PUF transponder for attaching to a physical product, and system for digitally verifying the authenticity of the product using a PUF transponder and a blockchain
The marking module with a transponder and PUF code synchronized with a blockchain addresses vulnerabilities in conventional authentication methods, offering secure and user-friendly product verification through a unique blockchain-based security anchor.
Patent Information
- Application Number
- PCT/CH2025/050034
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-05-14
- Filing Date
- 2025-09-15
- Publication Date
- 2026-01-08
AI Technical Summary
Conventional product authentication methods using RFID or NFC tags and blockchain are vulnerable to manipulation and require additional readers or applications, lacking user-friendly and secure verification.
A marking module with a transponder that generates a PUF code based on physically unclonable functions, synchronized with a blockchain, creating a unique blockchain-based security anchor for product authentication, using a data structure that includes a product ID and timestamp, and supports quantum-safe signatures.
Provides tamper-proof, user-friendly, and secure digital authentication by linking a unique PUF code to a blockchain-based security anchor, ensuring seamless traceability and immutability of product information.
Smart Images

Figure CH2025050034_08012026_PF_FP_ABST
Abstract
Description
PUFT transponder for attaching to a physical product and system for digital product authentication using a PUF transponder and a blockchain.
[0001] The present invention relates to a marking module for attachment to a physical product and a system for digitally verifying the authenticity of a physical product using the marking module and a blockchain.
[0002] Product authentication, also known as product verification, is required in sectors such as pharmaceuticals, nutritional supplements, medical technology, cosmetics, art dealing, luxury goods, and for physically documented valuables like precious metals, jewelry, watches, gemstones, or high-priced individual items. Generally, product authentication is relevant in all areas where consumers or buyers are unable to distinguish between genuine and counterfeit products.
[0003] The unintentional purchase or use of a counterfeit product is reprehensible from a legal, ethical, and economic perspective. Often, the purchase or possession of a counterfeit product is prohibited or at least legally problematic. Buyers believe they possess a valuable product, when in reality they have a copy that is inferior in value and / or quality. Manufacturers of genuine products lose revenue due to product piracy. Furthermore, counterfeit products often fail to meet the quality standards of the originals, which can lead to health or safety risks, particularly with medications, cosmetics, electronics, or mechanical components.
[0004] For product identification and authentication, the use of counterfeit-proof RFID or NFC tags (RFID: Radio-Frequency Identification, NFC: Near Field Communication) is common. Such "tags" are often also referred to as (electronic or digital) product labels. Another well-known option is to use a [missing information - likely a specific type of product label] as a product label. A visually visible code is attached to the product, such as a barcode or QR code, which allows product information to be retrieved from a database using this code. Conventional NFC tags or product labels with visual codes have the disadvantage of offering limited security against manipulation or duplication of the information they contain. Manipulation can occur, for example, directly on the label and / or when comparing it with information stored in a database about the product label.
[0005] A known step in the art to increase security involves combining product labels (also called product tags or, more generally, "identification modules") with blockchain solutions, for example, combining near-field communication with a non-fungible token (NFT). For instance, it is known to store a product code on an NFC or RFID tag and attach the tag to the product. The product code, which can be read using an NFC- or RFID-enabled reader, is then assigned to a non-fungible token (NFT) stored in a blockchain.
[0006] However, conventional near-field tags such as RFID or NFC tags only store limited data, and the communication between the near-field tag and the server database providing the blockchain remains vulnerable. Therefore, there is a need to further increase tamper resistance.
[0007] Visual codes affixed to products or codes provided via RFID or near-field communication can still often be easily copied or counterfeited, for example, by a counterfeiter applying the same code from a genuine product to a fake. Linking the code to a blockchain does not immediately eliminate this vulnerability. If the code is copied, each copy simply displays the same blockchain entry. However, there is no connection to the physical product, and the code on the counterfeit displays a genuine blockchain entry, meaning the buyer still cannot reliably identify the fake.
[0008] Existing authentication systems often require the use of readers and / or applications specifically designed for near-field tags. This can be disadvantageous for the consumer or buyer because spontaneous authentication may not always be possible without first acquiring the necessary reader or application.
[0009] Therefore, one of the aims of the invention is to provide an improved digital authentication of a physical product, overcoming the disadvantages described above.
[0010] Another task is to provide digital authentication, which offers increased security against manipulation.
[0011] Another task is to increase the user-friendliness of digital authentication while maintaining or further increasing the security level based on the state of the art.
[0012] These problems are solved by realizing at least some of the characterizing features of the independent claims. Features that further develop the invention in an alternative or advantageous way can be found in some of the remaining features of the independent claims and in the dependent claims.
[0013] The invention relates to a marking module configured for attachment to a physical product to provide digital product authentication. The marking module includes a transponder with a blockchain communication interface configured to communicate with a blockchain via the internet. The transponder is configured to generate a PUF code based on a physically unclonable function (PUF). Furthermore, the transponder is configured to synchronize with the blockchain via the blockchain communication interface. For this purpose, the transponder provides the PUF code with A data structure tailored for verification and / or creation of a blockchain-based security anchor within the blockchain is provided. This data structure includes, among other things, a product ID and a timestamp, enabling the PUF code to be assigned to a uniquely assigned blockchain-based security anchor within the blockchain, which is linked to unique product information.
[0014] The blockchain-based security anchor provides a unique, verifiable, and tamper-proof representation of a data state on the blockchain. For example, the blockchain-based security anchor can be token-based, message-based, or state-based. Each blockchain-based security anchor is unique and can only exist once. The blockchain-based security anchor with the associated product ID represents exactly one physical product, such as a drug package, and can also be referred to as the product's "digital twin."
[0015] For example, the blockchain-based security anchor can be designed as an immutable and uniquely identifiable object (also called an on-chain data object) stored on the blockchain, enabling seamless traceability (and linkable with metadata or references). The anchor thus serves as immutable proof of the existence, integrity, and ownership of a digital data record. It enables audit-proof archiving and transparent tracking of data changes. The unique addressability and traceability therefore provide tamper-proof, blockchain-based validation of unique product information (in the sense of a so-called "digital twin" of a physical product).
[0016] The blockchain-based security anchor, for example, provides an anchoring of the product ID in the blockchain or verification of the product ID using the blockchain to check the authenticity, integrity and ownership history of a physical product, by means of - tokenized verification: for example, by creating an NFT on a Blockchain (e.g. ICP, Ethereum, Polygon); - P2P message-based verification: for example, through signed blockchain messages (e.g., Signum Messaging, Canister Communication on ICP); - Hash-based status verification: Storing a PUF hash as a transaction or reference value in a smart contract, even without tokenization; - Broadcast-based proof of ownership: e.g., through public-key broadcast at blockchain level with timestamp as proof of ownership; - Chain-based verification link: Linking to decentralized referenced URLs that enable browser-based real-time verification (WebAuthn, QR-on-chain).
