This application is a U.S. National Stage Application of International Application No. PCT/EP2008/001131 filed Feb. 14, 2008, which designates the United States of America, and claims priority to German Application No. 10 2007 009 023.6 filed Feb. 23, 2007, the contents of which are hereby incorporated by reference in their entirety.
The invention relates to an apparatus and a method for transmitting RFID identification data to an authentication server, for instance in an airport.
The radio frequency identification (RFID) enables automatic identification in order to localize objects.
In addition to a transponder, a conventional RFID system includes a reading device with an assigned antenna, which is also referred to as reader. Transponders on or in the objects store data which can be read in a contact-free fashion and without visual contact. Depending on the embodiment, i.e. depending on whether the transponder is active or passive and depending on the used frequency band transmission power as well as environmental influences, the range lies between a few centimeters and several kilometers. The data transmission between the transponder and the reading device takes place by means of electromagnetic waves.
RFID tags are used in various ways, for instance in logistics processes to authenticate people and objects. The RFID tags are registered by the RFID reading device which registers the data stored on the RFID tag and transmits it to so-called RFID middleware. The RFID reading units are usually connected to a data network in a wired manner. In this way the RFID reading device is connected to a PC by way of a serial interface RS-232 or USB for instance.
In some systems, a RFID reading unit is connected to a WLAN access point (AP) by way of a WLAN interface. The WLAN access point (AP) here guarantees the terminal access to the data network following successful authentication.
To this end, either an EAP-based WLAN link layer authentication or an authentication by way of a web browser of the WLAN client node takes place, which is connected to the RFID reading device, opposite a Web server. The connection to the data network is only established once the inputted user credentials have been successfully verified.
A conventional RFID reading unit, which, as shown in
Operating an open or unprotected WLAN access point in order to prevent the configuration of the RFID reading unit to reduce the administration effort nevertheless brings about significant security risks.
According to various embodiments, an apparatus and a method can be created, with which the administration effort involved in configuring the RFID reading unit is avoided and a secure data transmission is ensured at the same time.
According to an embodiment, an apparatus may comprise an RFID reading unit, which transmits at least one RFID protocol message encoded in authentication messages to an authentication server in order to transmit RFID identification data read out from RFID tags.
According to a further embodiment, the transmitted RFID protocol message may have an identifier of the RFID reading unit in addition to the RFID identification data. According to a further embodiment, an address of the authentication server may be configured in the apparatus. According to a further embodiment, an address of the authentication server can be determined on the basis of the RFID identification data by the apparatus. According to a further embodiment, the address of the authentication server may be contained in the RFID identification data. According to a further embodiment, the apparatus may have a memory for storing a table, in which addresses of authentication servers for different RFID identification data are stored. According to a further embodiment, the RFID identification data may be encoded in a network access identifier NAI of the authentication network. According to a further embodiment, the authentication message can be transmitted via an access network to the authentication server. According to a further embodiment, the access network can be a wireless access network. According to a further embodiment, the wireless access network can be a W-LAN network. According to a further embodiment, the wireless access network can be a WiMax network. According to a further embodiment, the authentication messages can be transmitted from the RFID reading unit via a wired access network to the authentication server. According to a further embodiment, the authentication messages can be transmitted by means of an EAP data transmission protocol. According to a further embodiment, authentication messages can be transmitted by means of a radius data transmission protocol. According to a further embodiment, the authentication messages can be transmitted by means of an HTTP data transmission protocol. According to a further embodiment, the authentication messages can be transmitted by way of at least one authentication proxy server to the authentication server. According to a further embodiment, the apparatus can be provided in a mobile transportation vehicle. According to a further embodiment, the transportation vehicle can be formed by a ship, an airplane or a truck.
According to another embodiment, a method for providing RFID identification data, which is read out from RFID tags, for an authentication server, may comprise the step of transmitting at least one RFID protocol message to the authentication server encoded in authentication messages.
According to yet another embodiment, a system for transmitting RFID identification data, which can be read out from RFID tags, to an authentication server, may comprise at least one RFID protocol message being transmittable to the authentication server encoded in authentication messages by an RFID reading unit.
Embodiments of the apparatus and of the method are also described to explain features which are essential to the invention, in which;
According to various embodiments, an apparatus can be created with an RFID reading unit, which transmits at least one RFID protocol message encoded in authentication messages to an authentication server from RFID identification data read out from RFID tags.
