Systems and methods to determine identity, provenance, and / or authenticity of physical objects
The system uses a reader and computing system to verify the authenticity and provenance of physical objects through unclonable identifier data, addressing the inadequacies of existing methods by ensuring secure and reliable verification.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- POLYMARK SYSTEMS INC
- Filing Date
- 2025-11-03
- Publication Date
- 2026-05-15
AI Technical Summary
Existing methods for verifying the authenticity and provenance of physical objects are inadequate, as they are easily falsifiable and lack reliable mechanisms for verification.
A system comprising a reader and a computing system that utilizes unclonable identifier (UID) data from a physically unclonable function (PUF) to determine the unique identifier, authenticity, and provenance of physical objects, using optical spectra measurements and image data, with secure authentication and verification processes.
Provides reliable and secure verification of object authenticity and provenance, reducing dependence on third-party guarantees and enhancing supply chain integrity.
Smart Images

Figure US2025053747_15052026_PF_FP_ABST
Abstract
Description
SYSTEMS AND METHODS TO DETERMINE IDENTITY, PROVENANCE, AND / OR AUTHENTICITY OF PHYSICAL OBJECTSCROSS-REFERENCE TO RELATED APPLICATION
[0001] This application claims the benefit of priority to U.S. provisional patent app. No. 63 / 716,468, filed November 5, 2024, which is incorporated herein by reference in its entirety.FIELD
[0002] This description relates to systems and methods to determine identity, provenance and / or authenticity of physical objects.BACKGROUND
[0003] In many industries, counterfeiting of products is a substantial problem that significantly impacts not only the revenues of original product manufacturers, but may even pose a serious threat to health and even life of consumers or operators of counterfeited, i.e., fake, products. Such safety relevant product categories include, for example, parts for automobiles and aircraft, components for the construction of buildings or other infrastructure, food, and even medical devices and pharmaceuticals. A number of different protection measures have been developed in efforts to reduce counterfeiting and address safety concerns. Broadly used protection measures tend to include adding a so-called security feature to a product, the feature being rather difficult to fake. Some existing measures include the use of holograms, security labels, and / or RFID tags. Most existing protection measures, however, are inadequate as they tend to either be easy to fake or alter. Additionally, these and other measures fail to include reliable mechanisms to verify the authenticity and / or provenance of the item regardless of the protection measures.SUMMARY
[0004] This description relates to systems and methods to determine identity, provenance and / or authenticity of physical objects.
[0005] One example relates to a system that includes a reader and a computing system. The reader provides unclonable identifier (UID) data that includes spectra data representative of at least one optical spectrum measured from a portion of a physical object that includes a physically unclonable function (PUF). The computing system includes non- transitory memory and one or more processors coupled to the memory. The memory stores instructions and data, in which the instructions, when executed by the one or more processors, cause the one or more processors to receive the UID data. The instructions further cause the one or more processors to execute a compare function to determine a unique identifier, authenticity, and / or provenance of the physical object based on the received UID data and predetermined UID data in a data store. The one or more processors further can provide results data indicative of the unique identifier, authenticity,and / or provenance of the physical object. The results data can be sent to the reader, in which the reader is configured to provide a user-perceptible output specifying the unique identifier, authenticity, and / or provenance of the physical object based on the results data.
[0006] Another example provides a method. The method includes receiving, by one or more processors at a computing system, unclonable identifier (UID) data, in which the UID data includes spectra data representative of at least one optical spectrum measured by a reader from a portion of a physical object that includes a physically unclonable function (PUF). The method can also include determining, by the one or more processors, a unique identifier, authenticity, and / or provenance of the physical object based on a comparison of the received UID data and predetermined UID data stored in a data store. The method can also include generating results data indicative of the unique identifier, authenticity and / or provenance of the physical object. The method can also include sending the results data to the reader. The reader is configured to provide a user-perceptible output specifying the unique identifier, authenticity, and / or provenance of the physical object based on the results data.
[0007] Another example relates to one or more non-transitory computer readable medium having instructions that, when executed by one or more processors, cause the one or more processor to perform the foregoing method.BRIEF DESCRIPTION OF TIIE DRAWINGS
[0008] The foregoing and other features of the invention will become more apparent upon a consideration of the following description taken in connection with the accompanying drawings wherein:
[0009] FIG. 1 is a block diagram of an example system for determining a unique identity, authenticity and / or provenance of an object.
[0010] FIG. 2 is a block diagram of an example reader configured to obtain measurements and provide UID data.
[0011] FIG. 3 is diagram showing an example data structure for UID data.
[0012] FIG. 4 is a block diagram showing an example compare function that can be executed by a processor for determining a unique identity, authenticity and / or provenance of an object.
[0013] FIG. 5 depicts an example of a data collection phase that can be implemented by a reader.
[0014] FIGS. 6 depicts an example of a spectra measurement, showing the amplitude of measured light as a function of wavelength, which can be acquired by a reader.
[0015] FIG. 7 depicts an example of an image that can be acquired by a reader.
[0016] FIG. 8 depicts an example of a data preparation phase that can be implemented by a computing system.
[0017] FIG. 9 depicts an example of a captured spectra measurement that has been divided into a number of spectra features.
[0018] FIG. 10 depicts an example image of a portion of a physical object divided into a grid of image cells.
[0019] FIG. 11 is a table showing an example of image feature values for the example image of FIG. 10.
[0020] FIG. 12 depicts an example of a match processing and results determination phase.
[0021] FIG. 13 is a table showing example features determined for an example spectra measurement, such as for predetermined spectra measurements made for a plurality of UIDs that can be stored in predetermined UID data.
[0022] FIG. 14 depicts an example of a plurality of feature values, such as can be determined based on computing a match function between stored feature values and feature values determined from one or more spectra measurements.
[0023] FIG. 15 depicts an example of spectra measurement execution.
[0024] FIG. 16 depicts another example of spectra measurement execution.
[0025] FIG. 17 depicts an example external verification system.
[0026] FIG. 18 depicts an example of a high-level system architecture.
[0027] FIG. 19 depicts an example use case for a handbag manufacturer that can be implemented in the system.
[0028] FIG. 20 depicts an example use case for a parts manufacturer that can be implemented in the system.
[0029] FIG. 21 depicts an example use case that can be implemented for a military government in the system.DETAILED DESCRIPTIONSystem Overview
[0030] This description relates to systems and methods to determine identity, provenance, and / or authenticity of physical objects. For example, an entity (e.g., a producer, supplier, and / or owner) may wish to provide guarantees of an authentic item (e.g., any physical object, e.g., a collection of matter having a defined boundary, including natural and man-made objects) that was produced, manufactured, sold, packaged, and / or shipped by the entity or otherwise on its behalf. Also, or alternatively, a receiving entity (recipient) that may wish to verify the identity, authenticity and provenance of that “item” without necessarily having to rely on third parties providing those guarantees based on a sale or distribution from that third party to the recipient. In some examples,this description provides systems and methods that help to improve supply chain resilience and integrity by reducing the dependence on trusting a supply chain at all by providing a mechanism for any entity inside or outside the supply chain to verify the authenticity, provenance and / or identity of an item.
[0031] Authenticity and provenance verification provides an entity with an increased sense of trust in the “item” but does not necessarily require that the unique identity of the item also be verified. The systems and methods described herein not only can authenticate items but also can also uniquely identify a particular unique item apart from other authentic and unauthentic items in a manner that ensures entities can use the information gathered from the items supporting supply chain and asset tracking applications. Additionally, the systems and methods herein provide systems and methods support for determining for authentic items, their provenance, if that is required and supported by the entities using the system.