[0017] This modular verification architecture allows for a blockchain-agnostic design and is compatible with various protocols. In general, the blockchain-based security anchor, as defined in the invention, is an element or architecture that provides any form of blockchain-based digital verification, including but not limited to: tokenized data objects (e.g., NFTs), blockchain-based message verification (e.g., transaction attachments, messaging layers), smart contract-based status checks, event log verification, cryptographic signature matching, state queries within distributed ledger systems, and zero-knowledge protocols for maintaining confidentiality.
[0018] The architecture allows, in particular, integration with existing and future blockchain standards, including but not limited to: ICP, Signum, Ethereum, Polygon, Substrate, Hedera, Cosmos, as well as private or hybrid ledger environments.
[0019] For example, the blockchain-based security anchor is a token according to a predefined standard (e.g., ERC-721, ICP DIP721, etc.) that serves as a certificate of authenticity and proof of ownership, e.g., an on-chain data object according to NFT or equivalent verification standard.
[0020] An on-chain data object within the meaning of the invention is, for example, a digitally stored data block stored on a distributed ledger infrastructure (blockchain, DLT) that fulfills at least the following properties: - it is uniquely addressable (e.g. via hash, transaction ID or token ID); - it is demonstrably linked to a physical product (e.g. via PUF hash); - it allows automated verification of its validity or ownership history through on-chain access; - it is created or modified by a cryptographically signed transaction; - it can, but does not have to, conform to a token standard (e.g. NFT, Message, State Object).
[0021] The blockchain-based security anchor is, in particular, a structured, addressable data structure within a distributed ledger system and serves for unique addressability, physical product linking via a PUF-based hash value, and blockchain-based validation of ownership or authenticity status, e.g., either token-based, message-based, or state-based.
[0022] In general terms, the inventive transponder is configured to directly generate a transponder-specific identification code at the hardware level. This identification code is mined with unique product information to a blockchain-based security anchor (e.g., an on-chain data object) on a blockchain. After referencing on the blockchain, a product-specific identification code is created in the blockchain that correlates at all times with the physically generated identification code.
[0023] The data generated by the transponder is transmitted in a structured data format (e.g., JSON or byte matrix, binary serialized) and includes, in addition to the PUF code, a reference ID (e.g., containing serial number, batch, product type, production date, manufacturer ID, therefore also called product ID), a timestamp, and optionally status data (e.g., from monitoring sensors and / or auxiliary sensors as described below). described) and / or Challenge ID (for offline verification as described below), which allows them to be used, for example, directly for verification or creation of a blockchain-based security anchor on the blockchain.
[0024] For example, the data structure is designed so that it can be used directly by a blockchain backend such as a Minting API, Canister, or Gateway to create or verify a blockchain-based security anchor or on-chain data object. The data transfer includes, for example, structured information such as JSON with PUF hash, timestamp, and product ID, which can be used directly for NFT minting, messaging, or state change processes.
[0025] The transponder, for example, has internal communication logic (e.g., as FSM in VHDL) that prepares the structuring of the PUF code and its transmission to an external verification interface. The actual process of NFT minting and blockchain synchronization is carried out via external components, such as a web frontend, a gateway, or a mobile client.
[0026] The structured data representation for transferring the PUF code and accompanying data (e.g., product ID, timestamp, event information) to external verification interfaces (e.g., Minting API, Blockchain Gateway, Canister) can, for example, be provided in the form of a byte matrix. This is a clearly defined data structure containing the various values at fixed byte positions. Alternatively, a JSON format or a binary serialization format (e.g., CBOR, Protobuf) can be used, which is suitable for both embedded systems and blockchain-compatible interfaces.
[0027] For example, the transponder has an FPGA (see descriptions below) and the PUF code is transferred to the FPGA after generation by the initial contact, where it includes time and sensor values. supplemented and passed via the blockchain interface to an on-chain data object minting module (e.g. NFT minting module).
[0028] Product metadata can be stored on the transponder (e.g., on pre-configured flash memory) or externally at the verification system (e.g., in a database linked via the product ID). At a minimum, the transponder is designed to provide the PUF code and the reference ID (product ID) and exchange them with the verification platform.
[0029] The generation of the PUF code utilizes unavoidable physical differences that arise during the manufacturing of a transponder component, such as variations in the production of microprocessors, chips, or FPGAs, caused, for example, by minute differences in transistor sizes, switching times, etc. This creates a kind of "digital fingerprint" of the component or transponder. These differences are random, unpredictable, and non-reproducible. The PUF code is therefore unique to the component from which it was generated. For example, the physical properties or manifestations used to generate the PUF code are "captured" when the component is powered on, by exploiting the fact that an actual physical state provides a unique response to a defined query (this query-response behavior is unique to the component).
[0030] In one embodiment, the transponder is configured to generate a reproducible fault-tolerant extraction of the PUF code from a noisy signal, e.g. using a determinist fuzzy extractor.
[0031] In another embodiment, the transponder is configured to generate auxiliary data for the reproducible fault-tolerant extraction of the PUF code, wherein the auxiliary data enables the reconstruction of the PUF code from a noisy signal without revealing the PUF code itself.
[0032] In another embodiment, the transponder is configured so that the auxiliary data is contained in the data structure tailored for creating the blockchain-based security anchor, thus enabling the auxiliary data to be mapped to the blockchain-based security anchor in the blockchain. Alternatively or additionally, the auxiliary data can be stored on the transponder itself.
[0033] For example, the transponder features a fuzzy extractor (FE) with error correction functionality (ECC: Error Correction Code), e.g., a deterministic FE. The FE and the ECC are configured to generate the reproducible, fault-tolerant extraction of the PUF code from the noisy signal.
[0034] Since PUF codes are inherently sensitive to environmental influences (e.g., temperature fluctuations, power supply variations, material aging), they are stabilized using a fuzzy extractor and error correction (ECC). This allows, for example, the reconstruction of a stable digital hash value from the inherently noisy PUF signal without the need for permanent storage. This enables repeatable and reliable authentications even with slight measurement deviations. The integration of this technology also ensures the long-term stability of the system. Typical ECC methods include, for example, BCH codes or Reed-Solomon codes, which can be efficiently implemented in hardware.
[0035] When using a fuzzy extractor, for example, it is no longer necessary to temporarily store the PUF code on the transponder. The PUF code (e.g., a hash) is regenerated from the PUF with each interaction and can be verified against an on-chain stored reference value (the original PUF code generated during transponder initialization).
[0036] Since the blockchain-based security anchor is created directly from the PUF-based code, a forger would have to possess both the physical Copying the "fingerprint" of the transponder as well as the blockchain registration is practically impossible.
[0037] Furthermore, the blockchain-based security anchor can record an immutable history of specific events (e.g., captured by the identification module), such as production date, sensor data, and transport conditions. This history is tamper-proof because it is stored on the blockchain. In particular, the identification module can, for example, also have a break-sensitive conductor track, configured to detect when the identification module is removed from the product. For instance, the system is configured to write the history of such events (called authenticity events) to the blockchain in periodic anchor transactions, e.g., in a rollup format.
