sendet anstatt den Empfang der Identifikationsnummer des Transponder abzuwarten.
Independent claims6
85 paragraphs, as filed
p0001description
p0002process for cryptologic authentication in a Radiofreαuenz-, id-svstem
p0003The invention relates to methods for cryptologic authentication in a radio frequency identification system.
p0004When identifying persons, animals and objects, a system has in recent years proved, in which a (stationary or portable) reader, and reader or base station called, supplies a related object to be identified transponder via an alternating field with energy whereupon the transponder responds by transmitting the data stored in it. Due to the frequency range used is also called radio frequency identification systems, short FID.
p0005An RFID-τransponder generally consists of an antenna coil and an integrated circuit, all the necessary electronic circuit blocks, such as. For example, for power supply, clock generation, for flow control and for storing the necessary data for identification data includes. The parallel to the antenna coil capacity is also often part of the integrated circuit. However, it can also be formed by a discrete component.
p0006The RFID reader consists of a resonant circuit having a transmitting coil and a capacitor, which is driven by a driver stage with a signal having a generally fixed frequency (z. B. 125 kHz). The reader also includes electronic circuit blocks in order to detect the data sent by the absorption modulation by the transponder and to data and commands, for. example, by modulation of the field to be transmitted to the transponder.
p0007Reader and transponder form a loosely coupled transformer in the data or in the transmission of energy. Therefore, the power transmission is relatively small.
p0008The operating range for the contactless transmission of energy and data is affected by the following conditions:
p0009Transmission energy (limited by law) coil dimensions • noise level around
p0010Match the resonant frequencies
p0011modulation
p0012Voltage drop across the rectifier
p0013Transmission method used
p0014For example, in the application in the form of an immobilizer result from the small arranged around the ignition lock around transmit coil extremely unfavorable transmission conditions. Therefore it is necessary to optimize the system to minimal losses back. The crucial factor is:
p0015• Same resonant frequency of base station and transponder • temporally optimized transmission protocols
p0016• Minimal losses during power transmission
p0017• Maximum modulation when transmitting data to the base station (Read)
p0018• optimized data transmission to the transponder (Send)
p0019When starting a vehicle, the user takes a period of more than 150 ms, by turning the ignition key to start the engine, was a time delay. It follows that the entire transmission protocol must be passed in this very short period. It applies several points to consider, on the one hand should provide the correct result a unique data transmission, on the other hand, additional functions should like authentication by an algorithm in the shortest possible time to run.
p0020Object of the invention is to provide a process for cryptologic authentication in a radio frequency identification system that runs in the shortest possible time.
p0021This object is achieved by a method of cryptological authentication in a radio frequency identification system having the features of claims 1 and 4. FIG. The benefits of the invention is carried geäß the features of the dependent claims.
p0022The method of cryptological authentication in a radio frequency ldentifikations system having a base station serving an associated with the object to be identified transponder via the alternating field of an interrogation signal energy, includes the following method steps.
p0023For the substantially all communications between base station and transponder, the base station produces an interrogation signal. The transponder responds upon receipt of the transmitted interrogation signal from the base station with an identification number stored in its memory. Then, the base station encrypts a generated from their first bit sequence using a key bit sequence associated with the identification number of the transponder and sends the thus obtained second bit sequence to the transponder.
p0024Upon receipt of the second bit sequence, the transponder generates a bit sequence from the second Kontrollbitfolge and sends it after complete reception of the second bit sequence to the base station. This Kontrollbitfolge used to check the correct reception of the second bit sequence, for cryptographic authentication encrypts the transponder reconstructed from the second bit sequence first bit sequence based on the allocated to the transponder key bit sequence and sends the third bit sequence thus obtained to the base station. Still encrypts the second bit sequence to the third bit sequence during the transponder checks the base station on the basis of Kontrollbitfolge whether the transmission of the second bit sequence, an error has occurred interrupts, if appropriate, the current encryption in the transponder can thus be interrupted the current authentication, since not having a correct result can be expected. It is obtained at the start time of a renewed passage of the authentication process
p0025in the other case, the base station checks the validity of the received third bit sequence.
p0026A further shortening of the time period for authentication is achieved in that the transponder halves the length of the third bit sequence prior to sending to the base station
p0027in one embodiment, the process encrypts the base station at the beginning of the process immediately based on a her and allocated to the transponder of their generated first string Schlusselbitfolge and sends the thus obtained second bit sequence immediately to Transponderder instead only await receipt of the identification number of the transponder. Thereby, a further shortening of the time period for authentication is obtained.
