MANICA Brand Protection logo

BRAND PROTECTION — SECURITY

Why can't it be copied?

For each attack anticipated in anti-counterfeiting, this page explains how Manica Brand Protection defends against it — and how far that protection goes. We distinguish what the mechanism prevents outright, what it detects and warns about, and what only works in combination with operational measures.

← Back to the Manica Brand Protection overview

01 WHAT IS PROVEN

These are the three things we verify.

The "genuine" verdict on each tap is decided by checking three things: the tag's cryptographic signature, the read counter, and the brand's signed registration data. Blockchain recording is not a condition of the verdict — right after registration the verdict page shows "Pending," and once recording completes, the registration becomes evidence anyone can verify later. Every attack tries to break one of these, so it helps to know what is being verified first.

The tag is genuine

We verify that the cryptographic signature, which changes on every tap, could only have been produced by the key inside the tag (NTAG424 DNA / SDM).

This read is new

We verify that the tap counter has advanced since the last read, distinguishing reuse of old scan data.

The registrant and registration are correct

A digital signature made with the brand's secret key verifies who registered what, and when. The signature is also recorded on the blockchain, proving that "it certainly existed at that point in time" (03 Proof of existence).

02 ATTACKS & DEFENSES

Attack methods, and how each is stopped.

Blocked by designDetected & warnedCombined with operations
ATTACK 01Blocked by design

Copying a tag's contents verbatim (clone tag)

Attack

This method writes data read from a genuine tag onto an off-the-shelf NFC tag to make an identical one. QR codes and printed holograms can be duplicated this way. Even UID-only schemes can be defeated with special tags whose UID can be rewritten.

Defense

  • NTAG424 DNA generates the URL inside the tag on every tap (SDM: Secure Dynamic Messaging). The URL contains the tag's unique ID, a tap counter, and a cryptographic signature (AES-CMAC) computed from both.
  • The key used to compute the signature lives inside the tag and cannot be read out. A clone without the key cannot produce a new valid signature.
  • A matching UID alone is not judged as genuine. Only reads that pass signature verification are treated as authentic.

Limit

The best a clone can do is hold one previously read URL. Using it becomes attack 02 below and falls under detection.

ATTACK 02Detected & warned

Reposting or reusing a scanned URL (replay attack)

Attack

This method reposts a URL obtained by tapping a genuine tag once — via a QR code on a fake product, a clone tag, or a web page — to display the "genuine" verdict. Because the signature itself is genuine, signature verification alone cannot catch it.

Defense

  • The counter in the URL advances by one every time the genuine tag is tapped. The server remembers the last-seen counter for each product and judges any read that hasn't advanced as "copied data."
  • The verdict is shown to the consumer on the spot ("This data may have been copied" on the verdict page). A reused URL cannot produce the genuine screen.
  • The number of reuses is aggregated as "copy detections" in the admin scan statistics, so the brand side can see them too.

Limit

If the latest stolen URL is used before the genuine tag has ever been tapped, that single use is judged genuine. But once the genuine tag is tapped and the counter advances, all subsequent reuses are detected.

ATTACK 03Blocked by design

Registering products under another company's brand (impersonation)

Attack

A counterfeiter prepares their own tags and registers them under a famous brand's name to claim authenticity. This works in any system where anyone can register a brand name.

Defense

  • Registrations are signed with a per-company secret key (a digital-signature key of the same kind used by Bitcoin). A signature can only be made by the company holding the key, and the brand information shown on the verdict page is limited to registrations signed by that key.
  • The secret key is stored encrypted on MANICA's servers and never sent outside. Brand staff never need to handle the key.
  • Even if a third party registers under the same brand name, the different key distinguishes them as a different registrant.

Limit

The brand-name string itself can be registered by others. What distinguishes registrants is the key — and for consumers to tell an official registration, it helps if the brand points to its own registration on its official site or elsewhere.

ATTACK 04Blocked by design

Altering contents after registration (tampering / insider abuse)

Attack

This method rewrites the registered tag list or product info on the server afterward — swapping registrations to other products or backdating registration times. It includes insider abuse by server administrators or intruders.

Defense

  • A digital signature over the registration (timestamp, target tag IDs, comment) is recorded on the Bitcoin blockchain. Since blockchain records cannot be changed once written, comparing the registration against the record after completion reveals whether anything was altered.
  • Registrations accumulate as versions, and past versions can be viewed in the admin console's version history — a timeline of who registered which tags and when.

Limit

What is recorded on the blockchain is the signature (hash), not the product names or images themselves. Recording is also requested after registration; until it completes, the verdict page shows "Pending." The mechanism does not make tampering impossible — it makes tampering detectable by comparison once recording completes.

See how blockchain recording proves "existence" and "time" (03)

ATTACK 05Combined with operations

Fake tags that lead to a fake verdict site

Attack

This method attaches a tag pointing to a different website prepared by the counterfeiter. That site mimics the real verdict page and always shows "genuine." Because it never touches the cryptographic authentication, no technical check can block it.