[0038] In one embodiment, the transponder is configured to provide the PUF code based on a light pulse, heat, or voltage activation. The transponder is initialized, for example, by defined physical triggers such as light pulses, heat, or voltage. These triggers are detected by integrated sensors, whereupon a programmed sequence (state machine) in the transponder is started, e.g., controlled by an FPGA (Field-Programmable Gate Array) within the transponder.
[0039] For example, the transponder is configured to execute the following logic sequence: 1.) The physical trigger (e.g., light or voltage) is detected by the sensor; 2.) The transponder activates the PUF function; 3.) The PUF code is generated based on random material properties; 4.) The PUF code is timestamped; 5.) A hash (e.g., using SHA-256) is generated directly from the PUF output; 6.) A transaction signal is transmitted to an NFT minting module. This controlled sequence guarantees that the signature is unique, non-reproducible, and temporally unambiguous.
[0040] In another embodiment, the marking module is configured to provide a quantum-safe signature, such as XMSS or SPHINCS+, for signing the PUF code. For example, the quantum-safe signature (e.g., XMSS or SPHINCS+) is directly cryptographically integrated into an NFT creation and verification process by encrypting the PUF code (e.g., hash) generated from the PUF using a quantum-safe signature. This signature is either stored directly in the NFT metadata or logically linked to the NFT as a separate checksum. The signature secures both the identity of the physical product (PUF code) and the integrity of the transaction itself (minting, timestamp, metadata).
[0041] For example, the identification module, as described earlier, is embedded in a security system configured as follows: After the transponder is initialized, the PUF code is generated by a physically uncopyable function (PUF). This PUF code is the digital equivalent of a hardware fingerprint and serves to uniquely identify each physical product unit. The assignment to the blockchain-based security anchor is achieved through cryptographically secured communication: The transponder transmits the generated PUF code, along with associated product metadata (e.g., serial number, batch, product type), to an NFT minting engine connected to the blockchain. There, a non-fungible token (NFT) is generated based on this data according to the ERC-721 or ERC-1155 standard, with the PUF code being stored in the NFT metadata (on-chain or off-chain via IPFS).This creates a non-manipulable connection between the hardware-generated signature and the digital NFT, which permanently maps the authenticity, identity and history of the product.
[0042] For example, the labeling module is also configured to provide a quantum-safe signature for the product information, e.g. with XMSS or SPHINCS+.
[0043] For example, the transponder is configured to control communication via the blockchain communication interface and, for example, communication via the readout interface (see below) via an internal state machine (e.g., FSM, Finite State Machine), for example, where the finite state machine is implemented in VHDL or Verilog.
[0044] For example, the transponder is designed as an FPGA-based transponder, with the FPGA controlling communication to an on-chain data object website (e.g., an NFT website) and, if applicable, to the read interface (see details of the read interface below). Optionally, an authentication or cryptography unit can be implemented in the FPGA to ensure the integrity and authenticity of the product code during communication with the blockchain via the blockchain communication interface and / or when reading the product code via the read interface described below.
[0045] In another embodiment, the identification module has a non-volatile memory, e.g. a flash memory, which is connected to an FPGA of the transponder or externally to an FPGA of the transponder and is configured to store the PUF code.
[0046] For example, the transponder is configured so that the data structure adapted for the creation of the blockchain-based security anchor in the blockchain is provided in such a way that the uniquely assigned blockchain-based security anchor is generated in the blockchain according to the ERC-721 or ERC-1155 standard and is provided with a timestamp, batch number and product ID.
[0047] The transponder is based on an FPGA, for example, where the transponder has a miniaturized FPGA.
[0048] FPGAs (Field Programmable Gate Arrays) are programmable digital components that offer diverse interfaces (e.g., SPI, I2C, Ethernet) and flexible logic, enabling direct connection to internet services (e.g., NFT websites). This enables the linking to the blockchain-based security anchor of the blockchain to be automated and hardware-based, e.g. including a quantum-safe signature such as an XMSS signature (XMSS: extended Merkle Signature Scheme) for even greater security.
[0049] For example, the FPGA-based transponder is configured to establish a connection to an NFT website via the internet using communication logic such as Ethernet or WiFi MAC on an FPGA. The PUF code can then be synchronized or validated with the NFT on the website.
[0050] For example, the transponder is based on a miniaturized FPGA with a maximum size of 2 mm x 2 mm. Even more miniaturized FPGA chips already exist, e.g., smaller than 0.2 mm. Currently, the use of chips with a size of less than 0.9 mm down to less than 0.1 mm is realistic according to the invention.
[0051] In another embodiment, the transponder is configured to provide, as a response to an authentication function conducted via internet communication, a current readout of the PUF code with a data structure tailored to verifying the blockchain-based security anchor. Thus, based on a check to see if the assignment of the PUF code to the blockchain-based security anchor in the blockchain matches the current readout of the PUF code, product authentication can be provided.
[0052] In another embodiment, the transponder is configured to provide the current readout of the PUF code, taking into account auxiliary data associated with the blockchain-based security anchor. This auxiliary data is provided to the transponder for authentication purposes when the transponder communicates over the internet. The auxiliary data associated with the blockchain-based security anchor provides a reproducible Fault-tolerant extraction of the PUF code from a noisy signal is provided without revealing the PUF code itself. In particular, the auxiliary data (e.g., in the form of a so-called helper string) was generated by the transponder during initialization and stored on the blockchain (see above).
[0053] For example, the identification module is configured so that the communication of the transponder via the Internet for the authentication functionality and the associated current reading of the PUF code is initiated by scanning an NFC tag (NFC: Near-Field Communication) of the identification module and / or by an external request arriving via the blockchain communication interface.
[0054] Product authentication can be performed in a user-friendly manner via a verification platform in the form of a browser-based web application. For example, the identification module is configured so that the consumer or inspector scans either an NFC tag or a QR code affixed to the product. This opens a web application that establishes a connection to the blockchain and / or an on-chain data object database (e.g., an NFT database) via a predefined communication set, such as an API (Application Programming Interface). The predefined communication set defines how the transponder communicates with the blockchain and / or the on-chain data object database, for example, exchanging data without user intervention. This data exchange occurs in real time and on a predefined structure, thus simplifying interaction between different systems.The data exchange based on the communication ruleset provides, for example, a check to see if the PUF code stored on the blockchain matches a hash currently read from the transponder (which should correspond to the PUF code). The web application then displays one of the possible results in real time, e.g., "Genuine," "Modification risk," or "Forgery." The entire process works without an app, wallet, or registration—exclusively in the browser.
