Back

Product Authentication

Product Authentication vs Product Traceability: What's the Difference?

Thomas


09 Sept 2026

abstract dust

A genuine bottle of single malt appears on a shelf in Seoul. It was allocated to a duty-free operator in London. Tap the NFC chip: the cryptographic response confirms the product is real. Authentication has done its job. But authentication cannot tell the brand how a bottle allocated to Heathrow ended up in a Korean retail channel at a 30% discount. That question belongs to traceability. These two capabilities solve different commercial problems, address different threats, and use different data, but they run on the same chip.

What is product authentication?

Product authentication answers a single binary question: is this item genuine?

The mechanism is cryptographic. A secure NFC chip embedded in the product generates a unique, one-time response every time a phone taps it. The backend holds the corresponding key. If the response matches, the product is genuine. If it does not, the product is counterfeit or the chip has been cloned (which, with current-generation secure silicon, is computationally infeasible).

Authentication cares about identity, not history. It does not record where the product has been or through whose hands it passed. It confirms what the product is at the moment of the tap.

The threat it addresses: counterfeiting. Fake products that imitate genuine ones.

The result: genuine or not genuine.

What is product traceability?

Product traceability answers a different question: where has this product been, and through whose hands?

The mechanism is geographic and logistical. A cloud record stores the product’s allocated distribution territory, its custody chain (manufacturer to distributor to retailer), and the location of every scan event. When a scan occurs, the system compares the product’s current location against its expected path.

Traceability cares about history, not identity. It does not verify whether the chip is cryptographically genuine. It tracks whether a genuine product is where it is supposed to be.

The threat it addresses: grey market diversion. Genuine products sold outside their authorised channel or territory.

The result: consistent or anomalous, compared against the expected distribution path.

How does NFC product authentication work?

The process, from factory to consumer tap, follows a defined sequence.

  1. Tag embedding. A secure NFC chip (NTAG 424 DNA class, ISO/IEC 14443-A, NFC Forum Type 4) is embedded in or applied to the product during manufacture. Each chip carries a unique serialised identifier linked via GS1 Digital Link to GTIN and serial number.
  1. Key provisioning. The chip is provisioned with an AES-128 cryptographic key. The corresponding key is stored in the brand’s cloud platform. This pairing is irreversible: the chip cannot be reprogrammed to impersonate another product.
  1. SUN message generation. When a consumer taps the product with a smartphone, the chip generates a one-time encrypted response using Secure Unique NFC (SUN) messaging. Each tap produces a different code.
  1. Backend validation. The platform receives the SUN message, decrypts it using the stored key, and confirms whether the cryptographic response is valid.
  1. Consumer result. The consumer sees a clear verdict on their phone screen: verified genuine, or flagged. No app required. iPhone XS/XR and later read NFC tags in the background; Android reads natively with screen on.

The critical security property: the chip generates a new response every time. Copying a previous response and replaying it fails, because the backend has already seen that code. A basic NFC tag broadcasts the same static URL on every tap, like a door with the key hanging next to it. A secure NFC tag generates a fresh one-time code on every approach, and the only way to produce the right code is to possess the original silicon.

How does NFC product traceability work?

Traceability layers additional data on top of the same chip infrastructure.

  1. Territory allocation. At the point of dispatch, the platform records which market, distributor, or retail channel each serialised unit is allocated to.
  1. Custody events. Each handover in the supply chain, from manufacturer to logistics partner to distributor to retailer, is logged as a custody event with timestamp, location, and responsible party.
  1. Scan event geography. Every consumer tap (or supply-chain scan) records the geographic coordinates and timestamp of the interaction.
  1. Anomaly detection. The platform compares scan geography against the allocated territory and custody chain. A product allocated to France that surfaces in Brazil triggers an alert.
  1. Investigation data. The brand receives a chain-of-custody record that identifies the last authorised custodian before the anomaly, providing evidence for commercial or legal action against the diverting party.

