Print 19 comment(s) - last by mindless1.. on Sep 10 at 4:27 PM

Verayo claims its new chips are hack-proof. This claim has been questioned. Verayo's chips are active RFID and thus differ from the more hackable passive RFID.  (Source: Verayo)
A new "electronic DNA" approach claims to safeguard RFID -- but can it work as well as it claims?

RFID chips were one of the hottest emerging technologies of 2007 and 2008.  Top retailer Wal-Mart started using them in its shipping and people even began to implant themselves with RFID chips, despite cancer concerns.  The idea of instant identification seemed wonderful as it could make everything from work security to identifying a package much easier. 

However, hackers reprogrammed chips to gain access to RFID-controlled subways using techniques such as "cloning" -- swiping info from a legitimate chip and copying it to another.  MythBusters even jumped into the fray and said they were going to do an episode on how hackable the format was -- until they were advised that was an unwise legal move and recanted on their previous assertions.

Now amid the newfound concerns about RFID, a Palo Alto, Ca. startup is claiming to have an unbreakable RFID protection scheme.  Verayo Inc. is a newcomer to the business, only being in existence since 2005.  It was founded based on the research work of MIT Prof. Srini Devadas and his team.  Former Microsoft employee Tom Ziola cofounded the company.

The new allegedly "unhackable" chips use active RFID, slightly different from passive RFID.  As these chips require power, their applications might be slightly more limited and they would likely be more expensive.  The active chips use so-called "electronic DNA".  The key to their behavior is the technology Physical Unclonable Functions (PUF), developed at MIT.

Details on PUF can be found in an IEEE journal paper here (PDF).  Basically PUF takes inputs -- challenges -- and subjects them to unique logic to determine an output signal.  The input/output challenge and response pair is then compared over the internet against a database of pairs for valid chips.  The makers claim the new tech to be impervious as even if hackers stole an input/output pair, the information would be useless as the next time the chip would be prompted with a different question.

While the approach certainly seems more secure than traditional passive RFID, it might be premature to call it unbreakable.  As Gizmodo points out, one vulnerability is if the database was compromised and someone stole all the 64-bit challenge-response pairs.  Another relatively obvious possibility is that if the algorithms or production methods to manufacture the hardware and imprint any unique software were leaked, these could be used to build fake chips, which could likely process challenges and give the correct responses.

Nonetheless, despite the questionable nature of its claims, Verayo is making a splash in the RFID industry.  According to the company's online profile it has multiple contracts and a "deep" relationship with the U.S. Department of Defense, which is funding the development of the tech.

Comments     Threshold

This article is over a month old, voting and posting comments is disabled

RE: Haha
By Misty Dingos on 9/9/2008 9:38:28 AM , Rating: 5
I am not sure what advantage it would be to anyone to have one of these things shoved into their hides.

No I am not thumping bibles here. But the arguments I hear for it are all about some vaunted convenience for these people.

"You will be more secure." Why because I have some gadget stuck under my hide? There has never been any computer technology that hasn't circumvented or bypassed.

"You will be more identifiable." Widespread use of these things will destroy the dating scene. And no I don’t think the government is out to get me. And honestly I think I am “identifiable” enough as it is.

“It will help us identify murder victims.” I love this one. Most murder victims are easily identified. The few that are not are often the victims of someone that thought about killing them and took some pains to that effort. How much more work is it to remove the RFID?

"You can link it to your bank account and never have to carry a credit card or cash again." You know what all the women in the world I have ever met will tell you that even if you stuff one of these things under their skin it will not reduce the weight of their purses on ounce or gram. And you will still be a target for violence. All it will take is to remove your RFID and use it themselves. Criminals are not nice people and they won’t care if it hurts you.

The only thing I see happening with the use of human implantable RFIDs is removal services.

RE: Haha
By Seemonkeyscanfly on 9/9/2008 6:53:59 PM , Rating: 2
power it by the human body. Therefor if it is removed from the body, it will run one last command...Delete everything. Then fry itself, making it useless to the criminal.

RE: Haha
By Etsp on 9/9/2008 9:01:11 PM , Rating: 2
No, leave the name of the person in tact, but delete everything else, and flag it so that it cannot be used to identify anyone for any other reason than criminal investigation. That would cause it to lose all value to the hacker, without destroying evidence.

"We basically took a look at this situation and said, this is bullshit." -- Newegg Chief Legal Officer Lee Cheng's take on patent troll Soverain

Most Popular Articles5 Cases for iPhone 7 and 7 iPhone Plus
September 18, 2016, 10:08 AM
No More Turtlenecks - Try Snakables
September 19, 2016, 7:44 AM
ADHD Diagnosis and Treatment in Children: Problem or Paranoia?
September 19, 2016, 5:30 AM
Walmart may get "Robot Shopping Carts?"
September 17, 2016, 6:01 AM
Automaker Porsche may expand range of Panamera Coupe design.
September 18, 2016, 11:00 AM

Copyright 2016 DailyTech LLC. - RSS Feed | Advertise | About Us | Ethics | FAQ | Terms, Conditions & Privacy Information | Kristopher Kubicki