[0055] For example, the verification platform features a web server frontend with an integrated API backend. It communicates directly with the blockchain (e.g., Ethereum, ICP, or Polygon) via RPC interfaces or canister calls. The platform compares the PUF data sent by the transponder, the stored on-chain data object metadata on the blockchain, and the XMSS signature for security. All security-relevant processes, especially PUF verification, on-chain data object access, and, if necessary, event evaluation (see the following description), are protected, for example, by quantum-safe signatures such as XMSS. These can be generated by the transponder itself or by a server component (HSM or signature module).
[0056] It goes without saying that the process can alternatively also be carried out via a dedicated mobile application, whereby the application accesses the security anchor stored on the blockchain.
[0057] In another embodiment, the transponder has a read interface and is configured to automatically provide (enable) product authentication as part of its authentication functionality, e.g., in real time. Reading product information via the read interface requires authorization based on product authentication. Product authentication is performed through communication via the blockchain communication interface and based on the assignment of the PUF code to the blockchain-based security anchor in the blockchain.
[0058] The transponder is further configured, for example, to provide a quantum-safe signature for product information, specifically using XMSS or SPHINCS+. When using XMSS, for instance, a secure, rollback-protected OTS index is maintained, with key rotation occurring when a threshold is reached.
[0059] In another embodiment, the identification module is configured to provide a check, as part of the transponder's communication via the Internet for the authentication functionality, to verify whether a quantum-safe signature of the PUF code is valid.
[0060] In another embodiment, the transponder features monitoring sensors configured to detect physical changes within the transponder and / or mechanical impacts on the transponder. For example, the monitoring sensors are configured to detect at least one of the following: voltage differences, temperature differences, voltage variations, humidity differences, pressure differences, light variations, chemical markers, and vibrations. The transponder is further configured to automatically provide monitoring sensor data via the blockchain communication interface for the purpose of assigning the data to the blockchain-based security anchor in the blockchain and for considering the monitoring sensor data for product authentication.
[0061] For example, the transponder's monitoring sensors track the transport and storage conditions of the identification module, sending relevant changes to the blockchain and storing them as events. A trust engine of the verification system (see below) integrated with the transponder then compares the PUF code, blockchain-based security anchors, and sensor data to perform a trust assessment of the issued product information, resulting in a result such as "genuine," "risk of tampering," or "counterfeit."
[0062] For example, the transponder is configured to provide data from the monitoring sensors and to offer blockchain-based storage and evaluation of this data. The monitoring sensors include, for example, sensors such as a thermal sensor, a motion sensor, or an accelerometer, which collect data continuously or upon specific trigger events. If thresholds are exceeded (e.g., If a temperature exceeds a certain threshold and / or a shock load is detected, a blockchain event is automatically triggered and linked to the blockchain-based security anchor. These events are stored in an audit trail, which is evaluated (for example, by a AI-based) trust engine. This engine calculates a "trust level" for the product from the values (e.g., 98% "genuine", 72% "risk").
[0063] In general, the identification module can therefore be configured, within the framework of the transponder's communication via the internet for the authentication functionality, to further provide a comparison as to whether a product history currently issued by the transponder (e.g. sensor data, transport events) shows deviations from a product history linked to the blockchain-based security anchor based on the monitoring sensor data.
[0064] The invention further relates to a system for the digital authentication of a physical product. The system comprises a marking module according to one of the embodiments described above, as well as control logic. The control logic is configured to manage synchronization with the blockchain, such that the PUF code is assigned to the blockchain-based security anchor in the blockchain and the blockchain-based security anchor is linked to the unique product information.
[0065] For example, the control logic is configured to manage the signing of the PUF code and / or product information with a quantum-safe signature, e.g., using XMSS or SPHINCS+. When using XMSS, for instance, a secure, rollback-protected OTS index is maintained, with key rotation occurring when a threshold is reached.
[0066] The system can secure on-chain data objects and PUF codes, for example, in various blockchain ecosystems. For example, blockchain systems such as Ethereum, Polygon, Solana (SPL token), Avalanche, and Hedera Hashgraph (HBAR) are being considered.
[0067] In particular, the system is configured to control the authentication functionality described above and the verification of product information, especially to perform the check to see if the PUF code assigned to the blockchain-based security anchor on the basis of the assignment matches a code readout currently provided by the transponder, which is intended to reproduce the PUF code.
[0068] In one embodiment, the system therefore has a control logic that is configured to control the communication of the transponder over the Internet for authentication functionality and product authentication.
[0069] One specific implementation of the system includes, for example, a miniaturized FPGA chip (identification module, see above) that generates a unique cryptographic hash value upon product activation. This hash value is assigned to a non-fungible token (NFT), and the NFT is stored in a decentralized blockchain structure. The authenticity of the physical product can then be verified via browser-based verification without the need for an app. Verification is triggered, for example, by a QR code or NFC tag that links to a web-based verification platform.
[0070] For example, the control unit is configured to grant the release described at the beginning for reading the product information via the readout interface based on the authentication of the product.
[0071] In the event that the identification module has monitoring sensors (see above), the control logic can further be configured to assign the monitoring sensor data to the blockchain-based security anchor in the blockchain and to consider it for the To control the authentication of the product within the framework of the authentication functionality.
[0072] In another embodiment, the system includes an auxiliary module separate from the marking module, e.g., physically separate, configured for attachment to a storage component for storing the product. For example, the auxiliary module is configured and specifically designed to be attached to the product's packaging.
[0073] The auxiliary module is configured to provide communication with the blockchain via the internet. It also includes auxiliary sensors configured to detect any changes to the storage component and / or any mechanical impact on the storage component. For example, the auxiliary sensors are configured to detect at least one tampering attempt, one instance of the storage component being opened, and one instance of the storage component being moved. For example, the auxiliary module includes a break-sensitive conductor configured to detect the removal of the auxiliary module or the opening of the packaging.The control logic is configured to automatically assign auxiliary module information to the blockchain-based security anchor in the blockchain based on data from the auxiliary sensors, and to consider the auxiliary module information for product authentication within the authentication functionality.
[0074] In general, this embodiment thus relates to the combination of a PUF-enabled marking module integrated into the physical object with a separately installed auxiliary module, e.g., based on an FPGA (i.e., the auxiliary module has an FPGA), which processes sensor data and communicates with a blockchain structure (e.g., quantum-securely signed). For example, the system can be used in all areas where the authenticity of the product packaging is relevant or where changes in the packaging's condition are indicative of product tampering. These can be the cases. For example, the system is used to protect luxury goods such as precious stones, gold bars or watches, jewelry, medical technology, logistics, or supply chain monitoring from counterfeiting.
[0075] A tamper label with a break-sensitive conductor track or light sensor can trigger a hardware interrupt when the product is opened. This interrupt can be transmitted as an event to the blockchain, clearly documenting the attempted tampering. The system then marks the product as potentially compromised, allowing subsequent audits to address the issue.
