IP Library › Granted Patent US 9,641,515
Granted Patent B2
US 9,641,515 · App. 14/758,950 · Granted May 2, 2017

RFID tag and method for operating an RFID tag

Inventors: Markus Dichtl (München, DE); Erwin Hess (Ottobrunn, DE); Bernd Meyer (München, DE)
Assignee: Siemens Aktiengesellschaft
H04L63/0823G06F17/30879G06F21/445G06K19/07318H04L9/30
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,641,515
App. No.
14/758,950
Granted
May 2, 2017
Kind
B2
Abstract

The invention relates to an RFID tag, which comprises a receiving means, a first and a second verification means, and a transmitting means. The receiving means is designed to receive a challenge message sent by an RFID reading device. Said challenge message comprises a challenge data set, which has a digital certificate issued for the RFID reading device by a certification authority and signed by means of a private key of the certification authority and which has a request message, and a digital signature at least of the request message, which digital signature is generated by means of a private key of the RFID reading device. The first verification means is designed to verify the digital certificate by means of a public key of the certification authority. The second verification means is designed to verify the digital signature by means of a public key of the RFID reading device. The transmitting means transmits a response message to the REID reading device if the certificate and the digital signature are verified. By verifying the challenge message, the RFID tag can ensure that the RFID tag transmits a response message only to such a requesting REID reading device that is actually authorized to communicate with said RFID tag.

Claims (44)

1. An RFID tag for a product, the RFID tag comprising:

a receiver configured to receive a challenge message transmitted by an RFID reading device, the challenge message comprising a challenge data set, the challenge data set comprising a digital certificate issued for the RFID reading device by a certification body and signed with a private key of the certification body, the challenge data set further comprising a request message and a digital signature, at least of the request message, generated by a private key of the RFID reading device;

a first verification device configured to verify the digital certificate using a public key of the certification body;

a second verification device configured to verify the digital signature at least of the request message using a public key of the RFID reading device; and

a transmitter configured to transmit a response message to the RFID reading device when the digital certificate and the digital signature are verified.

2. The RFID tag of claim 1 , wherein the transmitter is configured to transmit the response message to the RFID reading device only when the certificate and the digital signature are verified.

3. The RFID tag of claim 1 , wherein a certificate data set included in the digital certificate comprises at least an identification number of the RFID reading device and authorization information to indicate a temporally, geographically, or temporally and geographically limited authorization of the RFID reading device to communicate with RFID tags, and

wherein the RFID tag further comprises a checking device configured to check the authorization information contained in the certificate data set.

4. The RFID tag of claim 3 , wherein the transmitter is configured to transmit the response message to the RFID reading device only when the certificate and the digital signature are verified and the check of the authorization information contained in the certificate data set is positive.

5. The RFID tag of claim 3 , wherein the authorization information comprises location information indicating a geographical area in which the RFID reading device is authorized to communicate with RFID tags, and time information indicating a time period in which the RFID reading device is authorized to communicate with RFID tags.

6. The RFID tag of claim 5 , wherein the checking device includes a first checking unit and a second checking unit,

wherein the first checking unit is configured to provide a first check result by comparing the location information contained in the certificate data set with current location information defined by the RFID tag, and

wherein the second checking unit is configured to provide a second check result by comparing the time information contained in the certificate data set, in the request message, or in the certificate data set and in the request message with a current time defined by the RFID tag (B).

7. The RFID tag of claim 6 , wherein the transmitter is configured to transmit the response message to the RFID reading device only when the certificate and the digital signature are verified, the first check result is positive, and the second check result is positive.

8. The RFID tag of claim 3 , wherein the certificate data set comprises the public key of the RFID reading device.

9. The RFID tag of claim 1 , further comprising a storage device configured to store the public key of the RFID reading device provided by the certification body.

10. The RFID tag of claim 1 , wherein the challenge message comprises the challenge data set, a hash value formed by the challenge data set, and the digital signature that is generated depending on the hash value and the private key of the RFID reading device.