Defense

  • The authentic verdict page is always served on the bp.manica.jp domain. Consumers can spot fakes by checking the domain in the browser's address bar.
  • The verdict page displays the registered company name and brand info. If the brand announces on its official site or packaging that "authenticity is verified on bp.manica.jp," consumers can judge more easily.

Limit

This attack is a weakness common to every NFC- and QR-based authenticity system. It cannot be prevented by mechanism alone — it presumes the operational measure of telling consumers which domain to check.

ATTACK 06Combined with operations

Peeling a genuine tag off and reattaching it to a fake

Attack

This method peels just the tag off a genuine product and sticks it on a fake. Since the tag is real, cryptographic verification passes normally.

Defense

  • What authenticity verification proves is that "this tag was legitimately registered." The physical bond between tag and product is determined by how it is attached.
  • We recommend implementations that prevent reuse after removal: tamper-evident tags that break when peeled, sealing inside packaging, or placing the tag where opening the package cuts it.
  • For products managed in MANICA, lending, return, and inventory history is kept per item — you can track where a genuine item should be, which helps detect leakage.

Limit

Reattachment cannot be prevented by mechanism alone. Since each fake requires one genuine tag, the method doesn't scale to mass counterfeiting — but for high-value goods, physical countermeasures are needed too.

ATTACK 07Detected & warned

Missing signs that counterfeits are spreading

Attack

Even if each fake can be spotted, you won't know where to act if you can't see which products are being targeted, since when, and how much.

Defense

  • In the admin scan statistics, you can check daily per-product counts of verdicts, copy detections, and suspicious reads.
  • We estimate actual taps from how the genuine tag's counter advances, and the gap versus verdict counts reveals signs of "tags being read without the page opening" (attempts at cloning).
  • If copy detections or suspicious reads concentrate on a specific product or period, treat it as a sign that counterfeiting of that product is being attempted and consider countermeasures.

Limit

Statistics indicate "signs" — they don't establish the fact of counterfeiting or identify distribution channels. Investigation and response after finding anomalies remain the brand's call.

03 PROOF OF EXISTENCE

Bitcoin certifies that the registration existed, with a timestamp.

Blockchain recording does more than "detect tampering." Its real purpose is to preserve, in a form no one — including us — can rewrite, the fact that "this registration certainly existed at that point in time." The procedure has four steps.

STEP 1

Verification document

We compile the registration time, target tag IDs, and comment into a single text.

STEP 2

Digital signature

We sign it with the brand's secret key — a declaration that "this company registered these tags with this content."

STEP 3

Hash (fingerprint)

A fixed-length value is computed from the signed document. Changing even a single character yields a different value.

STEP 4

Record on Bitcoin

The hash is written to the blockchain (OP_RETURN). Nodes around the world hold it, and no one can rewrite it.

Existence

It certainly existed at that time

A document bearing the same hash must have existed when the block was created. Something made later cannot be passed off as "already existing back then."

Time

The recorded time cannot be moved

No one — not us, not the brand — can change a block's timestamp. What is proven is "it existed no later than this time," and comparing the registration time in the document against the record time reveals whether a registration was made later.

Signer

Who declared it is also preserved

Because the document contains the signature, it even proves "the brand declared this content at that time."

Third parties can verify it.

The verdict page shows a link to the transaction holding the record, and anyone can confirm the record's existence and time on the blockchain. Matching it against the contents requires the signed verification document — recomputing the hash from the document we present lets verification hold without trusting our server's answers.

Limits

  • Only the hash is recorded. The document itself is kept by us and matched at verification time.
  • Recording is batched after registration, so until it completes the verdict page shows "Pending" (typically within a few days).
  • What is proven is that "the registration existed at that time." The quality of the product itself, and the physical bond between tag and product, are not proven.

04 COMPARISON

Comparison with common authenticity schemes.

○ = built into the mechanism, △ = conditional / requires operational measures, — = not provided. These are general characteristics of each scheme, not an evaluation of individual products.

Attack / requirementQR codePrinted hologramStandard NFC(UID check only)Manica Brand Protection(NTAG424 DNA + blockchain)
Copying data verbatim
Reusing a scanned URL
Impersonating a registration
Tampering with registration data
Leading to a fake site
Reattaching a genuine tag
Consumer can verify without a dedicated app

05 HONEST LIMITS

We're also upfront about what it can't do.

  • We don't claim "100% counterfeit prevention" or "absolutely impossible to copy." The value of this mechanism is that cryptography makes copying extremely difficult, and that reuse can be detected and flagged.
  • What is proven is the authenticity of the tag and its registration. The quality of the product itself and the physical bond between tag and product are ensured operationally — through attachment and sealing methods.
  • Consumers knowing the verification domain (bp.manica.jp) is a prerequisite for fake-site countermeasures. We recommend noting it on packaging and official sites.

Questions about adoption or technical details? Ask away.

We can also advise on attachment methods suited to your products and on combining with your existing anti-counterfeit measures.