[0076] For example, the system combines an object-integrated nano-NFC / PUF chip (identification module) with an FPGA-based packaging module (auxiliary module) equipped with sensors and optional AI logic. During initialization, a physically uncopyable hash value (PUF code) is generated, which is linked to an NFT on a blockchain. The NFT serves as digital proof of ownership and documents additional information such as serial number, event logs, and timestamps. Tampering attempts, openings, or changes in the packaging's location are detected by sensors and recorded as events on the blockchain. Verification can be performed, for example, without an app, using a mobile device via NFC or QR code. Offline verification could also be enabled through challenge-response with rolling codes, the results of which are later synchronized. Zero-knowledge proofs allow for the verification of events or changes of ownership without disclosing sensitive data.
[0077] The system thus enables, through a modular system, the provision of digital authentication, ownership documentation, and blockchain-based event logging of a physical object. For example, the system, comprising the identification module integrated into the physical object (e.g., also referred to as a PUF-On-Chain data object chip) and the separately installed auxiliary module, is configured such that the identification module and the auxiliary module communicate using a quantum-securely signed blockchain structure.
[0078] In another embodiment, the control logic is configured to control the provision of verification information via a web browser as part of the authentication functionality, based on the product information linked to the blockchain-based security anchor (and, for example, based on the authentication of the product). For example, the system features a browser-based verification platform configured to display the verification information.
[0079] In another embodiment, the system is configured to provide the verification information via the web browser by scanning an NFC tag of the identification module or by scanning a 2D code associated with the identification module, e.g. a barcode or QR code.
[0080] The provision of verification information via the web browser can therefore be done without an app on a mobile device, e.g., a smartphone or tablet.
[0081] The verification logic can optionally be processed in a hardware-based secure execution environment, e.g., through: - ARM TrustZone - Intel SGX (Software Guard Extensions). The goal is the secure execution of sensitive AI decisions, hash / NFT coupling, and signature processing in an isolated hardware environment.
[0082] In another embodiment, the system is configured to provide offline authentication functionality, whereby a challenge code is sent to the transponder, which in response generates a signed reply that is then verified against the blockchain when a network connection is available. For example, product authentication is secured via a rolling code or monotonic counter.
[0083] The results of challenge-response and rolling codes can be synchronized later. Furthermore, zero-knowledge methods, for example, allow for... Proofs provide evidence of events or changes of ownership without disclosing sensitive data.
[0084] The system may also feature the use of artificial intelligence for pattern analysis and verification decision-making, e.g., a machine learning method for identifying discrepancies in the authenticity of blockchain-stored PUF codes, product information, and NFT transaction paths.
[0085] For example, the system features several AI modules for real-time analysis of authenticity data: 1) PUF code pattern clustering, where unusual deviations in PUF codes (e.g., hash values) are detected via k-means clustering or cosine similarity; 2) Geo-based duplicate identification, where AI is used to analyze whether an identical code (e.g., NFT hash) is scanned multiple times from different regions; 3) Trust assessment via event logs, where AI performs a blockchain-based evaluation of events (e.g., temperature exceedances, irregularities in the transport process) and generates a numerical risk score; 4) Decision logic, where a trained decision tree or a simple neural network provides a final classification such as "Authentic," "Suspected forgery," or "Risk of manipulation."
[0086] In another embodiment, the system is generally configured such that the authentication of the product, as part of the authentication functionality, includes an artificial intelligence-based check for the authenticity of the PUF code assigned to the blockchain-based security anchor, the product information, and transaction paths associated with the blockchain-based security anchor.
[0087] For example, the system is configured to classify product information into different confidence classes using decision logic based on a trained decision tree or a neural network.
[0088] In another embodiment, the system is configured for the detection of deviations in PUF codes via k-means clustering or cosine similarity.
[0089] In another embodiment, the system is configured to detect, via duplicate identification, whether an identical PUF code is scanned multiple times from different geographical regions.
[0090] In another embodiment of the system, where monitoring sensors are provided for the transponder and / or auxiliary sensors for the auxiliary module, the system is configured to use artificial intelligence to classify events into different classes based on sensor data stored on the blockchain and data acquired by sensors of the identification module and / or the auxiliary module. Based on this classification, the system then provides a risk assessment. For example, the event classes are based on events such as temperature exceedances or location changes.
[0091] The blockchain-based security anchor, e.g., NFT, acts as digital proof of ownership. Ownership transfer occurs through the transfer of the NFT token to a new wallet address. Optionally, physical delivery confirmation (e.g., via QR / NFC scan by the new owner) can be logged as an on-chain event. The system thus supports the transfer of ownership of the physical product through the transfer of an associated NFT (or, more generally, a blockchain-based security anchor). The transfer can be further secured through on-chain events, biometric verification, or timestamping mechanisms.
[0092] Zero-knowledge proofs allow users to prove, for example, that they legally own a product or are located in a legitimate location, without disclosing sensitive data. Examples of methods that can be used include zk-SNARKs and bulletproofs. The system can therefore optionally perform verifications without revealing sensitive user data such as location, identity, or transaction details.
[0093] The inventive marking module and system are described in more detail below with reference to exemplary embodiments schematically depicted in the figures. Identical elements are marked with the same reference numerals in the figures. Specifically, the figures show...
[0094] Fig. 1: a schematic representation of an initialization of an embodiment of the inventive identification module;
[0095] Fig. 2: a schematic representation of a product information retrieval process for product authentication;
[0096] Fig. 3: a schematic representation of an inventive marking module and its components according to a further embodiment;
[0097] Fig. 4: a schematic representation of the functionality of a product authentication using a web application according to the present invention;
[0098] Fig. 5: another exemplary embodiment of an embodiment of the inventive system;
[0099] Fig. 6: schematically a complete architecture of an authenticity verification according to an embodiment of the inventive system;
[0100] Fig. 7: a schematic representation of the functioning of the inventive system according to a further embodiment.
[0101] Figure 1 shows a schematic representation of an initialization of an embodiment of the inventive identification module 1 and its transponder 2. For example, the transponder 2 is designed as an FPGA-based transponder.
[0102] Upon activation 3, the transponder 2 generates a unique, physically non-repeatable PUF code 4, for example, a hash value. This PUF code 4 serves as the starting point for generating an on-chain data object, for example, a non-fungible token (NFT), which is stored on a decentralized blockchain 5 (or multiple blockchains). For this purpose, the transponder 2 establishes communication 6 with the blockchain 5 via the internet using a blockchain communication interface. The combination of the FPGA-generated PUF code 4 with a digital NFT on a blockchain 5 forms the basis for a fully decentralized, tamper-proof authentication system.
[0103] The synchronization of transponder 2 (e.g., the transponder's hash value 4) with blockchain 5 is achieved through a combination of the transponder's internal communication logic and an external NFT minting API. Once the PUF hash 4 has been generated, it is transmitted to the minting system via the blockchain communication interface. Additionally, structured product information (e.g., batch number, production date, manufacturer ID) is integrated into the payload format. The NFT is then generated using this combined data, either entirely on-chain (e.g., with ICP) or off-chain (e.g., metadata via IPFS). The synchronization process thus includes, for example: generation of the PUF hash 4, XMSS signature of the PUF hash 4, data transmission, blockchain minting, and the final linking step of the PUF hash 4 with the NFT.