p0028Brief Description of the Figures
p00291 shows a flowchart of the method of cryptological
p0030Authentication in a radio frequency ldentifikations- Svstem on the transponder side;
p0031Figure 2 shows the flow of the process in an immobilizer for a
p0032Motor vehicle;
p0033Figure 3 shows various signal get lost in the communication between base station and transponder; Figure 4 shows a detailed flowchart of an RFID system
p0034Cryptologic authentication.
p0035the method according to the invention with the aid of the figures will be explained by way of example in the following. To explain the principle of a cryptologic authentication is developed on the example of the immobilizer specifically of TEMlC for high safety requirements, such and optimized procedures TIME (TEMlC immobilizer incrvption) received, which is characterized by the following features.:
p0036• Safe and fast authentication (<100 ms)
p0037• Application Optimized high-security algorithm
p0038• Customized generation of unique keys
p0039Thereby, a high degree of safety, achieved both in the data transmission as well as for the actual encryption in connection with an extremely short time authentication. Figure 1 shows the optimized from TEMlC on minimum time through authentication flow. The special is, first, the need for the calculation of the algorithm low period to interrupt at any time (Encryption time 30 ms), second, the reduction of the response from eight to four bytes by a special process and, thirdly, the ability to drain the event of an error.
p0040When initializing the RFID system the transponder and the base station is a joint, the function of the crypto-algorithm determining and specially generated, 120 bits long cryptologic key, the so-called Key Crvpto passed. This key is unique in the whole system. No other RFID system, ie no more base station and no further transponder has this key.
p0041in operation the transponder transmits to the synchronization (setup) with the base station a uniquely determined bit string (String) fixed-length (depending on the application, eg., 64 bits), called the ID code or short ID, to the base station. This ID is usually used for key identification. This is required when different transponders should cooperate (with different crypto keys) with a base station.
p0042If the authentication protocol being used is a challenge and response protocol, as shown in Figure 2, with the feature that "Known piaintext" - and "choosen Plaintext' attacks are unsuccessful.
p0043The base station generates a 64 bit random number Z and encrypts it using a 32-bit partial key that is generated from the Crypto-Key. The resulting 64 bit random result - the so-called challenge - is sent to the transponder. Only one transponder, which has the same key portion, is able to reconstruct the random value. An observer of the Protocol is therefore not capable of the random number z elicit. The transponder and the base station encrypt the challenge using the 120 bit crypto keys, using a specially developed algorithm AUT 64 a 32-bit string is respectively from 64 bit encryption result generated. The transponder sends this string - the so-called Response - to the base station. If they match the transmitted response and the generated strings, the base station accepts the authenticity of the transponder.
p0044The algorithm AUT 64 used is a byte-oriented block cipher generated from 64 bits using a 120 bit Crypto Keys output-strings. (The encryption result here) in a 64-bit output string transferred - A 64 bit lnputstring (here the random number Z) is encryption - in 24 rounds. In each round, another is used generated from the Crypto Key key. Through this procedure as the high level of safety is achieved. Statistical analyzes confirm the impressive fashion. Substance of this is essentially a non-linear encryption, each round different (key controlled) is selected.
p0045Key generation: To generate the 120-bit crypto-keys provides TEMlC a program available which uses inter alia the Data Encryption Standard (DES) as a random number generator. This ensures that only the user has knowledge of the crypto key. The used for the AUT 64 120 bits Crypto Key consists of the components Family-Key (24 bits), User-Key (64 Bit) and Random Key (32 Bit). The user key is generated by the manufacturer by means of a Serial-Kev.
p0046Random-Key: The random key is generated by the DES. The associated 56 bit DES key and the DES lnput determines the user so that TEMlC has no information on the DES output and thus on the generated random key.
p0047Family-Key: The respective keys are generated by means of a special program, is in particular guaranteed that different users get different sets of Family-Keys of length 24 bits. Each user is doing 12 bits assigned so that they can choose to pay a portion of the 16th This is the only knowledge that has TEMlC over the coming later used keys.
p0048User Key: Using a special process, it generates a unique 64-bit random number, which means that each user key is generated only once. A replay place only after 20.9 * 10<sup>12</sup> generated user keys instead.
p0049Shortening of the transmission protocol by:
p0050• It must not only the sending of the entire ID code (ID) to wait, but the challenge could be sent after the power-on-reset -> save 20ms.