[0032] FIG. 1 is a block diagram of an example system 100 for determining a unique identity, authenticity and / or provenance of an object. The system 100 includes a reader 102 and a computing system 104. The reader 102 is configured to measure an unclonable identifier (UID) from a portion of a physical object 106 (also referred to herein as an item) that includes a physically unclonable function (PUF). The reader can generate UID data that includes spectra data representative of at least one optical spectrum measured for the portion of the physical object containing the UID. For example, a polymer-based film or other structure, shown at 108, is attached physically to the physical object or otherwise incorporated within the physical object to define a UID for the physical object. For example, the PUF that defines the UID can be in the form of a disordered multilayer photonic crystal structure encoding data representative of the UID (e.g., implemented in a polymer film) that is attached to and / or embedded within the physical object. Examples of polymer films or other structures that can be attached to or incorporated into objects are disclosed in U.S. patent no. 12,059,830, which is incorporated herein by reference. The UID for the physical object defined by film or other structure 108 provides guarantees of authenticity and unique identity that are verifiable according to the systems and methods described herein.
[0033] The reader 102 can be a handheld device, a bench top device, or have other form factors that can vary depending on the particular use environment. In an example, the reader 102 includes a spectrometry apparatus configured to acquire at least one measure of electromagnetic transmission and / or reflection spectrum or spectra for a portion of the physical object having the PUF. The spectrometry apparatus provides spectra data representative of the measurement(s) acquired from the physical object. In some examples, the reader 102 can also include an optical imaging apparatus configured to acquire an optical image of one or moreportions of the physical object and provide image data. The UID data thus can include the spectra data or a combination of spectra data and image data.
[0034] The computing system 104 can be a cloud-based system that includes non- transitory memory 110 and one or more processors 112 (also referred to in its singular form for sake of brevity). The computing system 104 can be local or remote from the reader 102 and receive the UID data through a communications link, shown at 114. The communications link 114 can include a direct local connection, a direct remote connection, or an indirect connection through a local area network and / or a wide area network, such as the internet. Thus, the communications link 114 may include any number of one or more physical and / or wireless communication links). The communications link 114 can include one or more connections to a server or cloud, defining the computing system 104. In examples, the systems and methods herein can be implemented according to various deployment models. In one example deployment model, the computing system 104 is managed by a third party, which can provide the software and operationally manage the cloud-based computing system 104 as a service supporting all users that make use of those services. In another example deployment model, the computing system 104 and one or more instances of software is owned and / or controlled by the user, such as implemented in their own computing system (e.g., a cloud-based system). In any deployment model, the computing system 104 can be implemented as a local on-premises computing system, a cloud-based computing system, or include both local on-premises computing system and cloud-based computing system. There can be more than one instance of the computing system, local or remote, in any deployment of the system 100.
[0035] The memory 110 can store instructions 116 and data 118. The processor 112 is coupled to the memory 110 to access the instructions so that, when executed by the processor, the instructions cause the processor to perform the functions described herein. In the example of FIG. 1 , the instractions 1 16 include a compare function 120, a results generator 122, and a response handler 124. The data 118 can include received UID data 126 and results data 128. In some example implementations, the instructions 116 can also include an external verification function 130 that can access third party verification features.
[0036] As an example, the processor 112 can execute the compare function 120, based on the received UID data 126 provided by the reader, which causes the processor to determine a unique identifier, authenticity, and / or provenance of the physical object 106 based on the received UID data 126 and predetermined UID data 132 in a data store 134. The data store 134 can be an external data storage, as shown, and / or be implemented within the memory 110 of the computing system 104. Regardless of its location, the data store 134 can store the predetermined UID data for a multitude (e.g., billions) of UIDs. The compare function 120can further cause the processor 112 to match the received UID data 126 from the reader 102 against such predetermined UID data 132 in an efficient, effective, and secure manner. For example, the compare function 120 performs a matching process that includes data segmentation to analyze features, such as derived based on the spectra data, find a closest match for segments across the spectrum measurement(s), and determine if a match exists within a set of possible matches. In some examples, subsequent to this initial phase of matching, the compare function 120 can finalize selection on whether a match has been determined or not based on the image data, which has been acquired by the reader and provided as part of the UID data 126. The processor 112 can execute the results generator 122 to generate the results data 128 based on the matching by the compare function 120. The results data 128 is thus indicative of the unique identifier, authenticity, and / or provenance of the physical object 106. The response handler 124 can cause the processor 112 to send the results data back to the reader 102. The reader 102 can further be configured to provide a user-perceptible output on a user interface 136, such as including an output device. For example, the reader 102 can provide a visual display (e.g., on a display device), an audible indicator (e.g., on a speaker), and / or a tactile indicator (e.g.. on a haptic device) specifying the unique identifier, authenticity, and / or provenance of the physical object based on the results data 128.
[0037] In some examples, the polymer film or other structure 108 on the object 106 includes one or more markers on or incorporated within the polymer film. For example, the one or more markers include a randomly generated non-sequential number that is associated with (e.g., programmatically linked to) a respective batch of the polymer film from which the particular structure 108 on the physical object 106 has been produced. Also, or alternatively, the one or more markers can include a defined image that is associated with the batch of him producing the polymer him, which contains the UID, and / or an optical feature implemented in the film.
[0038] The reader 102 can be further configured to provide marker data that has been produced, as part of the film, to encode each marker and / or film or other structure 108 with which the respective marker is associated. For example, the reader 102 is configured to capture (e.g., by an optical imaging apparatus thereof) each of markers within a designated one or more portions of the physical object that includes the PUF and provide captured marker data that is included as part of the UID data 126 that is received by the computing system. As part of a pre-provisioning phase (e.g., before the structure 108 is applied to the object 106), marker data for a given batch of polymer film can be securely captured (e.g., by an instance of the reader or other optical imaging device) and saved cryptographically in the data store 134 aspart of the predetermined UID data 132. The marker data can be used as part of the verification process, such as described herein.
[0039] As described herein, the computing system 104 can be implemented as a cloudbased security system that provides a set of features to one or more entities to provide for authenticity, provenance, identity, and fraud detection to such entities when working with UID- based objects. The computing system 104 further can support secure operations of binding, verification, and lookup associated with UIDs to operationalize the use of the UID-based objects by one or more entities. In some examples, an external transaction network can be configured to verify the UID data for some entities.
[0040] As used herein, binding refers to the operation undertaken by a producing entity of an item that wishes to “bind” the combination of a unique polymer film on a produced item and create an identifier that proves this item is unique, authentic and has an associated identifier. This binding operation establishes the UID in a secure manner. The identifier can be stored as predetermined UID data encoding a UID attached to and / or incorporated into the item. For example, the binding operation is performed by authenticated and authorized individuals or agents operating a reader that is also authenticated and authorized. The binding
[0041] As used herein, verification refers to the operation undertaken by any party that is authenticated and authorized within the closed ecosystem of a producing party of an item. This verification operation establishes if an item has a UID, whether that UID is both authentic and what its UID is, thereby enabling further processing such as in supply chain, asset tracking applications. For example, the verification operation establishes the UID in a secure manner such that the operation is performed by authenticated and authorized individuals or agents operating a reader that is also authenticated and authorized. As used herein, an operation with a reader that generates UID data for a physical object (e.g., item) defines a transaction (also referred to herein as an operational transaction).
[0042] As used herein, lookup is the operation undertaken by any party that is authenticated and authorized within the open ecosystem of the producing party of an item where that producing party has a policy of responding to those open queries about items’ authenticity and / or identity, and / or provenance. This lookup operation establishes if a particular item has a UID, whether that UID is both authentic and what its UID is, thereby enabling further processing in supply chain, asset tracking applications. This lookup operation establishes the UID in a secure manner such that the operation is performed by authenticated and authorized individuals, or agents that are allowed by the producing party’s policies, operating a reader that is also authenticated and authorized.