[0104] Furthermore, the system can also include multimodal sensors that capture physical, biometric, and emotional parameters, with biometric and emotional data stored off-chain and referenced on-chain as a cryptographic commitment or zero-knowledge proof. For example, so-called biodata (also called biometric verifiers) captures at least one of the following: heart rate, skin conductance, pupil diameter, facial expression, voice, and body temperature. The biometric verifiers enable personalized access to blockchain verification or digital verification. Proof of ownership. For example, biometric verification is useful to secure medical products, digital certificates, etc.
[0105] Blockchain storage can occur on one or more blockchains. In other words, the system can provide cross-chain blockchain storage and, for example, support both ICP and at least one other public blockchain. Cross-chain proof-of-concept is achieved, for example, through Merkle commitments and light client verification.
[0106] An on-chip AI can analyze sensor data locally and detect anomalies, while a backend AI (trust engine) generates risk scores and pattern recognition. Optionally, an MCSS blockchain is used, which can operate as a permissioned or permissionless distributed ledger, with quantum-safe node identities and advanced privacy features.
[0107] The identification module, for example, designed as an NFC / PUF chip as just described, can be physically attached to or integrated into the product in a variety of ways. Depending on the application, this includes: direct embedding in a setting (e.g., ring band, holder), integration into metallic structures such as chain links, clasps, or spacers, or embedding in a transparent sealing module within a packaging unit. For gemstones—especially diamonds—the chip can also be applied to the back of the stone's surface as a flat, transparent polymer chip (e.g., with a thickness of 0.6 mm–0.9 mm, and in the future down to less than 0.1 mm), provided there is no optical impairment. This option is particularly suitable for larger diamonds that are set freely in settings. The attachment can be reversible (e.g., for loan systems) or permanent, depending on the chosen application.All integration types allow contactless activation and querying of the chip logic via NFC or PDF and ensure that the system's authenticity logic is maintained even with changing product versions.
[0108] The transponder 2 can also be designed as a printable, flexible, or transparent chip structure, for example, based on polymer printing technologies where the logic unit is applied directly to the substrate. This can be advantageous for applications with high production volumes or low unit costs. For example, printed NFC / PUF labels can be used on flexible substrates. These labels contain, for example, a break-conducting conductor track, the interruption of which triggers a signed tamper event.
[0109] Figure 2 shows a schematic representation of a product information retrieval process 8 for product authentication. The authenticity of a product is verified by a request 7 directed to the transponder 2, which is performed, for example, via a browser and without an app.
[0110] The query is performed, for example, via a web-based scanning process using NFC on the identification module or a QR code associated with the identification module (e.g., attached to or provided by the identification module). After the scan, a URL automatically opens, which is linked to the NFT entry on blockchain 5. The web application then retrieves the associated metadata of the NFT – including the PUF code 4, timestamp, sensor events, and signature. This data is validated and then presented to the user in plain text. Possible status indicators include: "genuine," "risk," or "forgery," based on a real-time comparison of the PUF and sensor data and their cryptographic verification.
[0111] Figure 3 shows a schematic representation of an inventive marking module 1 and its components according to a further embodiment of the invention.
[0112] The identification module includes a transponder 2 configured to generate a so-called PUF code 4 (Fig. 1) based on a so-called PUF functionality 9 using a physically non-copyable function (PUF). Furthermore, the transponder 2 includes a blockchain Communication interface 10 and a readout interface 11 are provided. The PUF code 4 is stored on a memory 12 of the identification module 1, for example configured as a flash memory connected to an FPGA of the transponder 2.
[0113] The identification module 1 is configured, for example, so that all communication between transponder 2, a server of the verification platform (e.g., an API gateway that aggregates blockchain and sensor data), and blockchain 5 takes place using quantum-safe signatures, e.g., XMSS signatures (RFC 8391). The same applies, for example, to the communication between auxiliary module 14 (see Fig. 4), the server of the verification platform, and blockchain 5. An interaction occurs, for example, in the following sequence: 1.) Transponder 2 generates hash and sensor data; 2.) These are sent to a blockchain backend via standardized protocols (e.g., SPI, I2C, BLE); 3.) The server compares the data with the blockchain 5, verifies the signature, and forwards the validated product information to a frontend; 4.) Optionally, a trusted computing module (e.g., SGX or TrustZone) can encapsulate the logic.
[0114] Figure 4 shows a schematic representation of the functioning of a product authentication using a web application 13 according to an embodiment of the inventive system with a marking module 1 and an additional auxiliary module 14 attached to the packaging.
[0115] Both the identification module 1 and the auxiliary module 14 are configured to provide communication with a blockchain network 5 and a verification server 15 via the internet. The web application 13 can be accessed, for example, via a mobile device 16, such as a smartphone or tablet.
[0116] The system also includes, for example, event logging and a tamper label (not shown). If the tamper label is damaged, an alarm is triggered. An event is triggered, which is automatically linked to the NFC in the blockchain. The NFT thus represents a digital proof of authenticity.
[0117] Web application 13 performs three core functions: First, it initiates the retrieval of NFT data via the unique product ID (based on the PUF code). Second, it validates the received PUF code and the signature using publicly available verification keys (XMSS). Third, it presents the verification result as well as further product information (e.g., production location, transport history, trust score) to the end user. For example, the platform interacts with the blockchain via REST or GraphQL API, uses client-side rendering, and enables barrier-free authentication without an additional app.
[0118] The identification module 1, e.g., a miniaturized NFC / PUF chip integrated directly into the physical object, generates a unique PUF code upon activation. The auxiliary module 14, integrated into the packaging and e.g., based on an FPGA, features sensors and optional AI functionality, and processes other security-relevant events. An NFT is created via a blockchain interface, serving as proof of ownership and a certificate of authenticity. Verification is possible via a browser using NFC or QR code, e.g., also offline via a challenge-response protocol. Zero-knowledge proofs ensure data privacy for proof of ownership and location.
[0119] In a specific example, a gemstone is equipped with the NFC / PUF chip 1. Upon the first scan of chip 1, the PUF generates a hash. An FPGA-based auxiliary module 14 attached to the gemstone's packaging registers environmental influences. An NFT containing the owner's address is created. Upon resale, the NFT is transferred.
[0120] The NFT represents ownership. A transfer is documented on-chain. Optionally, a "dispute mode" can be triggered if a physical transfer is not completed.
[0121] For offline verification, the mobile device sends a challenge code (16), which is answered by the PDF. The answer code is stored locally and synchronized the next time a network connection is available.
[0122] Zero-knowledge proofs include, for example, zk-SNARKs or bulletproofs. The user can prove that they are in the correct location or are the rightful owner without revealing any details.