p0051• during the calculation of the algorithm (Encryption, encryption of the challenge) is sent a check sum to the base station. This will determine whether the challenge has been transmitted correctly, this is not correct, the Encryption can immediately send a Gap to be interrupted and a new
p0052Challenge is sent. It is necessary to wait so not only the inevitable wrong and therefore useless response.
p0053• The result of the encryption is like the mput (the challenge) of 8 bytes. These 64 bits are linked, for example, by an XOR function, so that only 4 bytes as a result (response) to
p0054Base station need to be retransmitted. -> Halving of the time (in this example from 20 ms to 10 ms). High security algorithm:
p0055The random number, ie the input for the AUT 64 algorithm is not transmitted directly, but first encrypted (result = the Challenge) -> no choosen plaintext attacks possible. • The algorithm AUT 64 is run 24 times and it varies in each round, ie the non-linear encryption is selected in each round different (key controlled). -> Algorithm difficult "to break".
p0056Key generation:
p0057• A key part - the User-Key - is produced using a special process so that it is unique. A replay place only after 20.9 * 10<sup>12</sup> generated user keys instead.
p0058• Only the user has influence on the generation of random Kev - neither TEMlC anybody else about information. • When Family-Key TEMlC forgives a portion of each user. This user, z. B. a car manufacturer can choose from a range of 16 numbers and assign therefore each vehicle series (z. B. every vw golf) a particular Family κey-τeilschlüssel. -> Each user gets a certain part of the key area, which is also the accessing to the key algorithm is different (eg VW and.
p0059Opel have different keys).
p0060The data transfer process in the described here can be divided into three areas:
p0061• Read Mode = data transmission from the transponder to the base station • send-mode = data transmission from the base station to
p0062transponder
p0063• write-mode = data transmission from the base station to the transponder with subsequent programming
p0064To ensure data integrity, ie, the manipulation-free and thus unaltered data transmission in the individual modes, different ways to apply. in read mode, are read out and transmitted to the base station data (ID code) from the EEPROM memory of the transponder. The first 8 bits here represent a custom header that is programmed by TEMlC and secured against manipulation. The other bits can be programmed by the customer and normally include a serial number including checksum, so that a faulty transmission of the code can be detected.
p0065Advantage: header and checksum are checked.
p0066The sending mode is used in the transmission of the starting value (challenge) for authentication. The transponder checks the correct number of bits transmitted and the field clocks between the field gaps. It then sends a check sum of the number of transmitted "ones" formed to verify the correct transmission to the base station (Figure 5). If the checksum is not correct, so it is possible to interrupt the authentication process and to start again.
p0067advantageous: Bits and clock number between the field gaps and sending the checksum are checked.
p0068The Temic write process based on the ON / OFF keying of generated by the reader RF field. The information is in the number of
p0069Field clocks between two field gaps included (Figur3). By decoding the reached between two pauses count are the transmitted
p0070Bits detected. It is also possible, in addition to the data information
p0071to transmit control signals. These additional counts are defined. The transition from the read mode to the transmit mode is a
p0072initiated field gap, whereupon the smart card to "send mode" switches and the subsequent data recording. The data transfer is on
p0073Validity and number of data checks. The sending mode is exited when a break is not recognized by the latest 64 field clocks.
p0074In write mode, the data is first transferred from the base station to the transponder and then programmed into the EEPROM. As in the send mode, the correct transmission of the data bits is also being considered in this case. Is to be described storage area protected against manipulation by the corresponding lock bit is set, it will be registered by the IDIC and prevents programming (Figure 4). If all logical checks described are positive, so the need for programming high programming voltage of approximately 16 v internally generated and measured analogously. This check is also during the entire programming process instead, in case of failure interrupts the IDIC programming immediately and goes into read mode where it transmits the ID code. This particular behavior is recorded by the base station. For a correct functioning of newly programmed block is transferred back for verification to the base station.
p0075Advantage: checks before being programmed.
p0076• transmission of data must be correct, ie, number of bits transmitted and clocks between the field gaps have to be right.
p0077Password-protection must not be set.
p0078Lockbit must not be set.
p0079HV voltage must be large enough (for programming the EEPROMs are about 16 v needed). This is the before and wähend
p0080Programming checked.
p0081in case of failure of the IC goes immediately, ie, early in the read mode and sends data. This can be recognized by the base station.
p0082To protect the data stored several mechanisms have been implemented:
p0083• lock function Password-protection UV protection
p0084different memory areas can be protected by lock bits separately against manipulation prevail. This lock function can not be undone. the password protection is activated, certain data may be programmed only after sending the correct passwords to memory or read from memory. For example, a known only to the respective customer password before shipping the transponder is programmed, so that an unauthorized user has no access to the memory.
p0085If an attacker trying to bypass the password protection or the lock function by deleting the EEPROMs, z. B. by UV radiation, so the UV protection in force. This prevents the reprogramming of a once completely erased memory.
