Rfid secure authentication

US2018026795A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2018026795-A1
Application numberUS-201715692110-A
CountryUS
Kind codeA1
Filing dateAug 31, 2017
Priority dateMar 14, 2013
Publication dateJan 25, 2018
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Authentication systems and methods for a population of devices each associated with an RFID tag are described. For each device, a secret key is combined cryptographically with a publicly-readable unique identifier (UID) of an RFID tag to obtain a unique authorization signature. The RFID tag is prepared utilizing the unique authorization signature as memory-access and/or tag-operation password(s). The systems and methods may safeguard against attacks whereby compromise of a single tag will not compromise the entire population of devices and may reduce or eliminate the use of inappropriate surgical devices during a surgical procedure.

First claim

Opening claim text (preview).

1 - 20 . (canceled) 21 . A method of authenticating, the method comprising: encrypting a secret key stored on a first device with a unique identification code of the first device to generate an original authentication signature at the first device; storing the original authentication signature in a memory associated with the first device; reading the unique identification code from the memory using a second device; encrypting a copy of the secret key stored on the second device with the unique identification code of the first device to generate a second authentication signature at the second device; comparing the second authentication signature to the original authentication signature; and determining authenticity of the first device based on a comparison of the second authentication signature and the original authentication signature. 22 . The method according to claim 21 , wherein the original authentication signature and the second authentication signature are generated by performing a hash function on the secret key stored in the memory or the copy of the secret key stored at the second device, respectively, and the unique identification code of the first device. 23 . The method according to claim 22 , wherein the hash function is selected from the group consisting of an SHA-1 function, an SHA-1 HMAC function, an SHA-2 function, and an MD5 function. 24 . The method according to claim 21 , wherein the original authentication signature and the second authentication signature are generated by: concatenating the unique identification code of the first device and the secret key stored in the memory or the copy of the secret key stored at the second device to create a bitstring; and performing a hash function on the bitstring. 25 . The method according to claim 24 , wherein the hash function is selected from the group consisting of an SHA-1 function, an SHA-1 HMAC function, an SHA-2 function, and an MD5 function. 26 . The method according to claim 21 , further comprising: dividing the original authentication signature into a plurality of bitstrings; and performing an XOR operation on a first bitstring of the plurality of bitstrings and on a second bitstring of the plurality of bitstrings to obtain an intermediate signature. 27 . The method according to claim 26 , further comprising: performing an XOR operation on the intermediate signature and on a third bitstring of the plurality of bitstrings. 28 . The method according to claim 21 , wherein determining authenticity of the first device further includes performing at least one of a read function, a write function, or a read-write function on the memory by the second device. 29 . An apparatus, comprising: a first memory storing a unique identifier and a password; and a preparation unit including: a communication module configured to communicate with the first memory; a second memory configured to store a secret key; a processor coupled to the second memory and the communication module, the processor configured to: read the unique identifier from the first memory; encrypt the secret key with the unique identifier to generate an authentication signature; and store the authentication signature as the password in the first memory. 30 . The apparatus according to claim 29 , wherein the processor is further configured to output a verification status in response to a match between a proffered password and the password stored in the first memory. 31 . The apparatus according to claim 30 , wherein the first memory includes an RFID tag. 32 . The apparatus according to claim 31 , wherein the processor is further configured to enable at least one of a read operation or a write operation on the first memory in response to a match between a proffered password and the password stored in the first memory. 33 . The apparatus according to claim 32 , wherein the processor is further configured to initialize a data structure in response to a match between a proffered password and the password stored in the first memory. 34 . The apparatus according to claim 33 , wherein the data structure is further configured to store one or more datum selected from the group consisting of a usage count, a manufacturing date, a manufacturer serial number, an expiration date, calibration data, usage data, certification data, and an operational limit parameter. 35 . The apparatus according to claim 29 , wherein the processor is further configured to generate the authentication signature based on a cryptographic hash of the secret key and the unique identifier. 36 . The apparatus according to claim 35 , wherein the cryptographic hash is selected from the group consisting of an MD5 hash, an SHA-1 hash, an SHA-1 HMAC function, and an SHA-2 hash. 37 . A system for authenticating a surgical instrument, the system comprising: a surgical instrument including: a first memory configured to store a unique identifier; and a password module configured to store a password; and an authentication unit, including: a communication module configured to communicate with the first memory; a second memory configured to store a secret key; a processor coupled to the second memory and the communication module, the processor configured to: read the unique identifier from the first memory; encrypt the secret key with the unique identifier to generate an authentication signature; transmit the authentication signature to the password module; and receive a verification status from the password module in response to the authentication signature matching the password. 38 . The system according to claim 37 , further comprising an electrosurgical generator operably coupled to the authentication unit. 39 . The system according to claim 38 , wherein the electrosurgical generator is configured to enable an operational mode in response to the verification status. 40 . The system according to claim 39 , wherein the first memory is further configured to store data and the authentication unit is configured to modify the data stored in the first memory.

Assignees

Inventors

Classifications

  • G06F21/44Primary

    Program or device authentication · CPC title

  • Authentication · CPC title

  • Key management, e.g. using generic bootstrapping architecture [GBA] · CPC title

  • the pass enabling tracking or indicating presence · CPC title

  • Logistics, e.g. warehousing, loading or distribution; Inventory or stock management · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2018026795A1 cover?
Authentication systems and methods for a population of devices each associated with an RFID tag are described. For each device, a secret key is combined cryptographically with a publicly-readable unique identifier (UID) of an RFID tag to obtain a unique authorization signature. The RFID tag is prepared utilizing the unique authorization signature as memory-access and/or tag-operation password(s…
Who is the assignee on this patent?
Covidien Lp
What technology area does this patent fall under?
Primary CPC classification G06F21/44. Mapped technology areas include Physics.
When was this patent published?
Publication date Thu Jan 25 2018 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).