ComparisonPhygital Assets

Choosing a product identifier that resists copying: NFC, QR, RFID and unclonable features

Any product identifier can be copied unless the design deals with copying. A printed QR code tells a phone where the record lives; it says nothing about whether the bottle in your hand is the one that was enrolled. This comparison sets the main options against the attacks they face, including NFC tags that produce a fresh cryptographic code on every tap, and shows how to combine them by product tier.

Reviewed 8 min read

On this page
  1. Four ways counterfeiters defeat a product identifier
  2. Printed codes: static QR, serialised QR and copy-detection patterns
  3. NFC tags: passive identifiers versus tags that authenticate each tap
  4. UHF RFID (RAIN) belongs in the supply chain, not in the shopper's hand
  5. Unclonable features and tamper-evident packaging
  6. Identifier options compared on clone resistance, reach and privacy
  7. From tap to verdict: how a scan reaches the product record
  8. Combining identifiers by product tier
  9. Questions and answers
  10. Sources

Four ways counterfeiters defeat a product identifier

Start with how a fake or diverted item would get past the check, because each identifier fails in a different way.

Copying is the simplest attack: photograph a code, print it on a thousand fakes, and every one scans as genuine. Transplanting moves a real identifier from a genuine item, or its packaging, on to a counterfeit. Refilling keeps the original container and replaces the contents, the main exposure for spirits, perfume and lubricants. Diversion sells genuine goods outside the channel or market they were released for, so provenance rather than authenticity is in question.

Name who scans, too. A customs officer with a dedicated reader, a warehouse gate and a customer in a bar have different tools and motivation, and the identifier must serve the person whose decision it informs.

Printed codes: static QR, serialised QR and copy-detection patterns

A static QR code printed identically on every unit is cheap and readable by any phone camera, but a photocopy works exactly as well as the original. Serialising the code adds a little: the record shows where each serial has been scanned, and one serial scanned in two countries on the same afternoon is worth investigating. That is a signal, not proof, because the first scan of a copied serial looks legitimate.

Copy-detection patterns are printed areas of fine, high-entropy detail that lose information when scanned and reprinted, so a verifier can judge whether it is looking at a first-generation print. They keep the low cost and phone reach of printing, but results depend on print control at the factory, the camera and lighting during the scan, and a verification service that stays available for the product's life.

Whichever printed option you choose, a GS1 Digital Link URI is a sensible way to encode the identifier: it writes the product's GS1 key, plus a serial or batch where needed, as a web address that one QR code can carry for retail and consumer use alike2. It identifies; it does not authenticate.

NFC tags: passive identifiers versus tags that authenticate each tap

A basic NFC tag stores a fixed identifier and a link. Phones read it without an app, but its contents can be copied to a blank tag with consumer tools, so it is no stronger than a serialised QR code.

Cryptographic tags change that. NXP's NTAG 424 DNA, for example, uses AES-128 cryptography and offers what NXP calls SUN message authentication within a standard NDEF read, so an ordinary phone tap returns a link carrying a fresh, verifiable code1. The verification service checks that code with an incrementing tap counter, so a link captured from one tap and replayed later fails. A TagTamper variant adds a loop that reports whether a seal has been opened1.

What cryptography cannot stop is a transplant: a genuine tag peeled from a real product and stuck on a fake still produces valid messages. The defence is mechanical as much as digital. Embed the tag inside the product or closure, use inlays that tear on removal, and bind the tag to a serialised visual feature that the verifier also checks.

UHF RFID (RAIN) belongs in the supply chain, not in the shopper's hand

UHF RFID, promoted under the RAIN name, lets fixed and handheld readers identify many items at once from a few centimetres to several metres away3. That suits stock counts, dock-door receiving and spotting diverted cartons, and the reads can feed the same provenance record as a consumer-facing tag.

It is a weak channel for consumer checks. Most phones cannot read UHF tags, and the read range that helps a warehouse becomes a tracking risk once a garment leaves the shop. If a tag identifier can be linked to a customer, through a loyalty account or a registered warranty for instance, its reads may become personal data under the GDPR4. Detach or disable tags at the point of sale and keep consumer checks on a short-range channel.

Unclonable features and tamper-evident packaging

Physical unclonable features rely on randomness that manufacturing cannot reproduce on purpose, such as leather grain, paper fibres, laser-mark speckle or variation in a chip's silicon. Enrolment captures the feature once and later checks compare against it. They are very hard to copy, but often need a dedicated scanner, and wear can change them over the years.

Tamper evidence is the partner every option needs against refilling and transplanting. Seals that break visibly, closures that destroy the inlay when opened and tags that report a loop's state turn a silent swap into something a person can see.

Identifier options compared on clone resistance, reach and privacy

Ratings are relative and assume a competent implementation. Costs are given as bands because they vary with volume, inlay format and the verification service.