[0043] FIG. 2 is a block diagram of an example reader 150 configured to obtain measurements and provide UID data. The reader 150 provides a useful example of the reader 102of FIG. 1. Accordingly, the description of FIG. 2 can refer to certain aspects of FIG. 1. The reader can include a combination of hardware and software arranged and configured according to a given use environment. In the example of FIG. 2, the reader 150 includes a spectrometry apparatus 152, an optical imaging apparatus 154, and a user interface 156. The reader 150 can also include one or more processors 158 and memory 160, which can store instructions and data. The processor 158 is coupled to the memory 160 to access the instructions and data so, when executed by the processor, cause the processor to perform the functions described herein. For example, the processor 158 and memory can be configured to control reader operations, perform processing of measurements, communicate with a cloud-based security system (e.g., computing system 104), and generate reader outputs.
[0044] The reader 150 further can include an input device 162 (e.g., mouse, keyboard, touchscreen interface, voice interface, or the like) and an output device 164 (e.g., a display, speaker, and / or haptic device). The input device 162, output device 164, and user interface 156, individually or collectively, enable an operator to interact with the reader 150. For example, an operator of the reader 150 may interact with the reader through the user interface 156, such as in response to a user input entered at the input device 162 of the reader. Responsive to such user inputs, the reader 150 can generate one or more user-perceptible outputs at the output device 164, such as to provide information relevant to the status, control, and / or operation of the reader 150.
[0045] In some examples, the reader 150 includes an authentication interface 166 (e.g., instructions stored in memory 160) configured to authenticate an operator as a valid user before enabling one or more functions of the reader for determining the identity, authentication, and / or provenance of an item. The authentication interface 166 can be configured to authenticate and authorize the reader (e.g., reader 102), locally and / or remotely, to perform measurement operations on behalf of an organizational entity who owns and / or controls an instance of the computing system. Also, or alternatively, the authentication interface 166 can be configured to authenticate and authorize an operator of the reader, locally and / or remotely, to perform the measurement operations on the authenticated and authorized reader.
[0046] As a further example, the authentication interface 166 can be configured to implement single or multi-factor authentication (MFA) to verify the operator’s identity as an authorized user for the reader 150. The authentication interface 166 can require the operator to enter a username and password through the user interface 156 (e.g., entered at input device 162). Also, or alternatively, the authentication interface 166 can require biometric identification, such as a facial scan and / or fingerprint. The level and method of authentication utilized for the reader can be set by the entity (or group of entities) that controls and / or owns the security system (e.g., system 100). As an example, the operator first enters their username and password into the user interface156 through the input device 162, and / or the operator can provide a biometric scan to verify their identity, enhancing security by requiring two different forms of identification. Other authentication schemes can be used in other examples, which can be defined by the entity that owns and / or controls the reader.
[0047] The authentication interface 166 can operate wholly at the reader 150 and / or require verification by an external system, such by communicating through one or more communications interfaces 168. For example, the authentication interface 166 can perform some reader-side processing (e.g., basic validation and / or no empty fields). The authentication interface 166 can then send the operator’s credentials (e.g., operator credential data) to a server, which can be the cloud-based security system (e.g., the computing system 104) or another system, through a corresponding communications link (e.g., link 114). The operator’s credential data can be encoded or encrypted by the authentication interface 166 (e.g., using SST / TTS or another cryptographic protocol) for an additional layer of security. The server receives the operator’s credential data, if necessary, decrypts the data, and extracts the username and password. The server can hash the entered password for the operator and compare it to a stored hash for verification. The server can return a response to the reader 150 (e.g., through the communications link) indicating whether the authentication is successful or not. If the authentication is successful, reader controls 180 (e.g., instructions stored in memory 160) can enable functionality commensurate with a level of authorization for the operator (e.g., for scanning and measurements of items). If the authentication is successful for the operator, the reader controls 180 can disable its functionality and an alert message can be sent to an administrator or other personnel.
[0048] After the reader is activated and enabled for scanning, the spectrometry apparatus 152 is configured to acquire at least one measure of electromagnetic transmission and / or reflection spectrum or spectra for a respective portion of a physical object. The portion of the physical object that is scanned by the spectrometry apparatus 152 includes a PUF (e.g., film or structure 108), which can be in the form of a disordered multilayer photonic crystal structure encoding data representative of the UID (e.g., implemented in a polymer film) that is attached to and / or embedded within the physical object. For example, the spectrometry apparatus 152 acquires one or more measurements responsive to a user input entered at a corresponding input device 162 (e.g., a trigger or switch, or other input device). The reader controls 180 further can be configured to control operation of the spectrometry apparatus 152 responsive to user input instructions entered through user interface 156 by the input device 162. The acquired measurement(s) for a given physical object can thus define spectra data 170 that are stored in memory 160 as part of UID data 172 for the given object. The reader controls 180 can one or more control operatingparameters of the spectrometry apparatus 152 (e.g., the wavelength or wavelength range, optical resolution, acquisition rate, etc.). For example, the reader controls 180 can control the measurement mode implemented by the spectrometry apparatus 152, such as to operate in a reflective mode or a transmission mode. The operating parameters of the spectrometry apparatus 152, including the measurement mode, can be stored in memory as part UID data, such as in the spectra data 170 and / or reader profile data 178.
[0049] In some examples, the spectrometry apparatus 152 collects a number (N) of measurements of the electromagnetic transmission and / or reflection spectrum or spectra for the physical object (e.g., providing N spectra measurement sets, where N is positive integer, such as five). The measurements can be analog signals that are converted to a corresponding digital representation having a defined number of bits of each of the respective measurements. For example, the instructions can include a measurement aggregator function 174 configured to cause the processor 158 to combine at least some of the measurements of the electromagnetic transmission and / or reflection spectrum or spectra (e.g., acquired over a measurement time interval) and provide an aggregate spectra measurement based on the N spectra measurement sets. In some examples, the measurement aggregator 174 is configured to average the collected N spectra measurement sets into a resultant spectra measurement set, which defines the spectra data 170, for use in subsequent processing. The spectra data 170 of the UID data 172 thus can include the aggregate measure of the electromagnetic transmission and / or reflection spectrum or spectra based on multiple measurements acquired over one or more time intervals. One or more timestamps can also be stored in the memory with the spectra data 170 to specify a transaction time for the measurement(s).
[0050] In examples where the reader 150 also includes the optical imaging apparatus 154, the optical imaging apparatus is configured to acquire one or more optical images of at least a portion of the physical object and provide image data 176. The optical imaging apparatus 154 can be a digital camera or other imaging device (e.g., including optics and an optical image sensor) and operative to acquire images in a wavelength range, such as including the visible light spectrum and, in some examples, also a portion of the infrared and / or ultraviolet spectrums. The portion of the object that is imaged can be the same or different from the portion of the physical object that is scanned by the spectrometry apparatus. As an example, the reader controls 180 (or other instructions) can cause the processor to control the optical imaging apparatus 154 to capture an area of the object (e.g., object 106) that includes the UID film based on a bounding box for the image capture, which can be defined to ensure normalized orientation and facilitate reproducible image matching. The bounding box can be a 2D rectangle (or other shape) having a well-defined surrounding marker to visualize the bounding box on the output device 164(e.g., a display) that the reader 150 is able to easily align (automatically or in response to a user input) at image capture.
