Back

Product Authentication

Product Authentication, Traceability and Digital Product Identity: How the Pieces Fit Together

Eugenia Vitali


26 Aug 2026

green links multi material

Brands that fight counterfeiting deploy authentication. Brands that manage grey market diversion deploy traceability. Brands that want regulatory compliance deploy digital product passports. They are buying three solutions to problems that share one infrastructure. This guide explains what each capability does, how they are connected, and what becomes possible when they are treated as a unified system rather than separate investments.

  • Authentication answers:Is this product genuine?
    A cryptographic verification that the product in a consumer’s hand is the one the brand made, not a fake, not a refill, not a clone.
  • Traceability answers:Where has this product been?
    A chain-of-custody record showing every authorised handover from production through distribution — and flagging when a genuine product appears where it was not supposed to go.
  • Digital product identity provides: The record that makes both possible
    A persistent, item-level record tied to a specific physical product from manufacture through the end of its life  the infrastructure that authentication and traceability run on.

Why These Three Are Treated as Separate and Why That Is a Problem

The confusion between authentication, traceability, and digital product identity is partly historical. Each capability emerged from a different commercial pressure and was addressed by a different part of the organisation.

Authentication was a brand protection problem, owned by legal or security teams, addressed by holograms, serial codes, and eventually NFC chips. Traceability was a supply chain problem, owned by operations, addressed by logistics scanning and ERP records that tracked units through distribution. Digital product identity is a newer concept, emerging from the intersection of regulatory pressure (the EU Digital Product Passport), consumer engagement, and the commercial value of post-sale product data.

Because these capabilities developed separately, organisations frequently deploy them separately — and pay three times for what is fundamentally one infrastructure. The NFC chip that authenticates the product is the same data carrier the DPP regulation mandates. The custody chain that traceability tracks is the same record that grey-market detection reads. The product identity record is the foundation of all three.

The practical cost of treating them separately: A brand that deploys NFC authentication for brand protection, a logistics scanning system for traceability, and a compliance data record for DPP is operating three systems that all start with the same thing, a unique identifier for each physical unit. If those identifiers are not the same one, the brand has created data silos that cannot talk to each other. Consumer authentication events are invisible to the supply chain team. Custody records are invisible to the compliance team. The commercial intelligence that would emerge from combining them does not exist.

What Each Capability Does and Where the Boundaries Are

  1. Authentication: Is this the genuine product the brand made? Does the item in my hand match the cryptographic identity of a unit commissioned at production?
    NFC chip with AES-128 challenge-response; backend validation; product identity record to validate against
  2. Traceability: Where has this unit been? Which distribution partners held it? Is it in the market it was allocated to? Has it been in custody of an unauthorised party?
    Item-level serialised identifier; custody event logging at each handover; territory allocation in the identity record
  3. Digital product identity: What is the complete lifecycle record for this specific unit  from production through first sale, service, resale, and end of life?
    Persistent cloud record linked to a unique identifier; data carrier on the product; role-based access for consumers, regulators, repairers, and internal teams
  4. Digital product passport: What are this product’s material composition, environmental footprint, repairability, and end-of-life characteristics? (EU regulatory requirement)
    The same NFC chip and the same product identity record, with DPP-specific data fields added to the existing record structure

The shared dependency: All four capabilities depend on the same starting point a unique identifier for each physical unit, linked to a cloud record, accessible via a data carrier on the product. Authentication validates the identifier cryptographically. Traceability records events against it. Digital product identity is the record itself. The DPP is the regulatory expression of what that record must contain. One identifier. One record. Four outputs.

The Four-Layer Infrastructure That Delivers All Three

When authentication, traceability, and digital product identity are treated as a unified system, they are delivered through a four-layer architecture. Each layer is a distinct capability; together they constitute what Selinko calls product identity as infrastructure.

  1. Foundation: Identity layer
    Cryptographic NFC chip embedded at manufacture

    An NFC chip implementing AES-128 challenge-response authentication is embedded in the product during production — not applied afterward. Each chip is encoded with a unique serialised identifier (SGTIN-compliant) and linked to the brand’s cloud platform. The chip’s secret key cannot be read externally; authentication requires the physical chip. This is the property that makes authentication a product-level security guarantee rather than a packaging-level one.

  2. Record: Data layer
    Product identity record: the digital twin

    The chip’s identifier points to a cloud record that starts at manufacture and accumulates data across the product’s full lifecycle: production details, material composition, allocated distribution territory, custody events, authentication interactions, ownership transfers, service events, and end-of-life processing. This is the product’s digital twin — the single source of truth that authentication reads, traceability writes to, and the DPP exposes.

  3. Interaction: Access layer
    Role-based views over the same record

    Different audiences need different views of the same data. Consumers see authentication results, provenance, care instructions, and ownership registration. Supply chain teams see custody chain records and grey-market anomaly flags. Compliance teams see DPP data fields. Regulators see conformity documentation. All are served from the same underlying record — different windows onto the same digital twin, controlled by the brand’s access policy.

  4. Connectivity: Integration layer
    Connection to existing enterprise systems

    The product identity record is the central node; other systems feed into and consume from it. PLM provides material and design data. ERP provides production and batch records. WMS and logistics systems provide shipment events. Resale and service platforms provide post-sale lifecycle events. DPP registries store the compliance record for regulatory access. The product identity record aggregates across all of these without replacing them.

How the Three Capabilities Connect in Practice

The connection between authentication, traceability, and digital product identity is not just architectural it produces specific commercial capabilities that neither authentication nor traceability delivers in isolation.