Authentication vs traceability: side-by-side comparison

Dimension Authentication Traceability
Core question Is this product genuine? Is this genuine product where it should be?
Verification method Cryptographic challenge-response Geographic and logistical comparison
Primary threat Counterfeiting Grey market diversion
Data used Chip cryptographic response vs stored key Territory allocation + custody events + scan geography
Result Genuine / Not genuine Consistent / Anomalous
Consumer-facing Yes, primary use case No, brand-facing intelligence
Requires serialisation Yes Yes
Requires custody data No Yes

The distinction that matters: Authentication tells you the product is real. Traceability tells you the real product is in the right place. A grey-market item passes authentication every time, because it is genuine. Only traceability flags the diversion.

Which threats does each capability detect?

Threat Authentication Traceability
Counterfeit products Detects No signal
Grey market diversion No signal Detects
Refill fraud (genuine container, wrong content) Partial: first-open detection via tamper loop Partial: geographic anomaly
Recall scope identification Limited Unit-level recall mapping
Distributor accountability No custody data Chain-of-custody record
Consumer verification at purchase Primary use case Not relevant
DPP compliance data carrier Partial: chip carries the identifier Partial: lifecycle events feed the record

The pattern is clear. Authentication and traceability have almost no overlap in threat coverage. A brand facing both counterfeiting and grey market diversion, which describes virtually every premium brand operating across markets with regional pricing differentials, needs both.

Why separate authentication and traceability systems fail

Many brands buy authentication from one provider and traceability from another. The authentication vendor supplies a chip. The logistics platform uses a different barcode or label with a different identifier. Each system works independently. Neither can answer combined questions.

The problem is fragmentation. When the authentication identifier and the custody-chain identifier are not the same, the brand cannot ask: “Did this authenticated genuine product come from the expected custody chain?” The two questions become unanswerable together, even though each system answers its own question correctly in isolation.

The infrastructure implication: a unified platform that delivers authentication and traceability from the same NFC chip and the same serialised identifier allows combined queries at any point. “This product is genuine (authentication) AND it is in the correct territory (traceability) AND its last custody event was with this specific partner (chain of custody).” None of those answers are available from separate systems. All three are available when both capabilities share one chip and one identifier.

When is authentication alone sufficient?

Authentication without traceability is appropriate in specific conditions:

  • The primary threat is counterfeiting, not diversion.
  • The brand has no significant grey market exposure.
  • Pricing differentials between markets are small, reducing diversion incentives.
  • The category has tightly controlled distribution with few intermediaries.

A brand protecting against counterfeit goods in a market with uniform pricing and short distribution chains can deploy authentication and address its most commercially significant threat without the additional data layer of traceability.

When is traceability alone sufficient?

Traceability without authentication fits supply-chain-internal contexts:

  • Logistics partners and warehouse operations tracking custody handovers.
  • Chain-of-custody compliance documentation.
  • Recall preparedness, where the goal is unit-level identification rather than consumer-facing verification.

Many logistics traceability deployments use non-cryptographic labels or standard barcodes. These provide no authentication security. They are not consumer-facing. They serve operational visibility, not brand protection.

Authentication and traceability by industry segment

Wine and spirits. Both capabilities are essential. Counterfeiting is a revenue and safety threat. Grey market diversion is pervasive in spirits, where duty-free, travel retail, and domestic channels carry different pricing. A secure NFC closure with a tamper-detection loop (TagTamper variant of NTAG 424 DNA) provides authentication and first-open detection simultaneously. Traceability flags bottles surfacing outside their allocated market.

Luxury goods and fashion. Counterfeiting drives the largest volume of seized goods: clothing, footwear and leather goods account for 62% of customs seizures (OECD/EUIPO, Mapping Global Trade in Fakes, 2025). Grey market diversion is equally damaging, particularly for items with regional pricing tiers. Both capabilities deployed from a single NFC tag embedded in the product or its packaging.

Cosmetics and fragrance. Counterfeits pose safety risks from unregulated ingredients. Grey market diversion, especially of prestige lines, undercuts authorised retail pricing. Authentication protects the consumer. Traceability protects the distribution strategy.