[0123] Figure 5 shows another exemplary embodiment of an embodiment of an inventive system 17 for authenticating a product 18. The system includes an FPGA-based transponder 2 which generates a hash 4 as a PUF code, an NFT 19 associated with the hash 4, a blockchain 5 (decentralized storage structure, blockchain node or IPFS) and a verification platform 15.
[0124] For product authentication, the FPGA-based transponder 2 reads the stored PUF code 4 from flash memory. Via an integrated Ethernet interface, the FPGA-based transponder 2 establishes a connection to an NFT website or a verification server 15 to synchronize or verify the PUF code 4. An external reader can query product information from the transponder 2 via a general interface (e.g., SPI or I2C).
[0125] Authentication can be performed during every communication to prevent manipulation. For example, a post-quantum security layer (XMSS = extended Merkle Signature Scheme) is used, which secures signatures at the hash and blockchain levels. XMSS can be combined with existing blockchain standards (e.g., Ethereum, Polygon), for example, by chaining the XMSS signature with the NFT transaction protocol.
[0126] A tamper-proof authentication system is provided through the unique combination of a programmable miniature FPGA chip, cryptographic hash generation, NFT technology, blockchain storage and a post-quantum resistant security architecture (XMSS).
[0127] Most state-of-the-art blockchain NFT solutions require apps or wallets. The system described in the invention operates "frictionlessly" for the mass market.
[0128] Figure 6 schematically shows the complete architecture for verifying the authenticity of a product 18 according to a further embodiment of the inventive system. The system is initiated by a request 20 to the identification module attached to the product 18 (e.g., a PU F- / N FC transponder with FPGA), where the request is triggered by an NFC query to the identification module or by scanning a QR code with a mobile device (whereupon the verification server contacts the identification module). In response to the request 20, an initial hash 21 is generated, which, controlled by an FPGA 22 of the identification module, is provided with a cryptographic signature 23, e.g., XMSS, and transmitted via a blockchain minting interface (e.g., NFT API) 24 to a blockchain backend 25 (e.g., ICP, Polygon).The PUF code can then be verified using a browser-based user verification 26, with a real-time comparison also taking place with the digital signature.
[0129] Figure 7 shows a schematic representation of the functioning of the inventive system according to a further embodiment. A physical object is provided with an inventive identification module with an integrated PUF / NFC chip. Authenticity verification is triggered by an initial activation of the identification module, which generates a (noisy) PUF signal. 27 is generated. The PUF signal 27 is then fed to a fuzzy extractor with error correction function integrated on the identification module. 28 is fed in, and in a next step 29 a (stable) hash including a helper string is generated. The hash including the helper string is then provided with a quantum-safe cryptographic signature 30 (e.g., XMSS, SPHINCS+). The transponder of the identification module provides the hash and the helper string as well as other data (e.g., product ID, timestamp) via a structured data transfer 31, e.g., using a byte matrix or JSON. ready. This structured data is then fed, e.g., as a structured payload, into a blockchain architecture 32 to create a blockchain-based security anchor (e.g., via API / gateway / canister). The preparation or provision of the structured data can also take into account further security-relevant data 33, e.g., data from an auxiliary module attached to the packaging for tamper monitoring or a challenge-response functionality for offline verification. The verification 34 of the product 18 by a user can then be carried out without an app via a corresponding web application.
[0130] The fuzzy extractor, including error correction, is implemented directly on the transponder itself, typically in an FPGA or as a dedicated circuit. The stabilized PUF code (i.e., the consistent hash result) is not stored locally but serves as a reference value for creating a blockchain-based verification object (e.g., an NFT or hash entry).
[0131] Depending on the system design, the optionally generated helper string can also be stored on the blockchain, in the backend, or on the transponder, but it is not strictly necessary for operation, especially if the fuzzy extractor operates deterministically. Deterministic means that the system always generates the same hash for the same PUF signal and helper string.
[0132] It is understood that these figures only schematically represent possible embodiments. The various approaches can also be combined with each other and with prior art methods. REFERENCE MARK LIST: 1 Labeling module 2 transponders 3 Activation of the transponder 4 PUF code 5 Blockchain 6. Communication via Blockchain Communication Interface 7 Request to transponder for reading of Product information 8 Product Information 9 PUF functionality of the transponder 10 Blockchain communication interface 11. Transponder readout interface 12 Memory locations of the identification module 13 Web application 14 Auxiliary module, e.g. for attaching to packaging 15 verification servers 16 User device, e.g. smartphone or tablet 17 System 18 physical product 19 NFT 20 Request to the identification module for product authenticity verification, e.g. triggered by NFC query to the identification module or by Scanning a QR code, whereupon the verification server contacts the labeling module. 21 initial hash 22 FPGA of the identification module 23 cryptographic signature layer, e.g. XMSS- Signature layer 24 Blockchain Minting Interface, e.g. NFT API 25 Blockchain Backend 26 browser-based product verification by users 27 (noisy) PUF signal Fuzzy extractor with error correction; generation of a (stable) hash including helper string; provision of a quantum-safe cryptographic signature to the hash including helper string; structured data transfer; blockchain architecture; further security-relevant data, e.g., from tamper monitoring or data for offline verification; product verification
Claims
Patent claims 1. Identification module, configured for attachment to a physical product to provide digital authentication of the product, characterized in that the identification module has a transponder with a blockchain communication interface configured to provide communication with a blockchain via the Internet, wherein the transponder is further configured • to generate a PUF code based on a physically uncopyable function (PUF), and • to provide synchronization with the blockchain via the blockchain communication interface, for which the transponder provides the PUF code with a data structure adapted for verification and / or creation of a blockchain-based security anchor in the blockchain, which has a reference ID and a timestamp, so that an assignment of the PUF code to a uniquely assigned blockchain-based security anchor in the blockchain takes place, which is linked to unique product information.
2. Identification module according to claim 1, wherein the transponder is configured to provide the PUF code based on a light pulse, a heat, or a voltage activation.
3. Identification module according to one of the preceding claims, wherein the transponder is configured to generate a reproducible fault-tolerant extraction of the PUF code from a noisy signal.
4. Identification module according to claim 3, wherein the transponder is configured to generate auxiliary data for the reproducible fault-tolerant extraction of the PUF code, wherein the auxiliary data enables the reconstruction of the PUF codes can be extracted from a noisy signal without revealing the PUF code itself.
5. Identification module according to claim 4, wherein the auxiliary data are contained in the data structure adapted for the creation of the blockchain-based security anchor or are stored on the transponder.
6. Identification module according to one of claims 3 to 5, wherein the transponder comprises a fuzzy extractor, FE, with error correction functionality, ECC, in particular a deterministically operating FE, wherein the FE and the ECC are configured to generate the reproducible fault-tolerant extraction of the PUF code from the noisy signal.
7. Labeling module according to any of the preceding claims, wherein the labeling module is configured to provide a signing of the PUF code with a quantum-safe signature, in particular with XMSS or SPHINCS+.
