IP Library Granted Patent US 10,664,670
Granted Patent B1
US 10,664,670 · App. 16/203,653 · Granted May 26, 2020

RFID tag and reader authentication by trusted authority

Inventors: Christopher J. Diorio (Shoreline, WA); Scott A. Cooper (Seattle, WA); Matthew Robshaw (Seattle, WA)
Assignee: Inpinj, Inc.
G06K7/10297H04L9/3273H04L2209/805
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,664,670
App. No.
16/203,653
Granted
May 26, 2020
Kind
B1
Abstract

A Radio Frequency Identification (RFID) reader containing a reader key authenticates an RFID tag containing a tag key by receiving a tag identifier from the tag; challenging the tag with a tag challenge; receiving a tag response based at least on the tag challenge and the tag key but not including the tag key; sending a second message including at least the tag identifier and the tag response to a verification authority; and receiving a reply from the verification authority. The reader and the verification authority may mutually authenticate each other before, during, or after the tag authentication process. The verification authority may notify a designated party if a response is incorrect.

Claims (76)

1. A Radio Frequency Identification (RFID) system component configured to authenticate RFID tags, the component comprising:

a reader interface configured to be communicatively coupled to an RFID reader;

a network interface configured to facilitate communication with one or more network components including one or more verification authorities; and

a processor block coupled to the reader interface and the network interface and configured to:

determine a first challenge sent by the RFID reader to a tag;

receive, via the reader interface, a first identifier from the tag and a first response cryptographically generated from at least the first challenge and a first key contained in the tag;

identify a verification authority suitable to authenticate the first response;

authenticate, via the network interface, the verification authority; and

after authenticating the verification authority, send, via the network interface, a first message including at least the first identifier and the first response to the authenticated verification authority.

2. The component of claim 1 , wherein the processor block is configured to determine the first challenge by at least one of:

generating the first challenge;

receiving the first challenge from the RFID reader; and

receiving the first challenge from the verification authority.

3. The component of claim 1 , wherein the processor block is configured to identify the verification authority by at least one of:

determining a verification authority identifier from at least one of the first identifier and the first challenge;

receiving, via the reader interface, the verification-authority identifier from the tag; and

retrieving the verification authority identifier from a memory coupled to the RFID reader.

4. The component of claim 1 , wherein the processor block is configured to authenticate the verification authority by:

sending, via the network interface, a second challenge to the verification authority;

receiving, via the network interface, a second response from the verification authority; and

authenticating the second response based on at least the second challenge and a second key associated with the verification authority.

5. The component of claim 1 , wherein the processor block is configured to authenticate the verification authority by at least one of:

verifying the authenticity of an electronic signature from the verification authority; and

determining that the verification authority knows a shared state or data.

6. The component of claim 1 , wherein the processor block is further configured to authenticate at least one of the component and the RFID reader to the verification authority.

7. The component of claim 6 , wherein the processor block is configured to at least one of:

send a response to a third challenge from the verification authority, the response based on a third key associated with at least one of the processor block and the RFID reader;

sign the first message with an electronic signature; and

indicate, to the verification authority, a shared state or data.

8. A Radio Frequency Identification (RFID) remote component configured to authenticate RFID tags, the component comprising:

a network interface configured to couple to at least one network and to facilitate communication with one or more network components including one or more verification authorities; and

a processor block coupled to the network interface and configured to:

determine a first challenge sent by an RFID reader to a tag;

receive, via the network interface, a first identifier from the tag and a first response cryptographically generated from at least the first challenge and a first key contained in the tag, wherein the first identifier and the first response are received by the RFID reader;

identify a verification authority suitable to authenticate the first response;

authenticate, via the network interface, the verification authority; and

after authenticating the verification authority, send, via the network interface, a first message including at least the first identifier and the first response to the authenticated verification authority.

9. The component of claim 8 , wherein the processor block is configured to identify the verification authority by at least one of:

determining a verification authority identifier from at least one of the first identifier and the first challenge;

receiving, via the network interface, the verification authority identifier from the tag; and

retrieving the verification-authority identifier from a memory coupled to the RFID reader.

10. The component of claim 8 , wherein the processor block is configured to authenticate the verification authority by:

sending, via the network interface, a second challenge to the verification authority;

receiving, via the network interface, a second response from the verification authority; and

authenticating the second response based on at least the second challenge and a second key associated with the verification authority.

11. The component of claim 8 , wherein the processor block is configured to authenticate the verification authority by at least one of:

verifying the authenticity of an electronic signature from the verification authority; and

determining that the verification authority knows a shared state or data.

12. The component of claim 8 , wherein the processor block is further configured to authenticate at least one of the component and an RFID reader coupled to the at least one network to the verification authority.

13. The component of claim 12 , wherein the processor block is configured to at least one of:

send a response to a third challenge from the verification authority, the response based on a third key associated with at least one of the processor block and the RFID reader;

sign the first message with an electronic signature; and

indicate, to the verification authority, a shared state or data.

14. A Radio Frequency Identification (RFID) remote component configured to authenticate RFID tags, the component comprising:

a network interface configured to couple to at least one network and to facilitate communication with one or more network components including one or more verification authorities; and

a processor block coupled to the network interface and configured to:

receive, via the network interface, a first identifier from the tag and a first response cryptographically generated from at least a first key contained in the tag, wherein the first identifier and the first response are received by an RFID reader in response to a challenge sent by the RFID reader to the tag;

identify a verification authority suitable to authenticate the first response; and

send, via the network interface, a first message including at least the first identifier and the first response to the verification authority.

15. The component of claim 14 , wherein the processor block is configured to identify the verification authority by at least one of:

determining a verification authority identifier from at least one of the first identifier and the first challenge;

receiving, via the network interface, the verification authority identifier from the tag; and

retrieving the verification-authority identifier from a memory coupled to the RFID reader.

16. The component of claim 14 , wherein the processor block is further configured to authenticate the verification authority by:

sending, via the network interface, a first challenge to the verification authority;

receiving, via the network interface, a second response from the verification authority; and

authenticating the second response based on at least the first challenge and a second key associated with the verification authority.

17. The component of claim 14 , wherein the processor block is configured to authenticate the verification authority by at least one of:

verifying the authenticity of an electronic signature from the verification authority; and

determining that the verification authority knows a shared state or data.

18. The component of claim 14 , wherein the processor block is configured to receive the first identifier and the first response from an RFID reader coupled to the at least one network.

19. The component of claim 18 , wherein the processor block is further configured to authenticate at least one of the component and the RFID reader to the verification authority.

20. The component of claim 19 , wherein the processor block is configured to at least one of:

send a third response to a second challenge from the verification authority, the third response based on the second challenge and a third key associated with at least one of the processor block and the RFID reader;

sign the first message with an electronic signature; and

indicate, to the verification authority, a shared state or data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 29, 2018
From: DIORIO, CHRISTOPHER J.; COOPER, SCOTT A.; ROBSHAW, MATTHEW
To: IMPINJ, INC.
Reel/Frame 047614/0192 →
Continuity (7)
Continuation 15683506 · Aug 22, 2017
Continuation 15293218 · Oct 13, 2016
Continuation 14946797 · Nov 20, 2015
Continuation In Part 14341401 · Jul 25, 2014
Continuation 13396889 · Feb 15, 2012
Provisional Application 61480543 · Apr 29, 2011
Provisional Application 61443842 · Feb 17, 2011
Cited By (4)
US 12,223,814 US 12,524,640 US 12,536,401 US 12,665,761