Watches and jewellery. High unit value makes both counterfeiting and diversion lucrative. NFC tags require on-metal variants with a ferrite layer to maintain read performance on metallic surfaces, at a 7-30% premium over standard tags.

Cigars. Authentication protects against counterfeit product in a category with limited consumer ability to verify visually. Traceability tracks units through complex multi-country distribution.

How much does secure NFC authentication cost per unit?

Published converter prices for NTAG 424 DNA-class labels cluster around $0.45-0.65 per unit at five-figure volumes, with on-metal variants at a 7-30% premium. Volumes above 50,000 units are quote-only (public catalogues, 2026).

Standard non-secure NFC tags (NTAG213 class) list around €0.19-0.23 at 1,000-10,000 units (public catalogues, 2026). These provide static data only, no cryptographic authentication.

The cost comparison that matters: the chip cost is the visible line item. The invisible cost is running two separate systems, one for authentication and one for traceability, with different identifiers, different platforms, and no combined query capability. Unification reduces total deployment cost and eliminates the integration gap.

What about the EU Digital Product Passport?

The central EU DPP registry under ESPR (Regulation (EU) 2024/1781) went live on 20 July 2026 (European Commission). First delegated acts for textiles and apparel are expected indicatively in 2027, with enforcement starting 18 months or more after each act.

The ESPR is data-carrier-neutral, but GS1 Digital Link QR is emerging as the de facto visible carrier for compliance. NFC serves as the trust layer: the QR carries the DPP data link, the NFC chip provides cryptographic authentication that the QR alone cannot deliver. Both authentication and traceability data feed the DPP lifecycle record.

Brands deploying NFC authentication and traceability today are building the infrastructure that DPP compliance will require. The chip is already the carrier. The serialised cloud record is already the data backbone.

40+ brands · 12+ years · €1.5B in product value protected.

Authentication and traceability are different questions with different answers, but they belong on the same chip. Selinko’s platform delivers both from a single NFC deployment: genuine or not genuine for the consumer, and where it came from for the brand.

FAQs

Does product authentication detect grey market diversion?

No. Authentication confirms whether a product is genuine, not whether it is in the correct market or channel. A grey-market item passes authentication because it is a real product. Detecting diversion requires traceability, which compares scan location against allocated territory and custody records.

Can traceability replace authentication?

Traceability tracks product movement but does not verify identity. A counterfeit item injected into the supply chain would appear in the custody record without being flagged as fake. Authentication and traceability address different threats and are complementary, not interchangeable.

Why should authentication and traceability use the same NFC chip?

When both capabilities share one chip and one serialised identifier, the brand can ask combined questions: “Is this product genuine AND is it in the right territory?” Separate systems with different identifiers cannot answer combined queries, creating a blind spot between authentication and custody data.

What NFC chip standard is used for product authentication?

Current-generation product authentication uses the NTAG 424 DNA chip family (ISO/IEC 14443-A, NFC Forum Type 4). It supports AES-128 encryption and Secure Unique NFC (SUN) messaging, generating a unique cryptographic response on every tap.

Do consumers need an app to authenticate a product?

No. iPhone XS/XR and later models read NFC tags in the background without an app. Android phones read NFC natively with the screen on. The consumer taps the product and sees the authentication result directly in their browser.

How does NFC traceability work for wine and spirits?

A secure NFC closure with tamper detection (TagTamper variant) is applied at bottling. Each custody handover is logged. When the bottle surfaces in a market, the scan location is compared against the allocated territory. If the location does not match, the brand receives an anomaly alert with the last authorised custodian identified.

Does NFC authentication work on metal products like watches?

Standard NFC tags detune on metal surfaces. On-metal tags with a ferrite layer solve this, maintaining read reliability at a 7-30% cost premium over standard labels. Authentication and traceability function identically on metal-mounted tags.

Is NFC or QR better for product traceability?

Traceability can use either carrier for scan-event logging. The difference is security: a QR code can be photographed and reproduced, making scan data unreliable for high-stakes custody evidence. An NFC chip with cryptographic authentication provides tamper-proof scan events, ensuring the traceability data is trustworthy.

Explore the platform

Blog

Discover more articles

All our articles