[0051] The optical imaging apparatus 154 further can acquire the image responsive to a user input entered at a corresponding input device 162 (e.g., a trigger or switch, or other input device). For example, the reader controls 180 can one or more control operating parameters of the optical imaging apparatus 154 (e.g., illumination wavelength range, optical resolution, acquisition rate, etc.). The image data can include one or more optical image frames. The optical image can be acquired concurrently (e.g., at the same time) with the measurement(s) acquired by the spectrometry apparatus 152 such as responsive to activation a common input device of the reader 150 for activating both the spectrometry apparatus 152 and the optical imaging apparatus 154. Alternatively, the optical imaging apparatus 154 can acquire the optical image sequentially with respect to (e.g., before or after) the measurement(s) acquired by the spectrometry apparatus 152, such as responsive to activation an input device, which can be the same or different input device for activating the spectrometry apparatus 152. The image data 176 can be stored in the memory 160 such as part of the UID data 172. Operating parameters for the imaging apparatus also can be stored as part of the UID data, such as in the image data or reader profile data 178
[0052] The reader profile data 178 can represent physical and / or logical attributes of the reader 150. The reader profile data 178 can be preconfigured for the reader 150 or, in other examples, the reader can be configured to support multiple reader profiles. When supporting multiple reader profiles, the reader profile data 178 would vary based on which profile is being used, such as can be selected in response to a user input entered by the operator (or an administrative user) through the user interface 156 or remotely through the communications interface 168. Also, or alternatively, the reader profile can be defined based on physical and / or configuration adjustments of the reader 150, which can also be represented in the reader profile data 178, automatically or responsive to a user input.
[0053] The reader profile data 178 can include operating parameters of the spectrometry apparatus 152 and / or the optical imaging apparatus 154, which can facilitate processing of UID data downstream (e.g., to perform filtering of data sets by computing system 104). The reader profile data 178 can also be used to identify the reader 150 uniquely within a global security system (e.g., the system 100 that includes the computing system 104). Also, or alternatively, the reader profile data 178 can include a unique identifier for each reader and indicate (directly or indirectly through a lookup) a particular entity or a subset of entities that are provisioned to operate each respective reader in the global security system (e.g., the system 100). For example, the reader profile data 178 can include an operatoridentifier and reader attribute data. The operator identifier can be determined based on an identity of a user of the reader 150 (e.g., determined at operator authentication by authentication interface 166). The reader attribute data can include information representative of at least one of a transaction timestamp for the UID data, physical location of the reader, and / or logical location of the reader 150 as well as metadata.
[0054] The reader can also include a UID generator 182 configured to generate the UID data 172 that is stored in the memory 160. For example, the UID generator 182 provides the UID data according to a schema based on the acquired spectra data 170, image data 176, and reader profile data 178. In some examples, the UID data 172 docs not include information describing or identifying the physical object, a supply chain in which the physical object is shipped, and / or an owner or manufacturer of the physical object. By omitting such information from the UID data 172, the identity of the physical object and information about its supply chain can remain obfuscated and thereby inhibit unauthorized authentication.
[0055] In some examples, the polymer film or other structure of the physical object can also include one or more markers, and the UID data 172 can also include marker data 184 encoding one or more markers that are on or incorporated in the polymer film or other structure defining the PUF. As mentioned, for example, the one or more markers can include a randomly generated non- sequential number, a defined image, and / or another optical feature implemented in a given batch of him producing the polymer him UID. For example, the optical imaging apparatus 154 is configured to capture each of markers within a designated one or more portions of the physical object (e.g., object 106) that includes the PUF. The marker capture can be part of a single image acquisition process that is used to provide the image data 176 or, alternatively, a separate marker acquisition phase can be implemented by the reader 150 to separately image and provide captured marker data 184 that is included as part of the UID data 126 that is received by the computing system. For example, the instructions can be programmed to cause the processor 158 to extract the marker(s) from the image, such as based on image processing (e.g., segmentation, feature extraction), and provide marker data 184 that encodes the marker and / or PUF with which the respective marker is associated.
[0056] The reader 150 can also include a UID binding module 186 (e.g., instructions stored in memory 160) configured to bind the UID data 172 with attributes of the reader. The attributes of reader can include including at least one of (a) a unique identifier for the reader, (b) a transaction timestamp, (c) a geographic location of the transaction, (d) logical network location, and / or (e) operator data to provide bound UID data. Also, or alternatively, the UID binding module 186 is configured to bind the UID data 172 with biometric and / or other datauniquely identifying an operator of the reader 102 to provide the bound UID data. For example, the authentication interface 166 can obtain the data identifying the operator as part of a device and / or operator authentication process, such as described herein. The reader controls 180 (or other instructions in the memory 160) further can be configured to control the communication interface 168 to package the UID data 172, which has been bound to other data and / or devices, and send the packaged UID data over a secure communications link (e.g., cryptographically encoded) to the computing system (e.g., computing system 104) for further processing as described herein.
[0057] As a further example, the UID binding module 186 can be enabled or disabled during operation of the reader 150 (in a binding mode) based on whether or not the reader has been authenticated and authorized (e.g., through the authentication interface 166). Provided that the reader 150 has been authenticated, the UID binding module 186 of the reader can utilize a digital certificate (e.g., an X.509 certificate or a self-signed certificate) for implementing a secure transaction through the communications interface 168. For example, the UID binding module 186 can control the reader to establish a mutually authenticated TLS connection to a binding receiver agent, such as implemented in the cloud-based security system (e.g., system 100) or part of an external transaction network (not shown - but see, e.g., FIG. 17). The UID binding module 186 can generate a digital signature using a private key and a signature for the reader 150 and generates an encrypted binding request that is submitted to the binding receiver agent (e.g., through an application programming interface (API)). For example, the binding request can be a binding package request, which can include UID+signature+nonce. The binding package request can use different information to uniquely identify the request from the reader 150. The binding receiver agent decrypts the binding package request, checks the digital signature within the package to ensure that it originated from an authorized binding reader device. If authorized, the binding receiver agent submits the package to a binding queue that sends the job to a process that captures the binding package for persistence. A binding processor can receive the binding package from the queue and extract the UID and other request data, which can be saved to persistent storage, and invokes a binding begin event with submitted infomration to any registered binding adapters. The binding processor can send back a confirmation message to the reader (e.g., through the same TLS connection) to indicate that the process has been persisted. The binding processor can invoke a binding complete event with submitted information to any binding adapters registered by the organization. The binding receiver agent can then receive the binding persisted response and then sends a response to the reader with a binding package response to confirm that the read has been completed. The reader 150 should either have ability to queue outstanding jobs or not allow further reads until the previous read has been confirmed. The reader can invoke a binding reader notifiedevent to any registered adapters informing them that the reader has successfully received the notification of the binding. Other binding protocols can be implemented in other examples.
[0058] FIG. 3 depicts an example data structure for UID data 200 that can be sent from a reader to a computing system implementing a security system (e.g., computing system 104), such as a cloud-based security system. As shown in FIG. 3, the UID data 200 includes reader profile data 202, spectra data 204, image data 206, marker data 208, and metadata 210. As described herein, the reader profile data 202 can include operator data 212 and reader attribute data 214. The metadata 210 can include security information (e.g., a digital signature) to ensure integrity of the content is not modified in transit. The operator data 212 can include operator ID data specifying an identity of the operator of the reader. In some examples, the operator data 212 can also include biometric data that is obtained by a biometric sensor that is part of or coupled to the reader. The reader attribute data 214 can include reader ID 220 specifying a unique identifier for the reader (e.g., serial number or other unique information). The reader attribute data can also include timestamp data 222 specifying a time for a given reader transaction. The reader attribute data 214 can also include location data, such as physical or geographic location, shown at 224, and a logical location (e.g., a system resource location), shown at 226. The reader attribute data 214 can also include other reader data 228, such as may indicate one or more operating parameters of the reader and / or sensed parameters for the environment where the reader transaction is performed. The particular format and notation used to store each of the data in the UID data 200 can vary according to application requirements and available resources.