  • Production: identity is created, territory is set
    When the NFC chip is encoded at manufacture, the product receives its unique identity and its territory allocation is recorded. Authentication is now possible. Traceability has a starting point. The DPP record exists. All three capabilities are live from the first moment the product exists as a specific unit.
  • Distribution: traceability builds the custody chain.
    Each scan at a distribution checkpoint — warehouse dispatch, regional hub, distributor receipt — is logged as a custody event against the unit’s identifier. The custody chain is the traceability record. It is also the baseline for grey-market detection: when a consumer scan later arrives from a territory with no recorded custody event, the anomaly is visible immediately against this record.
  • Consumer tap: authentication and data event simultaneously
    A consumer taps the product. The chip’s cryptographic response is validated — authentication is confirmed or denied. Simultaneously, the scan event is logged against the product’s record: timestamp, geographic indicator, tap counter value. This single interaction produces an authentication result for the consumer, a lifecycle event for the traceability record, and a geographic data point for grey-market intelligence. One tap. Three outputs.
  • Grey-market detection: traceability and identity working together
    When the platform compares the consumer scan’s geographic location against the unit’s territory allocation and custody chain, it is using the product identity record (territory allocation) and the traceability record (custody events) together to produce a grey-market signal. Neither authentication alone nor traceability alone produces this signal — it requires both, integrated through the shared identity record.
  • Resale: ownership transfers and provenance chain
    When a product changes hands, the new owner can register against the same identity record. The provenance chain accumulates: original production, every authenticated interaction, every custody event, every ownership transfer. For categories where resale value is tied to provenance — fine watches, collector fragrances, limited-edition footwear — this accumulated record is commercially significant, accessible from the product itself via a tap.
  • DPP compliance: the record already exists
    The EU Digital Product Passport requires a unique identifier per unit (the NFC chip), a data carrier on the product (the same NFC chip), and a record containing lifecycle, material, and sustainability data (the product identity record). Brands that have deployed connected product infrastructure for commercial reasons — authentication, grey-market detection, consumer engagement — meet the DPP mandate as a configuration exercise. The infrastructure is the compliance.

What Each Layer of the Combined System Produces

When authentication, traceability, and digital product identity are unified, the combined system produces outputs across brand protection, supply chain intelligence, consumer engagement, and regulatory compliance from the same per-unit NFC deployment.

Authentication outputs

  • Consumer verification at point of purchase
  • Counterfeit detection and geographic mapping
  • Refill fraud detection via tamper-evident integration
  • Recall verification — is this the affected unit?
  • Resale authentication across secondary market
Traceability outputs

  • Chain-of-custody record per unit
  • Grey-market diversion detection
  • Distributor accountability evidence
  • Recall scope mapping — which units, where
  • Demand intelligence vs sell-in calibration
Identity outputs

  • Consumer ownership registration and transfer
  • Post-sale brand engagement channel
  • Service and repair history record
  • Provenance chain for secondary market value
  • EU DPP compliance from existing record

Why this matters for investment decisions: A brand considering NFC authentication as a brand protection investment is also, from the same deployment, acquiring grey-market detection capability, consumer engagement infrastructure, secondary market intelligence, and a DPP compliance foundation. These are not add-ons, they are outputs of the same chip and record, differentiated only by which questions the platform is configured to answer. The cost of the infrastructure is constant; the decision to use it for one purpose or five is a configuration decision, not an infrastructure cost decision.

Go Deeper: Articles on Each Capability

This guide covers how the pieces fit together. The following articles go deeper on each specific capability and use case.

Explore Selinko's product identity platform.

Authentication, traceability, grey-market intelligence, consumer engagement, and DPP compliance from a single NFC deployment — built for luxury, spirits, beauty, and fashion brands.

FAQs

What is a digital product identity and how is it created?

A digital product identity is a unique record in a brand’s cloud platform, linked to a specific physical product unit via a data carrier — typically an NFC chip embedded in the product. It is created at manufacture, when the chip is encoded with a unique identifier and paired with a product record storing the unit’s model, batch, production date, and allocated distribution territory. Everything that happens thereafter: distribution scans, authentication events, ownership transfers, service events, is appended to this record as it occurs. The identity persists for the product’s full lifetime, regardless of how many times it changes hands.

Why does brand protection require both authentication and traceability?

Authentication alone detects fakes. Traceability alone shows where genuine products go. Brand protection requires both because the two most commercially significant threats require different detection mechanisms. A counterfeit product fails authentication. A grey-market product is genuine and passes authentication; detecting it requires knowing where the product is relative to where it was allocated. Without traceability, a brand knows a product is genuine but not whether it is in the right market. Without authentication, it cannot distinguish genuine from fake. Together, through a shared product identity record, they cover the full brand protection problem.

What is the EU Digital Product Passport and how does it relate to product authentication?

The EU Digital Product Passport (DPP) under the Ecodesign for Sustainable Products Regulation requires brands to attach a digital data carrier to each product linking to a record of material composition, environmental footprint, repairability, and end-of-life guidance. The NFC chip used for product authentication is the same data carrier the DPP mandates, and the product identity record created for authentication is the foundation of the DPP compliance record. Brands deploying NFC authentication now are simultaneously building DPP compliance infrastructure. The authentication deployment is the DPP deployment.

How does connected product technology deliver authentication, traceability, and identity together?

Connected product technology delivers all three simultaneously from the same per-unit NFC chip. The chip provides authentication (cryptographic challenge-response at consumer tap), traceability (each custody event logged against the chip’s identifier), and identity (the persistent cloud record that accumulates all lifecycle data). Each consumer tap, each distribution scan, each ownership transfer is both a data event for the brand and an interaction point for the consumer. The infrastructure is deployed once; authentication, traceability, identity, compliance, and consumer engagement are generated continuously from every subsequent interaction.

Talk to our team

Blog

Discover more articles

All our articles