CriterionStatic or serialised QRCopy-detection patternCryptographic NFCUHF RFID (RAIN)Unclonable feature
Clone resistanceNone if static; weak if serialisedModerate, depends on print controlHigh against cloning; transplant still possibleLow unless the tag supports cryptographic authenticationHigh
Readable by a customer's phoneYes, with the cameraYes, with a verification app or web readerYes, on most current phonesNo; needs a UHF readerRarely; often needs a dedicated scanner
Tamper evidenceNone by itselfNone by itselfAvailable with tamper-loop variantsNone by itselfIndirect: damage alters the feature
Privacy and tracking riskLow; read only when someone scansLowLow; very short read rangeHigher; readable at a distance after saleLow
Unit cost bandLowestLowModerateLow to moderateVaries widely with method
Best roleInformation and reachMass-market packaging checksPremium items and ownership claimsLogistics, inventory and diversion detectionHigh-value items checked by experts

No column wins every row. The section on product tiers below shows how the options are combined.

From tap to verdict: how a scan reaches the product record

ColdAI's phygital framework combines NFC chips, QR attestations and supply-chain oracles, so the identifier is one input to the verdict, not the verdict itself5.

01Tag or printed code02Phone or reader03Resolver04Verification service05Product record06Ledger anchor
  1. Tag or printed code

    Carries the identifier and, for cryptographic tags, a fresh code from each tap.

  2. Phone or reader

    Opens the encoded link; QR and NFC links need no app.

  3. Resolver

    Maps the GS1 Digital Link URI or tag URL to the right service, product and language.

  4. Verification service

    Checks the cryptographic code, the counter and the scan history, then decides what the page may claim.

  5. Product record

    Holds enrolment data, ownership state and service history, kept off-ledger so it can be corrected.

  6. Ledger anchor

    Optional hash or token that lets a third party confirm the record has not been altered.

Conceptual path of a consumer scan. The verification service, not the tag, decides what the result page claims.

Combining identifiers by product tier

These are hypothetical patterns, not prescriptions; your own threat model and margins decide the final mix.

  • If

    A luxury handbag whose price rewards counterfeiting and which is often resold through authenticated marketplaces.

    Then

    Embed a cryptographic NFC tag in the lining, enrol it with a photograph of a serialised hardware detail, and print a GS1 Digital Link QR code on the care card for reach.

    Resale buyers need proof that survives years of use, and the photograph exposes a transplanted tag.

  • If

    A spirits bottle exposed to refilling in bars and export markets.

    Then

    Fit a tamper-loop NFC tag across the closure and a serialised QR code on the label.

    The loop shows whether the bottle has been opened since sealing, the exact question refilling raises.

  • If

    An industrial spare part where fakes cause safety incidents and buyers check stock at goods-in.

    Then

    Laser-mark a serialised Data Matrix or QR code, add RAIN RFID for receiving, and verify against the distributor's dispatch records.

    Fake parts usually enter through the channel, so channel data catches more than consumer tags would.

  • If

    A mass-market cosmetic sold in high volume on thin margins.

    Then

    Print copy-detection patterns beside serialised QR codes and watch scan analytics for duplicated serials.

    The margins rarely support a chip, and the aim is to spot outbreaks of fakes in particular markets early.

Questions and answers

Can a genuine NFC tag be moved to a counterfeit product?

Yes, if it can be removed intact. Cryptography stops a tag being cloned, not relocated. Brands reduce the risk by embedding tags inside the product or closure, using inlays that tear when peeled, choosing tamper-loop variants for seals, and binding the tag to a visual serial or photograph that the verifier also checks. Scan history helps too: a tag that suddenly appears in a new market deserves a closer look.

Do customers need an app to check whether a product is genuine?

Not for QR codes or NFC tags that carry a web link: a phone camera or an NFC tap opens the verification page in the browser. Apps become useful for copy-detection patterns that need controlled image capture, for registering ownership, or for offline checks by inspectors. Requiring an app for a basic authenticity check usually means fewer people bother to scan.

What should happen when a tag fails to verify?

Treat it as a case, not a verdict. Tags fail for innocent reasons such as physical damage, a phone with a weak NFC antenna or a counter out of step after factory testing. The result page should explain what failed, offer a second method such as a printed serial, and route the case to brand protection with the scan location and time. Repeated failures from one market are a pattern worth investigating.

Sources

  1. NTAG 424 DNA and NTAG 424 DNA TagTamper product information — NXP Semiconductors · checked 10 October 2026
  2. GS1 Digital Link standards — GS1 · checked 10 October 2026
  3. What is RAIN RFID? — RAIN Alliance · checked 10 October 2026
  4. Regulation (EU) 2016/679 (General Data Protection Regulation) — EUR-Lex · checked 10 October 2026
  5. Phygital Assets: framework and delivery approach — ColdAI

More in Phygital Assets

Back to Phygital Assets

Next step

Send us your product, its channels and the fakes you see

Tell us what the product is, how it is sold and resold, and how counterfeit or diverted stock reaches customers. We will reply with the identifier options worth testing and the questions a pilot should answer.

Discuss product authentication