[0059] FIG. 4 is a block diagram showing an example compare function 300 that can be executed by a processor (e.g., processor 112) for performing matching analysis to determine a unique identity, authenticity, and / or provenance of an item (e.g., physical object 106). The compare function 300 is a useful example of the compare function 120 of FIG. 1. Accordingly, the description of FIG. 4 also refers to certain aspects of FIG. 1 . As described herein, the compare function 300 causes the processor to determine the unique identifier, authenticity, and / or provenance of the physical object based on UID data 302 (e.g., UID data 172) provided by a reader (e.g., reader 102, 150) and predetermined UID data 304 stored in a data store 306. In some examples, the UID data 302 includes spectra data (e.g., spectra data 170). In other examples, the UID data 302 includes spectra data (e.g., spectra data 170) and image data (e.g., image data 176). Thus, the predetermined UID data can include and / or be derived from predetermined spectra data and predetermined image data. The received UID data can further include other infomiation such as described herein (see, e.g., FIG. 3).
[0060] The compare function 300 includes a spectra processing module 308 and an image processing module 310. The spectra processing module 308 is configured to evaluate spectra datain the received UID data 302 with respect to the predetermined UID data. As described herein, the matching analysis that is implemented by the compare function 300 to determine the unique identifier, authenticity, and / or provenance of the physical object further can be implemented based on the image processing module 310. In the example of FIG. 4, the spectra processing module 308 includes executable instructions that include a spectra chunking function 312, a spectra feature extraction function 314, and a spectra feature match function 316.
[0061] The spectra chunking function 312 is configured to cause the processor to divide the measure of the electromagnetic transmission and / or reflection spectrum or spectra, which is defined by spectra data in the UID data 302, into a plurality of spectra features (also referred to as data chunks). The spectra chunking function 312 can divide the measured spectra into one or more discrete spectra features (e.g., chucks), such as features that are divided into a set of discrete wavelengths (e.g., bands or ranges centered about respective wavelengths). The number of wavelength features into which the measured spectra is divided can be a defined number (e.g., 20, 50, or more), which can be configured responsive to a user input. Also, or alternatively, the spectra chunking function 312 can divide the measured spectra into one or more other discrete spectra features including absorption and emission peaks, intensity (e.g., as measured by spectrometry apparatus), and / or features derived from one or more such features. As mentioned, the spectra data in the received UID data 302 can represent an average for each of the wavelengths over multiple measurements, and the averaging of spectral measurements can be integrated with the spectra chunking to produce a desired set of spectra features. In examples wherein the compare function 300 (or portions thereof) is implemented using artificial intelligence the averaging and other data processing implemented in the reader and / or spectra chunking function 312 may constitute data preparation steps.
[0062] The spectra feature extraction function 314 is configured to assign a respective spectra feature value to each of the discrete spectra features based on attributes of the respective spectra feature. The feature value for each spectra feature can be a single value or a vector representative of one or more attributes of each of the respective features into which the measured spectra has been divided (e.g., by chunking function 312). As an example, the spectra feature extraction function 314 can determine one or more intensity values (e.g., amplitude) for each of the discrete wavelengths extracted from the spectra data. One or more other spectra feature value can be determined according to the features into which the measured spectra has been divided. The values of each of the features can be normalized to a known scale, such that the spectra feature values determined by the spectra feature extraction function 314 are likewise scaled values.
[0063] The spectra feature match function 316 is configured to match, to within a feature threshold, at least some of the spectra features with predetermined spectra features. Forexample, the spectra feature match function 316 can compare the respective spectra feature values (e.g., intensity values) with predetermined spectra feature values that are stored in the predetermined UID data of the data store and, based on applying the spectra threshold to the comparison, determine one or more matches (if any). The spectra threshold can be a default value or be configured responsive to a user input instruction. The predetermined UID data 304 includes a spectra feature database 318, which includes predetermined spectra features that have been divided into at least some of the same respective wavelengths for each instance of UID data. The values of the spectra features stored in the spectra feature database 318 can be normalized to the same scale (or scaling can be applied during feature matching.
[0064] In some examples, the spectra feature database 318 can be implemented as a vector database, in which the vector database stores spectra feature vectors in multi-dimensional vector space. Each of the spectra feature vectors can have one or more values, defining spectra vector embeddings, representative of the predetermined spectra feature values. Each of the predetermined spectra feature values of a given spectra feature vector is representative of one or more attributes of one or more spectra features extracted from a corresponding measure of electromagnetic transmission and / or reflection spectrum or spectra for a respective PUF that is on or in a particular physical object. One example of a method to implement the vector database that can be used for implementing the spectra feature database 318 and image feature database 322 is described at https: / / weaviate.io / platfonn. Other methods can be used in other examples.
[0065] The spectra feature match function 316 can thus perform matching of values of at least some of the spectra features with the spectra features stored in the spectra feature database for each instance of UID data. As an example, the matching can include a comparison of the received UID data across all spectra features of UID data that are stored in the spectra feature database 318 of the data store. A confidence value can be computed based on each comparison. The feature match function 316 can then determine if the spectra data in the received UID data 302 matches any stored UID data with a based on the confidence value exceeding the feature threshold. The spectra feature match function 316 can return a results list identifying one or more candidate matching UIDs based on the number of matching features determined to exceed the feature threshold.
[0066] In another example, the spectra feature match function 316 can be configured to use each feature value in the set of features of the spectra data as a hash into a mapping table, such as can be used in the spectra feature database 318 (or another data structure) of the predetermined UID data 304 for indexing. If the hash returns a value, the returned value can indicate the occurrence of a match between the respective feature and a stored feature in the predetermined UID data 304. If the hash does not return a value, it is determined that the respective feature does not match anyfeatures in the predetermined UID data 304. A results list can be generated based on the matching features.
[0067] In some examples, the compare function 300 includes an image retrieval function 320 that is configured to return a list (e.g., including an identifier) for each image of one or more predetermined images for respective UIDs from the data store 306 based on the results list determined by the spectra feature match function 316. That is, the results list operates as a filter based on the measured spectra (e.g., spectra data in the received UID data 302) to identify predetermined UID data, particularly image data thereof, for processing by the image processing module 310.
[0068] For example, the predetermined images are stored in an image feature database 322 that is part of the predetermined UID data 304 of the data store 306. The image feature database can be implemented as a vector database to store image feature vectors in a multi-dimensional vector space, in which each of the stored image feature vectors has a number of image feature values, defining image vector embeddings for each respective image of a known item having a respective physical object having a UID. Each of the image feature values of a given one of the stored image feature vectors can represent one or more attributes of one or more image features, which has been extracted from a corresponding image of a respective second portion of a known physical object.
[0069] As a further example, the image processing module 310 is configured to cause a processor (e.g., processor 112) to find one or more images stored in the predetermined UID data 304 that most closely match the image represented in the image data of the received UID data. In one example, the image processing module 310 can limit (or constrain) its processing to the set of images associated with predetermined UID data 304 that are identified in the results list, which defines a spectra-filtered UID data set, which includes a subset of image data, as provided by the image retrieval function 320. In another example, the image processing module 310 can apply its processing to the entire set of images stored in the predetermined UID data 304, such as based on the images in the image feature database 322.
