2020-05-03
Strawman Authentication and Anti-Counterfeiting with Cardano
- The University of Wyoming lab is designing a cheap, secure hardware chip to fight counterfeiting in luxury goods supply chains.
- A tiny trusted hardware module, similar in spirit to Intel's SGX or ARM's TrustZone, holds a private key that a consumer checks by tapping their phone against the product.
- The first version, Strawman Z1, uses Cardano's multi asset standard so a supply chain role called the Authenticator issues on chain authentication tokens.
- Even a stolen chip moved to a fake item only turns a one-to-many counterfeiting problem into a one-to-one one, already a huge improvement over the industry norm.
- The same chip and metadata design can carry ownership, loyalty programs, and resale royalties, and could later extend to livestock traceability and one-time signatures for stake pools.
- IOHK donated five hundred thousand dollars to the University of Wyoming lab, matched by the state, to build this as open source hardware in a public-private partnership.
6 chapters · 31 markers
The counterfeiting problem 3
The University of Wyoming laboratory is going to tackle anti-counterfeiting, starting from the problem that a handbag's supply chain creates chances for counterfeiting and theft at every stage before it reaches a retail store.
There is no standardized anti-counterfeiting approach across retailers like Gucci, LVMH, and Rolex, and the early generation techniques they use, invisible inks, holographic tags, and serial codes, are not consumer friendly.
Brands like Louis Vuitton and Chanel often refuse outright to authenticate their own products, and even a hired domain expert can be fooled since counterfeits are sometimes made in the very same factories as the real item.
Designing the authentication chip 3
The lab plans to design a small, secure chip capable of cryptographic operations, in the same spirit as Intel's SGX or ARM's TrustZone trusted hardware modules.
These chips can be tiny and extremely cheap, as low as one cent to make with NFC or RFID antennas, and the lab's first phase is to nail down the price target, size, memory, and computing power needed.
After requirements comes an iterative prototyping process, eventually handed to a finisher who turns the academic project into something mass manufacturable, with all of the lab's work released open source for the Cardano ecosystem.
The strawman token protocol 8
The proposed strawman solution, Strawman Z1, relies on Cardano's multi asset standard, arriving during the Shelley or Goguen era, to issue an authentication token.
The role responsible for issuing that authentication token is called the Authenticator, and somewhere in the supply chain the chip gets physically inserted into the handbag.
Later in the chain the Authenticator examines the handbag's history, and once satisfied, sends one of the authentication tokens to the chip's TPM.
Once the private key is encumbered with that token it cannot be extracted from a correctly designed chip, though a challenge response protocol can still test it.
The check is simple: the consumer taps their phone against the chip over NFC or RFID, the chip signs a challenge, and the questioner checks the Cardano blockchain to confirm a legitimate token on a legitimate TPM answered it.
Beyond the private key, the token's metadata field can store an object's full history, where it was made, which store sold it, its ownership record, even a chain of custody like a bag once owned by a famous actress.
The strawman's one kink is that removing the chip and moving it to a new handbag can fool the check, but that only turns one real bag into one fake, not many.
Ordinarily counterfeiting is a one-to-many business: a single legitimate Louis Vuitton, Gucci, or Christian Dior item can spawn hundreds or thousands of cheaper fakes.
Hardening the chip and building loyalty 5
A further hardening idea is pairing chips that regularly communicate with each other, so a chip that loses contact for too long can erase its own key, alongside other anti-tamper tricks.
Separating the Authenticator from the manufacturer builds oversight into the supply chain, and because the chips are programmable, their cryptographic protocols can grow more sophisticated over time.
A purchase transaction can register a product to a specific person on the blockchain, turning a Christian Dior handbag into Alice's certificate of authenticity, which then supports transferable warranties and resale royalties.
Loyalty systems become possible too: Lamborghini's rare special edition Reventon is sold through a lottery limited to buyers who can already prove they own a Lamborghini.
If a lottery winner does not want the car, the tokenized right to buy can be resold to someone else for a profit at no cost to Lamborghini, and these composable loyalty systems can keep building new consumer benefits and revenue lines.
Funding, roadmap, and one-shot signatures 6
It's a public-private partnership: IOHK donated five hundred thousand dollars to the University of Wyoming lab, the state is matching it, and the resulting chip design will be released as open hardware, like a Raspberry Pi reference design, for the whole Cardano ecosystem.
If the chip is powerful enough it could also live inside a USB key for one-time signatures, an idea that grows out of a one-shot signatures paper on quantum cryptography written by IOHK chief scientist Aggelos Kiayias with coauthors from Princeton and the University of Edinburgh.
This authentication chip is very likely to be paired with PRISM, Cardano's identity solution built on decentralized identifiers, once the multi asset standard ships.
The metadata can add a geography check too: if a purse was last seen in the US and reappears in China with no travel record in between, that mismatch can be flagged automatically.
None of these pieces is revolutionary alone, but combining a blockchain, a trusted hardware module, a phone app, and cryptography is what makes it robust, and it still rests on trusting that the chip, the token issuer, and the Cardano Foundation are all solid.
Even at a dollar per chip, likely an overestimate, that is a tiny addition next to handbags selling for thousands of dollars or Rolex watches going for fifty thousand, and because it all runs on Cardano the accounting is free and global with one universal app instead of a separate app per brand.
Trust, scale, and beyond luxury goods 6
Consumers can even verify the unit count directly: if only fifty thousand tokens were issued but the count suddenly jumps to seventy five thousand, that mismatch signals a problem with the product run.
Once a buyer like Alice is identity tethered to her handbag, the issuer gets a channel to push her targeted perks, like discount coupons, once she proves she is a verified owner.
This multi year academic and private partnership is expected to run well beyond 2020, built on PRISM, the Cardano blockchain, and the multi asset standard so the whole system abstracts away its complexity down to a simple tap, turning a one-to-many counterfeiting problem into a one-to-one one.
Old school protections like holographic stickers and secret ink can still be layered on as a last resort, and the system does not have to be owned by one manufacturer since no single company could be trusted to run a shared centralized database for hundreds of luxury brands.
Building a proper trusted hardware module is a genuinely hard engineering and academic problem, and the same design could be reused for stake pools or embedded in a biocompatible package implanted in livestock like cows and sheep, carrying medical history and even IoT tracking to verify claims like grass fed or free range.
This is planned as a permanent, multi generation effort with version one, two, and three of the chip always paired with PRISM. It is not a perfect solution and the Authenticator and the counterfeiter will keep fighting, but for the first time a consumer can verify something is real with just a tap of their phone.