In one embodiment of the apparatus, the transmitted RFID protocol message has the RFID identifier and an identifier of the RFID reading unit.
In one embodiment of the apparatus, an address of the authentication server is configured in the apparatus.
In one embodiment of the apparatus, an address of the authentication server is determined by means of the apparatus on the basis of the RFID identifier.
In one embodiment of the apparatus, the address of the authentication server is contained in the RFID identifier.
In one embodiment of the apparatus, the apparatus has a memory for storing a table, in which addresses of authentication servers in respect of different RFID identifiers are stored.
In one embodiment of the apparatus, the RFID identifier is encoded in a network access identifier (NAI) of the authentication message.
In one embodiment of the apparatus, the authentication message is transmitted to the authentication server by way of an access network.
In one embodiment of the apparatus, the access network is a wireless access network.
In one embodiment of the apparatus, the wireless access network is a WLAN network.
In one embodiment of the apparatus, the wireless access network is a WiMax network.
In one embodiment of the apparatus, the authentication messages are transmitted from the RFID reading unit via a wired access network to the authentication server.
In one embodiment of the apparatus, the authentication messages are transmitted by means of an EAP data transmission protocol.
In one embodiment of the method, the authentication messages are transmitted by means of an AAA data transmission protocol.
In one embodiment of the method, the authentication messages are transmitted by means of a RADIUS data transmission protocol.
In one embodiment of the apparatus, the authentication messages are transmitted by means of a DIAMETER data transmission protocol.
In one embodiment of the apparatus, the authentication messages are transmitted by means of an HTTP data transmission protocol,
In one embodiment of the apparatus, the authentication messages are transmitted to the authentication server by way of at least one authentication proxy server.
In one embodiment of the apparatus, the apparatus is provided in a mobile transportation vehicle.
In one embodiment of the apparatus, the transportation vehicle is formed by a ship, an airplane, an automobile or a truck.
According to further embodiments, a method for providing RFID identifiers, which are read out from RFID tags, for an authentication server can be created, with at least one RFID protocol message encoded into authentication messages being transmitted to the authentication server.
According to yet another embodiment, a system for transmitting RFID identifiers, which can be read out from RFID tags, to an authentication server can be created, with at least one RFID protocol message being transmittable to the authentication server in authentication messages encoded by an RFID reading unit.
In the exemplary embodiment shown in
In an alternative embodiment, the authentication messages are not transmitted wirelessly but instead wired to the apparatus 2 with the authentication server 6, i.e. the access network is not wireless, as shown in
In one possible embodiment, the address of the authentication server 6 is and/or can be preconfigured in the apparatus 2.
In one alternative embodiment, the address of the authentication server 6 is determined by the apparatus 2 on the basis of the read-out RFID identification data. For instance, the address of the authentication server 6 is contained in the read-out RFID identification data.
In one possible embodiment, the apparatus 2 has a memory for storing a table for instance, in which addresses of authentication servers 6 are stored for different RFID identification data.
In one possible embodiment, the RFID identification data, which is read out from the RFID tag 4 by the RFID reading unit 2A, is encoded in a network access identifier NAI of an authentication message.
The authentication messages can be transmitted by way of different data transmission protocols, for instance by means of an EAP data transmission protocol, by means of a radius data transmission protocol or by means of an HTTP data transmission protocol.
The apparatus 2 shown in
The RFID reading unit 2A shown in
The RFID data transmission protocols can generally differ in terms of tag and reading data protocols. The tag data transmission protocols determine the communication between the RFID tag 4 and the RFID reading unit 2A. Accordingly, the reader data transmission protocols define the message transmissions between the RFID reading unit 2A and the RFID background system, i.e. between the RFID reading unit 2A and the authentication home server 6. Different manufacturers of terminals and/or systems to some extent use different protocol implementations. A number of properties which support each RFID data transmission protocol exist independently of the manufacturer and the type of RFID tag 4. In the simplest case, with a tag data transmission protocol, the process is “singulation”, “anti-collision” and “identity”. The process “singulation” is provided here to uniquely identify and read out individual tags. The process “anti-collision” regulates the response timing for instance, in order to be able to directly read out individual tags 4. The property “identity” describes which data is stored in which manner on tag 4.