[0070] In the example of FIG. 4, the image processing module includes an image segmentation function 324, an image feature extraction function 326, and an image feature match function 328. The image segmentation function 324 is configured to divide the optical image of the physical object, which is represented in image data of the received UID data, into a plurality of discrete images. For example, the acquired image defined by image data in the UID data 302 can include a known bounding box, image segmentation function 324 can divide the captured image into a number of data cells, such as arranged as rows and columns of cells (e.g., defining atwo-dimensional grid) within the bounding box to facilitate comparing the image to stored images in the predetermined UID data 304 in the data store.
[0071] The image feature extraction function 326 can be configured to determine respective feature values for each of the respective cells. For example, the image feature extraction function 326 can determine one or more values for each cell, which can include a color value for each color of a particular color model being used (e.g., RGB, HSL, CMYK, etc.). In one example, the image feature extraction function 326 can convert the image into a two-dimensional grid of cells, which includes a set of color values determined for each respective cell, which can be stored as an image vector for the respective image.
[0072] The image feature match function 328 can be configured to perform an image match function to compare extracted respective feature values for the image to predetermined images stored in the image feature database 322. The image feature match function 328 can further be configured to compute a confidence score, with respect to a confidence threshold, based on a comparison of the respective image feature values for the optical image and corresponding image feature values for each of the predetermined images. As mentioned, in some examples, the images in the predetermined UID data 304 to which the image feature match function 328 compares the extracted features for the received optical image can be a proper subset of the images in the predetermined UID data 304, such as the spectra-filtered UID data set that includes image data selected by the image retrieval function 320 based on the spectra matching (e.g., by spectra processing module 308). Based on such image feature matching, the image feature match function 328 can identify a closest image match.
[0073] In some examples, compare function 300, including the spectra processing module 308 and / or the image processing module 310, is implemented using artificial intelligence. For matching spectra data of in the received UID data 302 with predetermined spectra data sets (e.g., in spectra feature database 318) in the predetermined UID data 304 of the data store 306, the spectra processing module 308 can implement machine learning classifiers or probabilistic methods c to analyze and compare spectra data. Also, or alternatively, the image processing module 310 can implement artificial neural networks or deep learning algorithms to extract and match features from image data in the UID data 302 with predetermined image data (e.g., in image feature database 322) in the predetermined UID data 304 of the data store 306.
[0074] As a further example, the compare function can include one or more other filter functions operative to reduce the size matching functions implemented by the spectra processing module 308 and / or the image processing module 310. In the example of FIG. 4, such filters include a reader profile filter 330 and a marker filter 332. In other examples, one or more other filters can be applied to reduce the size of the relevant dataset in the data store 306.
[0075] The reader profile filter 330 can implement filtering of the predetermined UID data 304 in the data store 306 based on reader profile data (e.g., reader profile data 178, 202) that is included in the received UID data 302. As described herein, the reader profile data can define physical and / or logical attributes of the reader, to identify the reader within the system. There can be a multitudinous (e.g., millions or billions) of UID data sets, defining the predetermined UID data 304 in the data store 306, in which each UID data set is associated with a known physical object and / or a known PUF (e.g., represented in the film or structure 108). The reader profile filter 330 is configured to filter the UID data sets in the data store 306 to identify a subset of the predetermined UID data sets. The compare function 300, including the spectra processing module 308 and / or the image processing module 310, can thus be executed with respect to each of the UID data in the identified subset of the UID data sets to increase computational efficiency. For example, the compare function 300 can perform an indexed query of the predetermined UID data sets based on the reader profile data, in which the predetermined UID data sets in the data store are indexed based on profile data.
[0076] As described herein, polymer-based film or other structure (e.g., film or structure 108 defining a UID for a physical object) can include one or more markers on or incorporated within the film. The marker can be fixed (e.g., the same) across a given manufacturing batch of the film or vary across the given batch. For example, each marker can include a randomly generated non- sequential number, a defined image that is associated with the batch of him producing the polymer him UID, and / or an optical feature associated with a given batch of the film. Additionally, the optical imaging apparatus of the reader (e.g., reader 102, 150) can be configured to capture one or more markers in the acquired image of the physical object that includes the PUF(e.g., within the bounding box). In this way, the acquired image and the image data (e.g., part of the UID data 302) includes the marker(s). In some examples, the reader (e.g., UID generator 182 or other code) is configured to extract the marker from the acquired image and generate marker data that is included as part of the UID data. Additionally, corresponding marker data can be produced to encode each marker and / or PUF with which the respective marker is associated, and the marker data can be securely captured and saved cryptographically in the data store 306 as part of the predetermined UID data 304.
[0077] In the example of FIG. 4, the marker filter 332 that is configured filter the UID data sets in the predetermined UID data 304 of the data store 306 based on marker data in the received UID data 302. For example, the marker filter 332 includes a marker comparator 334 and a marker categorization function 336, which cooperate to define the functionality of the marker filter 332. Additionally, known marker data can be produced to encode each marker and / or PUF with which each respective marker is associated, and the marker data can besecurely captured and saved cryptographically in the data store 306 as part of the predetermined UID data 304, shown as a marker database.
[0078] The marker comparator 334 is configured to perform a comparison of the marker data across all marker data that are stored in the marker database 338 of the data store 306 and compute a confidence value based on each marker comparison. The marker filter can return the results data specifying a negative match indicative of failing to specify the identity, authenticity, and / or provenance for the physical object responsive to determining that the confidence value does not exceed a confidence threshold. Alternatively, based on determining that the confidence value exceeds the confidence threshold, the marker categorization function 336 can further determine a marker categorization based on the marker data. For example, the marker categorization can define a category or type of each item. The marker filter further can filter the predetermined UID data sets in the data store based on the determined marker categorization to provide a subset of the predetermined UID data having the determined marker categorization. The compare function 300 (e.g., the spectra processing module 308 and / or the image processing module 310) further can be executed with respect each of the UID data in the subset of the predetermined UID data sets returned by the marker filter 332.
[0079] In some examples, the predetermined UID data 304 can be filtered by the reader profile filter to produce a first subset of the predetermined UID data and the marker filter 332 can be applied to the first subset of the predetermined UID data to produce a second, likely smaller subset of the predetermined UID data. The compare function 300 (e.g., the spectra processing module 308 and / or the image processing module 310) can be applied with respect to the second subset of the predetermined UID data 304.
[0080] As a further example, the spectra processing module 308 can be applied to the second subset of the predetermined UID data 304 to produce a third subset of the predetermined UID data 304 (e.g., the spectra-filtered UID data set), which can specify a set of image data selected by the image retrieval function 320. The image processing module 310 can be applied to the third subset of predetermined UID data to ascertain the identity, authenticity and / or provenance of the physical object for which the UID data 302 has been received.
[0081] Alternatively, the image processing module 310 can be applied to the second subset of the predetermined UID data 304 to produce another subset of the predetermined UID data 304 (e.g., an image-filtered UID data set), which can specify a set of spectra data for different UIDs. The spectra processing module 308 can be applied to the image-filtered UID data set of the predetermined UID data 304 to ascertain the identity, authenticity and / or provenance of the physical object for which the UID data 302 has been received. In response to the determination of the identity, authenticity and / or provenance of the physical object for which the UID data 302 hasbeen received, a results generator 340 (e.g., results generator 122) can generate the results data based on the matching by the compare function 120. The results data is indicative of the unique identifier, authenticity, and / or provenance of the physical object. As described herein, the results can be sent to the reader (e.g., by response handler 124 through a secure communications link) for specifying and / or confirming the identity, authenticity, and / or provenance of the physical object.