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US7239657B1 | Cited by | United States of America | Applicant |
| WO0137202A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| DE102018002157A1 | Cited by | Germany | Search report |
| EP0683293A1 | Cites | European Patent Office (EPO) | International search |
| EP0723896A2 | Cites | European Patent Office (EPO) | International search |
| US3605091A | Cites | United States of America | International search |
| DE4317380A | Cites | Germany | International search |
29 members in 7 offices
Members29
| Document | Office | Kind | |
|---|---|---|---|
| WO9811496A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO9811505A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO9811553A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO9811689A2This record | World Intellectual Property Organization (WIPO) | A2 | |
| AU4458297A | Australia | A | |
| AU4458397A | Australia | A | |
| AU4622897A | Australia | A | |
| AU4702997A | Australia | A | |
| WO9811689A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP0925548A1 | European Patent Office (EPO) | A1 | |
| EP0925551A1 | European Patent Office (EPO) | A1 | |
| EP0925665A2 | European Patent Office (EPO) | A2 | |
| JP2001500685A | Japan | A | |
| JP2001501051A | Japan | A | |
| JP2001501391A | Japan | A | |
| EP0925548B1 | European Patent Office (EPO) | B1 | |
| DE59703244D1 | Germany | D1 | |
| ES2157089T3 | Spain | T3 | |
| US6272321B1 | United States of America | B1 | |
| EP0925665B1 | European Patent Office (EPO) | B1 | |
| DE59706402D1 | Germany | D1 | |
| EP0925551B1 | European Patent Office (EPO) | B1 | |
| US6426692B1 | United States of America | B1 | |
| DE59707804D1 | Germany | D1 | |
| ES2172769T3 | Spain | T3 | |
| ES2179369T3 | Spain | T3 | |
| US6510517B1 | United States of America | B1 | |
| JP3867251B2 | Japan | B2 | |
| JP3890510B2 | Japan | B2 |
11 legal events, as 2 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Wipo information: grant in national officeWWG | WWG | WO | |
| Wipo information: published in national officeWWP | WWP | WO | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Entry into the national phaseENP | ENP | JP | |
| Wipo information: entry into national phaseWWE | WWE | WO | |
| Ep: the epo has been informed by wipo that ep was designated in this application121 | 121 | WO | |
| Designated statesAK | AK | WO | |
| Designated countries for regional patentsAL | AL | WO | |
| Request for preliminary examination filed prior to expiration of 19th month from priority date (pct application filed before 20040101)DFPE | DFPE | WO | |
| Designated statesAK | AK | WO | |
| Designated countries for regional patentsAL | AL | WO |
Numbers
- Publication
- 98/11689
- Application
- 9705012
Titles3
- English
- METHOD OF CRYPTOLOGICAL AUTHENTIFICATION IN A SCANNING IDENTIFICATION SYSTEM
- German
- VERFAHREN ZUR KRYPTOLOGISCHEN AUTHENTIFIZIERUNG IN EINEM RADIOFREQUENZ-IDENTIFIKATIONS-SYSTEM
- French
- PROCEDE D'AUTHENTIFICATION CRYPTOLOGIQUE DANS UN SYSTEME D'IDENTIFICATION A BALAYAGE
Classification
- CPC, 9
- G07F7/1008
- G06K7/0008
- G06K19/0723
- G06K19/0726
- G06Q20/341
- G06Q20/40975
- G11C7/1048
- G11C7/1051
- G11C11/419
- IPC, 13
- E05B49 00
- G01S13 75
- G01S13 76
- G01S13 79
- G06K7 00
- G06K19 07
- G07F7 10
- G11C7 10
- G11C11 419
- H04B1 59
- H04B5 48
- H04L1 12
- H04L9 32
Designated states24
- Regional, 17
- Austria
- Belgium
- Switzerland
- Germany
- Denmark
- Spain
- Finland
- France
- United Kingdom
- Greece
- Ireland
- Italy
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Portugal
- Sweden
- National, 7
- Australia
- Brazil
- Japan
- Republic of Korea
- Mexico
- New Zealand
- United States of America