11. The RFID tag of claim 1 , wherein a certificate data set included in the digital certificate comprises at least an identification number of the RFID reading device and authorization information to indicate a temporally, geographically, or temporally and geographically limited authorization of the RFID reading device to communicate with RFID tags, and

wherein the RFID tag further comprises a checking device configured to check the authorization information contained in the certificate data set.

12. The RFID tag of claim 11 , wherein the transmitter is configured to transmit the response message to the RFID reading device only when the certificate and the digital signature are verified and the check of the authorization information contained in the certificate data set is positive.

13. A system comprising:

a plurality of RFID reading devices and a plurality of RFID tags, wherein an RFID tag of the plurality of RFID tags is for a product and comprises:

a receiver configured to receive a challenge message transmitted by an RFID reading device, the challenge message comprising a challenge data set, the challenge data set comprising a digital certificate issued for the RFID reading device by a certification body and signed with a private key of the certification body, the challenge data set further comprising a request message and a digital signature, at least of the request message, generated by a private key of the RFID reading device;

a first verification device configured to verify the digital certificate using a public key of the certification body;

a second verification device configured to verify the digital signature at least of the request message using a public key of the RFID reading device; and

a transmitter configured to transmit a response message to the RFID reading device when the digital certificate and the digital signature are verified.

14. The system of claim 13 , wherein a certification body is provided to issue a digital certificate for a respective RFID reading device from the plurality of RFID reading devices.

15. The system of claim 13 , wherein the transmitter is configured to transmit the response message to the RFID reading device only when the certificate and the digital signature are verified.

16. A product comprising:

an RFID tag comprising:

a receiver configured to receive a challenge message transmitted by an RFID reading device, the challenge message comprising a challenge data set, the challenge data set comprising a digital certificate issued for the RFID reading device by a certification body and signed with a private key of the certification body, the challenge data set further comprising a request message and a digital signature, at least of the request message, generated by a private key of the RFID reading device;

a first verification device configured to verify the digital certificate using a public key of the certification body;

a second verification device configured to verify the digital signature at least of the request message using a public key of the RFID reading device; and

a transmitter configured to transmit a response message to the RFID reading device when the digital certificate and the digital signature are verified.

17. A method for operating an RFID tag for a product, the method comprising:

receiving a challenge message transmitted by an RFID reading device, the challenge message comprising a challenge data set, the challenge data set comprising a digital certificate issued for the RFID reading device by a certification body and signed with a private key of the certification body, the challenge data set further comprising a request message and a digital signature, at least of the request message, generated by a private key of the RFID reading device;

verifying the digital certificate using a public key of the certification body;

verifying the digital signature at least of the request message using a public key of the RFID reading device; and

transmitting a response message to the RFID reading device when the digital certificate and the digital signature are verified.

18. In a non-transitory computer-readable storage medium that stores instructions executable by a program-controlled device to operate an RFID tag for a product, the instructions comprising:

receiving a challenge message transmitted by an RFID reading device, the challenge message comprising a challenge data set, the challenge data set comprising a digital certificate issued for the RFID reading device by a certification body and signed with a private key of the certification body, the challenge data set further comprising a request message and a digital signature, at least of the request message, generated by a private key of the RFID reading device;

verifying the digital certificate using a public key of the certification body;

verifying the digital signature at least of the request message using a public key of the RFID reading device; and

transmitting a response message to the RFID reading device when the digital certificate and the digital signature are verified.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 2, 2015
From: DICHTL, MARKUS; HESS, ERWIN; MEYER, BERND
To: SIEMENS AKTIENGESELLSCHAFT
Reel/Frame 035973/0846 →
Priority Claims (1)
DE 10 2013 200 017 · Jan 2, 2013 · national
Continuity (1)
Related Publication 20150341343A1 · Nov 26, 2015