- What is a verifiable product identity?
- A verifiable product identity uniquely identifies a physical product instance and enables its producer-authorized data to be cryptographically verified. Unlike a GTIN, which identifies a product class, or a plain QR code, it can combine serialization, digitally signed attributes and trusted verification to establish product-level authenticity and integrity.
- How does product authentication work?
- A unique identity is generated, digitally signed and applied during production. When scanned, Ciphercode verifies the producer-authorized data through its trusted certificate chain and evaluates contextual signals such as repeat scans, location and device patterns. Valid signatures establish data authenticity; anomalous identity reuse helps expose copied or suspicious products.
- How does verifiable product identity support traceability and compliance?
- A serialized identity connects machine-readable product data with lifecycle events generated across production, distribution and verification. This can support GS1 Digital Link, serialization and aggregation, India's Schedule H2 pharmaceutical traceability requirements, and product-data frameworks such as the EU Digital Product Passport, according to each regulation's specific requirements.
- How does Ciphercode connect product identity across the product lifecycle?
- Ciphercode maintains a common product identity across serialization and QSeal, warehouse and distribution operations, QReach consumer interactions, and enterprise integrations. GS1-based identifiers and interoperable data structures help different lifecycle systems reference the same product identity, connecting previously fragmented events into trusted product-level intelligence.
- What's the difference between a cryptographically signed QR code and a regular QR code?
- A regular QR code is simply a data carrier and can be copied. A cryptographically signed QR can carry or resolve producer-authorized data whose integrity and origin are independently verifiable. Copying a valid code doesn't forge its signature; instance uniqueness and contextual or physical authentication are needed to detect cloning.