8. Identification module according to one of the preceding claims, wherein the transponder is configured to control communication via the blockchain communication interface via an internal state machine, in particular wherein the finite state machine is implemented in VHDL or Verilog.
9. Identification module according to one of the preceding claims, comprising a non-volatile memory which is connected on an FPGA of the transponder or externally from an FPGA of the transponder and configured to store the PUF code.
10. Identification module according to one of the preceding claims, wherein the transponder is configured such that the data structure adapted to the creation of the blockchain-based security anchor in the blockchain is provided in such a way that the uniquely assigned blockchain-based security anchor is generated in the blockchain according to the ERC-721 or ERC-1155 standard and is provided with a timestamp, batch number and product ID.
11. Identification module according to one of the preceding claims, wherein the transponder comprises a miniaturized FPGA, in particular wherein the miniaturized FPGA has a size of at most 2 mm x 2 mm side lengths.
12. Identification module according to one of the preceding claims, wherein the transponder is configured to provide, as a response within the framework of an authentication functionality taking place via communication of the transponder over the Internet, a current reading of the PUF code with the data structure adapted to the verification of the blockchain-based security anchor, so that, based on a check whether the assignment of the PUF code to the blockchain-based security anchor in the blockchain matches the current reading of the PUF code, authentication of the product is provided.
13. Identification module according to claim 12, wherein the transponder is configured to provide the current readout of the PUF code taking into account auxiliary data associated with the blockchain-based security anchor, which is provided to the transponder during communication of the transponder over the Internet for authentication functionality, wherein the auxiliary data associated with the blockchain-based security anchor provides a reproducible fault-tolerant extraction of the PUF code from a noisy signal without revealing the PUF code itself.
14. Identification module according to claim 12 or 13, wherein the identification module is configured such that the communication of the transponder via the Internet for the authentication functionality and the associated current reading of the PUF code is initiated by scanning an NFC tag of the identification module and / or by an external request arriving via the blockchain communication interface.
15. Identification module according to one of claims 12 to 14, wherein the transponder has a readout interface and is configured to automatically provide authentication of the product within the scope of the authentication functionality, in particular in real time, wherein reading the product information via the readout interface requires release based on the authentication of the product.
16. Identification module according to claim 15, wherein the transponder is configured to provide a signing of the product information with a quantum-safe signature, in particular with XMSS or SPHINCS+.
17. Identification module according to one of claims 12 to 16, wherein the identification module is configured to provide, within the context of the communication of the transponder via the Internet for the authentication functionality, a check as to whether a quantum-safe signature of the PUF code is valid.
18. Identification module according to any one of claims 12 to 17, wherein the transponder comprises monitoring sensors configured to detect a physical change in the transponder and / or a mechanical action on the transponder, in particular configured to detect at least one of the following: voltage differences, temperature differences, voltage variations, humidity differences, pressure differences, light variations, chemical markers and vibrations, wherein the transponder is configured to automatically provide monitoring sensor data via the blockchain communication interface for the purpose of assigning the data to the blockchain-based security anchor in the blockchain and for taking the monitoring sensor data into account for product authentication.
19. Identification module according to claim 18, wherein the identification module is configured, within the framework of the communication of the transponder via the Internet for the authentication functionality, to further provide a comparison as to whether a product history currently issued by the transponder shows deviations from a product history linked to the blockchain-based security anchor based on the data of the monitoring sensors.
20. System for digital authentication of a physical product, wherein the system comprises a marking module according to any one of claims 1 to 19 and a control logic configured to control synchronization with the blockchain, such that the assignment of the PUF code to the blockchain-based security anchor in the blockchain takes place and the blockchain-based security anchor is linked to the unique product information.
21. System according to claim 20, wherein the control logic is configured to control the signing of the PUF code and / or the product information with a quantum-safe signature, in particular with XMSS or SPHINCS+.
22. System according to one of claims 20 to 21, wherein the identification module is configured according to one of claims 12 to 19, and the control logic is configured to control the communication of the transponder via the Internet for the authentication functionality and the authentication of the product, in particular where the control unit is configured to grant permission to read the product information via the readout interface based on product authentication.
23. System according to claim 22, wherein the identification module is configured according to one of claims 18 to 19, and the control logic is configured to control the assignment of the monitoring sensor data to the blockchain-based security anchor in the blockchain and its consideration for the authentication of the product within the framework of the authentication functionality.
24. System according to one of claims 22 to 23, wherein the system comprises an auxiliary module separate from the identification module, in particular physically separate, configured for attachment to a storage component for storing the product, in particular for attachment to packaging of the product, wherein the auxiliary module is configured to provide communication with the blockchain via the Internet and • the auxiliary module has auxiliary sensors configured to detect a change in the storage component and / or a mechanical impact on the storage component, in particular configured to detect at least one tampering attempt, an opening of the storage component, and a change in the location of the storage component, • the control logic is configured to automatically assign auxiliary module information to the blockchain-based security anchor in the blockchain based on data from the auxiliary sensors, and • the control logic is configured to control the consideration of the auxiliary module information for the authentication of the product within the framework of the authentication functionality.
25. System according to one of claims 22 to 24, wherein the control logic is configured to control, within the framework of the authentication functionality, the provision of verification information based on the product information linked to the blockchain-based security anchor, and in particular based on the authentication of the product, via a web browser, in particular wherein the system has a browser-based verification platform configured for displaying the verification information.
26. System according to claim 25, wherein the system is configured such that the provision of the verification information via the web browser is provided by scanning an NFC tag of the identification module or by scanning a 2D code associated with the identification module, in particular a barcode or QR code.
27. System according to one of claims 25 to 26, wherein the system is configured so that the provision of the verification information via the web browser is app-free via a mobile device, in particular a smartphone or tablet.
28. System according to any one of claims 22 to 27, wherein the system is configured to provide an offline functionality of the authentication functionality, wherein a challenge code is sent to the transponder which in response generates a signed response which is compared with the blockchain when a network connection is available, in particular wherein the authentication of the product is secured via a rolling code or monotonic counter.
29. System according to any one of claims 22 to 28, wherein the system is configured such that the authentication of the product within the framework of the authentication functionality is performed by means of artificial intelligence to verify the authenticity of the PUF code assigned to the blockchain-based security anchor, the product information and of the Blockchain-based security anchors associated transaction paths, in particular where product information is classified into different trust classes using a decision logic based on a trained decision tree or a neural network.
30. System according to claim 29, wherein the system is configured for detecting deviations in PUF codes via k-means clustering or cosine similarity.
31. System according to one of claims 29 to 30, wherein the system is configured for detection by means of duplicate identification whether an identical PUF code is scanned multiple times from different geographical regions.
32. System according to one of claims 29 to 31 and claim 23 and / or 24, wherein the system is configured to classify events into different classes based on sensor data stored on the blockchain and data acquired by sensors of the identification module and / or the auxiliary module using artificial intelligence, in particular wherein the event classes are based on events such as temperature exceedances or location trends, and to provide a risk assessment based on the classification.