The tag is genuine
We verify that the cryptographic signature, which changes on every tap, could only have been produced by the key inside the tag (NTAG424 DNA / SDM).

BRAND PROTECTION — SECURITY
For each attack anticipated in anti-counterfeiting, this page explains how Manica Brand Protection defends against it — and how far that protection goes. We distinguish what the mechanism prevents outright, what it detects and warns about, and what only works in combination with operational measures.
01 WHAT IS PROVEN
The "genuine" verdict on each tap is decided by checking three things: the tag's cryptographic signature, the read counter, and the brand's signed registration data. Blockchain recording is not a condition of the verdict — right after registration the verdict page shows "Pending," and once recording completes, the registration becomes evidence anyone can verify later. Every attack tries to break one of these, so it helps to know what is being verified first.
We verify that the cryptographic signature, which changes on every tap, could only have been produced by the key inside the tag (NTAG424 DNA / SDM).
We verify that the tap counter has advanced since the last read, distinguishing reuse of old scan data.
A digital signature made with the brand's secret key verifies who registered what, and when. The signature is also recorded on the blockchain, proving that "it certainly existed at that point in time" (03 Proof of existence).
02 ATTACKS & DEFENSES
Attack
This method writes data read from a genuine tag onto an off-the-shelf NFC tag to make an identical one. QR codes and printed holograms can be duplicated this way. Even UID-only schemes can be defeated with special tags whose UID can be rewritten.
Defense
Limit
The best a clone can do is hold one previously read URL. Using it becomes attack 02 below and falls under detection.
Attack
This method reposts a URL obtained by tapping a genuine tag once — via a QR code on a fake product, a clone tag, or a web page — to display the "genuine" verdict. Because the signature itself is genuine, signature verification alone cannot catch it.
Defense
Limit
If the latest stolen URL is used before the genuine tag has ever been tapped, that single use is judged genuine. But once the genuine tag is tapped and the counter advances, all subsequent reuses are detected.
Attack
A counterfeiter prepares their own tags and registers them under a famous brand's name to claim authenticity. This works in any system where anyone can register a brand name.
Defense
Limit
The brand-name string itself can be registered by others. What distinguishes registrants is the key — and for consumers to tell an official registration, it helps if the brand points to its own registration on its official site or elsewhere.
Attack
This method rewrites the registered tag list or product info on the server afterward — swapping registrations to other products or backdating registration times. It includes insider abuse by server administrators or intruders.
Defense
Limit
What is recorded on the blockchain is the signature (hash), not the product names or images themselves. Recording is also requested after registration; until it completes, the verdict page shows "Pending." The mechanism does not make tampering impossible — it makes tampering detectable by comparison once recording completes.
See how blockchain recording proves "existence" and "time" (03) →
Attack
This method attaches a tag pointing to a different website prepared by the counterfeiter. That site mimics the real verdict page and always shows "genuine." Because it never touches the cryptographic authentication, no technical check can block it.
Defense
Limit
This attack is a weakness common to every NFC- and QR-based authenticity system. It cannot be prevented by mechanism alone — it presumes the operational measure of telling consumers which domain to check.
Attack
This method peels just the tag off a genuine product and sticks it on a fake. Since the tag is real, cryptographic verification passes normally.
Defense
Limit
Reattachment cannot be prevented by mechanism alone. Since each fake requires one genuine tag, the method doesn't scale to mass counterfeiting — but for high-value goods, physical countermeasures are needed too.
Attack
Even if each fake can be spotted, you won't know where to act if you can't see which products are being targeted, since when, and how much.
Defense
Limit
Statistics indicate "signs" — they don't establish the fact of counterfeiting or identify distribution channels. Investigation and response after finding anomalies remain the brand's call.
03 PROOF OF EXISTENCE
Blockchain recording does more than "detect tampering." Its real purpose is to preserve, in a form no one — including us — can rewrite, the fact that "this registration certainly existed at that point in time." The procedure has four steps.
STEP 1
We compile the registration time, target tag IDs, and comment into a single text.
STEP 2
We sign it with the brand's secret key — a declaration that "this company registered these tags with this content."
STEP 3
A fixed-length value is computed from the signed document. Changing even a single character yields a different value.
STEP 4
The hash is written to the blockchain (OP_RETURN). Nodes around the world hold it, and no one can rewrite it.
Existence
A document bearing the same hash must have existed when the block was created. Something made later cannot be passed off as "already existing back then."
Time
No one — not us, not the brand — can change a block's timestamp. What is proven is "it existed no later than this time," and comparing the registration time in the document against the record time reveals whether a registration was made later.
Signer
Because the document contains the signature, it even proves "the brand declared this content at that time."
Third parties can verify it.
The verdict page shows a link to the transaction holding the record, and anyone can confirm the record's existence and time on the blockchain. Matching it against the contents requires the signed verification document — recomputing the hash from the document we present lets verification hold without trusting our server's answers.
Limits
04 COMPARISON
○ = built into the mechanism, △ = conditional / requires operational measures, — = not provided. These are general characteristics of each scheme, not an evaluation of individual products.
| Attack / requirement | QR code | Printed hologram | Standard NFC(UID check only) | Manica Brand Protection(NTAG424 DNA + blockchain) |
|---|---|---|---|---|
| Copying data verbatim | — | △ | △ | ○ |
| Reusing a scanned URL | — | — | — | ○ |
| Impersonating a registration | — | — | — | △ |
| Tampering with registration data | — | — | — | ○ |
| Leading to a fake site | △ | — | △ | △ |
| Reattaching a genuine tag | △ | △ | △ | △ |
| Consumer can verify without a dedicated app | ○ | △ | ○ | ○ |
05 HONEST LIMITS
We can also advise on attachment methods suited to your products and on combining with your existing anti-counterfeit measures.