[0082] FIGS. 5-16 describe a sequence of phases that can be implemented for determining the identity, authenticity and / or provenance of the physical object. For example, FIGS. 5-7 depict an example of a data collection phase that can be implemented by a reader. FIGS. 8-13 depict an example of a data preparation phase that can be implemented by a computing system. FIGS. 14-16 depict an example of a matching and determination phase that can be implemented by a computing system. The example of FIGS. 5-16 can be implemented using the reader, computing system, and compare function of FIGS. 1-4. Accordingly, the description of FIGS. 5-16 may refer to certain aspects of FIGS. 1-4.
[0083] FIG. 5 depicts an example of a data collection phase 400 that can include collecting one or more measurements of a physical object 402 (e.g., object 108) by a reader 404 (e.g., reader 102, 150). The physical object 402 includes a PUF that defines a UID for the physical object (e.g., a disordered multilayer photonic crystal structure encoding data representative of the UID). A valid PUF can be used to verify the identity, authenticity, and / or provenance of the physical object. Alternatively, an invalid PUF (e.g., a counterfeit) will result in negative results (e.g., no match). The reader 404 can provide and store in memory a raw UID data set of measurements 406, which can include spectra measurements acquired by a spectrometry apparatus of the reader 404 (e.g., by spectrometry apparatus 152). Alternatively, the reader can provide a combination of spectra measurements 408 and one or more images 410 acquired by an optical imaging apparatus (e.g., optical imaging apparatus 154).
[0084] FIG. 6 depicts an example of a plot containing a set of spectra measurements 450 that can be acquired by a spectrometry apparatus of the reader 404, such as the original spectra measurements 408 in the raw UID data set of measurements 406. The spectra measurements 450 depict intensity as a function of wavelength over a range of wavelengths (e.g., the x-axis represents wavelength and the y-axis represents intensity). FIG. 7 depicts an example of an image 460 that can be acquired by a reader, such as defining the image 410 acquired for a designated portion of the physical object 402. The image 460 can be acquired by the imaging apparatus (e.g., optical imaging apparatus 154). The image can be a color acquired according to a color model, such that the pixels in the image include color values representing the intensity of respective colors based on the color model being used. Alternatively, the image can be a grayscale or monochrome image.
[0085] The raw UID data set of measurements 406 can be processed (e.g., locally at the reader 404 and / or by external imaging processing) to provide a UID data set and pre-processed data 412. The UID data set and pre-processed data 412 can include aggregated spectra measurements 414 and one or more images 416. As described herein, the aggregated spectra measurements 414 can include an aggregate measure of the electromagnetic transmission and / or reflection spectrum or spectra, which can be averaged based on multiple measurements (e.g., an average for each of the wavelengths over the multiple measurements). Also, the image(s) 410 can be pre-processed to provide the image(s) 416, such as cropping to remove other portions that reside outside a defined bounding box. Some initial filtering can also be performed on the raw image to place it in a format and desired resolution for backend processing.
[0086] FIG. 8 depicts an example of a data preparation phase 500 that can be implemented by a computing system, such as a cloud-based security system (e.g., computing system 104, including some parts of compare function 120, 300). As shown in FIG. 8, a cloud data receiver 502 receives UID data (e.g., UID data 126, 172, 302) generated by a reader (e.g., reader 102, 150, 404). For example, the reader sending the data has been authenticated and authorized (e.g., using a certificate or secure token) to operate as a legitimate source of data with the cloud data receiver 502 and / or the UID data that is received from the reader can also be authenticated and authorized (e.g., using a digital signature or message authentication code), such as to ensure that the data itself is verified and comes from a legitimate source. The received UID data can include spectra data 504 and image data 506, which can be provided a spectra data preparation block 508 and an image data preparation block 510, respectively. For example, the spectra data preparation block 508 can be implemented by spectra processing module 308 and the image data preparation block 510 can be implemented by the image processing module 310. The spectra data preparation block 508 chunks the spectra measurements defined by the spectra data into spectra features 512, shown as spectra chunks 1 through M, where M is a positive integer representing the number of spectra features (e.g., M can be a default value or be configurable). For example, the spectra features can each have one or more values representing a spectral intensity at one or more wavelengths, such as a spectra measurement 530 shown in FIG. 9. In the example of FIG. 9, the captured spectra measurement 530 (e.g., spectra data 504) that has been divided into 50 of spectra features (e.g., labeled from 1 to 50), each representing a different wavelength. While the example of FIG. 9 shows the spectra measurement divided into 50 spectra chunks, a given spectra measurement can be divided into a different number of chunks that can be greater than or less than 50. Additionally, the spectra data preparation block 508 can assign one or more values to each of the spectra features 512, such as specifying an intensity or amplitude of one or more wavelength peaks or other waveform features (e.g., waveform morphology, such as phase, frequency, shape, etc.).
[0087] Referring back to FIG. 8, the image data preparation block 510 chunks (e.g., segments) the image defined by the image data 506 into image features 514, shown as image features 1 through P, where P is a positive integer representing the number of image features. For example, FIG. 10 depicts an example image 550 of a portion of a physical object divided into a two-dimensional grid of image data cells 552. Each cell 552 can include one or more pixels, which can depend on the original image and the size of the bounding box at image capture. The image data preparation block 510 can assign one or more values to each of the image features 514 (e.g., cells 552), such as specifying values representative of the colors for each image feature. The value can be a vector of color values of each pixel that defines the respective image feature. Alternatively, the value for each image feature can be an aggregate value based on the set of pixels that define each respective image feature. As an example, FIG. 11 is a table 560 showing an example of image feature values specified for respective cells 552 in the image 550 of FIG. 10. The table 560 includes “I” columns and “J” rows, where I and J are positive integers defining the dimensions of the grid for the image 550. The cells of the table 560 each include a set of values representative of the color or colors for each cell of the image 550 to enable subsequent processing that can compare the image feature data for the captured image to corresponding features for stored images in the data store.
[0088] The data preparation phase 500 can also include a reader profile selection function 520 to select a reader profile from a plurality of reader profiles 522, shown as profiles 1 through Q, where Q is a positive integer representing the number of profiles. For example, the reader profile selection function 520 can select a data filtering index based on the reader profile. The reader profile can be defined by reader profile data (e.g., reader profile data 178) that is provided in the UID data received by the cloud data receiver 502 for the active transaction. The data filtering index that is selected can be used (e.g., by reader profile filter 330) to filter the UID data sets in the predetermined UID data in the data store (e.g., data store 134, 306) for the active measured data in the received UID data. The data preparation phase 500 can output the pre-processed UID data shown at 524, which can include the spectra features 512, image features 514 and other UID data (e.g., reader profile data, marker data and the like), such as described herein.
[0089] FIG. 12 depicts an example of a match determination phase 600 that is implemented based on pre-processed UID data 524 provided by the data preparation phase 500. The match determination phase 600 includes a reader profile filter function 602 that is configured to filter the spectra data in the data store (e.g., spectra feature database 318) to provide a filtered spectra data set 604 based on the reader profile (e.g., data filtering index) in the pre-processed UID data 524. For example, the predetermined UID data (e.g., the spectra feature database of the predetermined UID data 132, 304) stored in the data store is indexed based on reader profile so that the filtering at602 can be implemented as an indexed query based on reader profile data. As described herein, the filtered spectra data set 604 defines a subset of the predetermined UID data that includes a corresponding set of spectra data consistent with the reader profile data.
[0090] At 606, match determination phase 600 includes filtering of the subset of predetermined UID data, which is defined by the filtered spectra data set 604, based on the measured spectra that are defined by the spectra features 512 in the pre-processed UID data 524. For example, FIG. 13 depicts a table 650 showing spectra feature values that have been predetermined for a plurality of UIDs, shown s UID 1 through UID N, where N represents the number of UIDs (c.g., the number predetermined data sets) in the data store. In FIG. 13, spectra values are determined for each of the features (numbered features 1 through 50) for wavelengths ranging from 350 nm to 750 nm. Other ranges of wavelengths and numbers of features can be used in other examples. Referring back to FIG. 12, the filtering at 606 provides a filtered image data set 608, which is a further subset of the subset of predetermined UID data defined by the filtered spectra data set 604. For example, the filtered image data set 608 can include a subset of the N data sets shown in the table 650 of FIG. 13 based on the filtering at 606.
