Abstract:
The present invention describes a system wherein an RF ID card uses a user interface, such as a keypad, to input a password. The password is encrypted and sent to an RF ID reader. Since the password is not permanently stored on the RF ID card, someone stealing the RF ID card cannot use the RF ID card to impersonate a user.
Abstract:
The system (100) includes an RF ID card (102) and an RF ID reader (104). The ID is stored in storage (106) of the RF ID card (102). A message composition unit (108) receives the ID and composes the message including the ID, responding back to the RF ID reader (104). The RF ID reader (104) includes a timestamp production unit (107) which produces a timestamp which is provided to the message composition unit (110). The timestamp is received by the RF ID card (102). The message reception unit (109) provides the time stamp to the encryption unit (112) in the RF ID (102). The encryption unit (112) also receives a key value from storage (106). In a preferred embodiment, the encryption unit uses the key to encrypt the timestamp along with a password received form the user interface (114). The RF ID reader (104) receives the encrypted message in the message reception unit (118). Alternately, public/private encryption system is used in which the key at the RF ID card (102) is a private key while the key at the RF ID reader (104) is a public key or vice versa. In some embodiments, the ID look-up functions (120) are implemented at the external network. The decryption operation (122) receives the encrypted message and uses the key from the ID look-up to decrypt the message. Authorization unit (124) examines the password obtained by the ID look-up and the current time stamp in order to determine an authorization.