The reader data transmission protocols, which determine the communication between the RFID reading unit 2A and the authentication server 6, can be subdivided into “commands” and “notifications”. A connected system uses the so-called “commands” and/or command messages to trigger actions on the RFID reading unit 2A, for instance to read out data or to modify a configuration. The “notifications” and/or display messages are messages which the RFID reading unit 2A sends to the system, for instance read out data, alarms or other error messages. With the system 1, as shown in
In a first embodiment of the apparatus 2, an RFID identifier is transmitted encoded in an authentication message. In a further embodiment, one and/or several RFID protocol messages is/are transmitted encoded in the authentication messages.
In an EAP-based network registration, the data and/or RFID identification data is encoded in the transmitted network access identifier NAI by way of EAP messages. Here either the registered identification data of the RFID tag 4 is transmitted or the RFID data transmission protocol is transmitted ciphered between the RFID tag 4 and the RFID reading unit 2A.
For the access nodes and/or access point AP and/or for the base station 3, as shown in
With the embodiments shown in
In an alternative embodiment, the RFID identification data is transmitted to remote servers, for instance to a server in an airline company, to a server in a services company or to a server in an airplane manufacturer. It is thus possible to forward the authentication messages from the authentication server 6 of the airport network 9 via any networks, for instance the internet, to the corresponding server. In one possible embodiment, the authentication proxy server 5, as shown in
A network access identifier NAI generally has the following data form: “user@realm”, for instance mueller@lufthansa.com.
In a first embodiment, the RFID identifier and/or the RFID identification data RFID-ID is encoded in the user and/or user part, for instance RFID-ID@lufthansa.com.
In an alternative embodiment, the RFID identification data RFID-ID is encoded into the so-called realm part of the network access identifier NAI, for instance: reader@RFID-ID.lufthansa.com. In one possible embodiment, the identifier of the RFID reading unit 2A (ARC-ID) is also encoded into the authentication messages, for instance RFID-ID.arc-id@lufthansa.com or arc-id@RFID-ID.lufthansa.com.
Number | Date | Country | Kind |
---|---|---|---|
10 2007 009 023 | Feb 2007 | DE | national |
Filing Document | Filing Date | Country | Kind | 371c Date |
---|---|---|---|---|
PCT/EP2008/001131 | 2/14/2008 | WO | 00 | 11/18/2009 |
Publishing Document | Publishing Date | Country | Kind |
---|---|---|---|
WO2008/101634 | 8/28/2008 | WO | A |
Number | Name | Date | Kind |
---|---|---|---|
7096014 | Haverinen et al. | Aug 2006 | B2 |
7138915 | Morito et al. | Nov 2006 | B2 |
20050261970 | Vucina et al. | Nov 2005 | A1 |
20060032901 | Sugiyama et al. | Feb 2006 | A1 |
20060055538 | Ritter | Mar 2006 | A1 |
20060073840 | Akgun et al. | Apr 2006 | A1 |
20060168644 | Richter et al. | Jul 2006 | A1 |
20070002140 | Benson | Jan 2007 | A1 |
20070011269 | Jeon et al. | Jan 2007 | A1 |
20070045424 | Wang | Mar 2007 | A1 |
20070080784 | Kim et al. | Apr 2007 | A1 |
20080148050 | Sparrell | Jun 2008 | A1 |
Number | Date | Country |
---|---|---|
1584911 | Feb 2005 | CN |
102004014411 | Oct 2005 | DE |
100652023 | Nov 2006 | KR |
WO 2005065261 | Jul 2005 | WO |
WO 2006100714 | Sep 2006 | WO |
Entry |
---|
Dantu et al., “EAP Methods for Wireless Networks”, Computer Standards and Interfaces, Elsevier Sequoia, Lausanne, CH, vol. 29, No. 3, Feb. 2, 2007, pp. 289-301: Others. |
ITU-T Draft Yong-Woon Kim et al., “Review Report of Standardization Issues on Network Aspects of Identification including RFID; D155”, ITU-T Draft Study Period 2005-2008, International Telecommunication Union, Geneva, Ch, Study Group 17, Apr. 19, 2006, pp. 1-49,; Others. |
International Search Report, PCT/EP2008/001131 14 pages, Aug. 13, 2009. |
Standard IEEE 802.11 , IEEE Wireless LAN Edition, (1999; R2003): Others. |
Number | Date | Country | |
---|---|---|---|
20100079237 A1 | Apr 2010 | US |