It surprises me that the tags are deactivated instead of read by a reader and registered in a database as “sold” and the alarm system checks that database whenever it reads a tag. That way it would be impossible for thieves to just deactivate the tag with their own magnet.
Not sure you would even need encryption. Surely It can’t be illegal to ask the root servers (and all the other DNS servers involved, because the root servers only have IPs for TLD DNS servers) for IPs