[0091] The filtering at 606 (e.g., corresponding to spectra feature match function 316) can be configured to match the spectra features in the pre-processed UID data 524 to sets of spectra features in the subset of predetermined UID data based on defined spectra matching thresholds. Accordingly, the filtering at 606 may be implemented according to one or more different methods.
[0092] FIG. 14 depicts an example of feature values, such as can be determined based on computing a match function (e.g., by the filtering at 606, such as corresponding to spectra feature match function 316) between stored feature values and feature values determined from one or more spectra measurements. For example, for each feature value from the spectra measurements a match value is determined for the corresponding feature in each of the data sets in the data store. The spectra feature values for each of the data sets can be sorted based on the results of the matching function, such as shown in respective columns for each of the measured spectra features.
[0093] As a first example, assuming 50 spectra features, the filtering at 606 can implement sequential spectra filtering. For each feature (e.g., from Feature 1 to Feature 50) starting at Feature 1, in sequential spectra filtering, perform the match for an active match feature (AMF), using the closest match function F, such as described herein. If the AMF match falls below the match threshold (MT), then a count of failed feature matches is incremented. If the failure threshold for feature failures is met, then the sequential spectra filtering can terminate further searching and return no UID match found. If the AMF match succeeds, above the match threshold (MT), then sequential spectra filtering can move onto the next feature until we reach the last feature N.
[0094] As a second example, the filtering at 606 can be implemented using a windowed spectra filtering method. For a window size (NW), where NW is between 2 and N / 2 features, the windowed spectra filtering method can execute parallel threads that perform closest match function F for the respective feature and return the match result to an aggregator function. If the aggregator function determines that the resultant NW matches is above the failure threshold then further searches can be terminated and return no match found. If the aggregator function determines that the resultant NW matches is below the failure threshold then continue to the next feature window. If the last feature window, windowed spectra filtering method can collect all resultant match scores across the NW-windows list and determine if a complete match is found, such as determined using the above threshold.
[0095] As a further example, the closest match function F can be implemented using a vector database technology, in which each spectra feature is a separate vector database and each feature vector includes FS discrete measurements (where FS denotes a feature size representing a number of discrete measurements). Each match function looks in the assigned vector database for its corresponding wavelength. The vector database supported Hamming function can be used to find the closest feature vector and then return the data associated with the found feature vector including how close it is (e.g., a distance, such as a Hamming or other distance measure).
[0096] For each feature found in the measured spectra of in the data sets of the predetermined UID data, the matching implemented by the filtering 606 returns a closest match image list of the respective feature stored in the predetermined UID data that meets the defined feature values threshold for the matching. In an example where the matching or filtering at 606 is implemented using artificial intelligence, such as a neural network, this step is similar to how a neural network works where the features passed into the first layer of the network and then subsequent nodes / layers in the NN aggregate the outcome of the feature analysis from the prior layer to aggregate the resultant output at the final layer.
[0097] As a further example, where there are eight spectra feature values for each feature, each discrete measurement within a respective feature contributes to 12.5% of the accuracy. If the match does indicate the exact same value then the degradation of accuracy can be a percentage of difference between the measured and stored values. As a further example, FIGS 15 and 16 depict examples of spectra measurement execution for a match function used by the filtering at 606 (e.g., spectra feature match 316). FIG. 15 depicts an example of spectra measurement execution, in which an almost perfect match results with one discrete measurement within a feature not matching. FIG. 16 depicts an example of spectra measurement execution, in which less than perfect match results with 2 features not matching.
[0098] Referring back to FIG. 12, at 610, image matching 610 is performed based on the filtered image data set 608 produced by the filtering at 606. For the matched image list defined by the filtered image data set 608, the image matching at 610 can be configured to take each image and compare that image using an image match function IMF (e.g., image feature match function 328) with respect to the images defined by the filtered image data set, which includes a subset of the data sets in the data stored based on the previous filtering at 602 and 606. The imaging matching at 610 thus can be configured to find the closest match of the image list returned with the highest confidence score. As one example, the image matching can be implemented using the Oriented FAST and Rotated BRIEF (ORB) algorithm described in OpcnCV. Other image matching methods (e.g., SIFT or SURF among others) can be used in other examples.
[0099] The UID match determination at 612 is configured to provide results data at 614 based on the image matching at 610 provided that a sufficient number of the spectra measurement features have matched based on spectra feature threshold values. The number of spectra measurement features can be defined by a feature threshold. Provided that the sufficient number of spectra measurement features have matched (e.g., meeting the respective feature’s threshold) a second matching is performed based on image comparison. For example, the second matching can compare the features and the resultant confidence score relative to an image confidence threshold. If the matching determines the confidence score exceeds the image confidence threshold, then a match is provided in the results data 614, otherwise no match is returned in the results data.
[0100] As a further example, a neural network implementation for the match determination phase 600 could implement the image matching at 610 as a second (or subsequent) layer of a neural network fed by the spectra matching layer (implemented at 606) and the resultant set of images and their associated confidence scores would feed a layer implementing a UID match determination at 612. The match determination layer implemented at 612 could define an output layer of the neural network configured to provide the output of the network analysis of the input features and its resulting analysis of the features on whether a match to an item in the database was found. The results data at 614 thus can include the identity, authenticity, and / or provenance of the physical object for which the measurements have been collected and processed.
[0101] FIG. 17 depicts an example external verification system 700, which can be used in connection with the systems and methods described herein. The system 700 includes an external verification engine 702 that can communicate with an external transaction network 704, such as through a secure communications link 706. The external transaction network 704 can be a blockchain-based network, for example. The external verification engine 702 is an example of the external verification function 130, which can be implemented in the system 100 as instructions to cause one or more processors (e.g., processor 112) to perform the functions described herein. Theconnection between the system 100 and the external transaction network allows binding transactions to be committed to the external transaction network 704 so that the binding operation is both transparent, immutable and available on the external transaction network. By committing the binding operations to the external transaction network 704, parties that may wish to verify the authenticity and identity of an item without being provisioned as part of the closed or open ecosystem that would support the normal verification and lookup operations.
[0102] The external verification engine 702 (or another function) can be configured to bind operational transaction data 708 to the external transaction network 704. The operational transaction data 708 that is being bound can include and / or be associated with the received UID data (e.g., from a reader). The external verification engine 702 can also include an external request generator 710 configured to further cause the one or more processors to send the operational transaction data 708 to the external verification network through the communication link 706 (e.g., a secure link) as described herein. A response handler 712 can be configured to handle responses received from the external transaction network 704 based on the request to the external transaction network 704.
[0103] The external transaction network 704 can include a request handler 714, an authentication engine 716, and an immutable transaction data store 718. The request handler can process authentication requests from any number of requestors, including the external verification engine. The authentication engine 716 can verify the identity of the information in the operational transaction data, such as by matching the operational transaction data against the information in the immutable transaction data store 718. The results of the matching can confirm the match (e.g., with a confidence threshold) or determine whether the operational transaction data is invalid. The authentication engine 716 can command the request handler 714 to issue a response to the operational transaction data identity based on the results of the matching. The request handler 714 can provide a response through the link back to the external verification engine 702. The response handler 702 thus can receive the response from the external transaction network 704. The response can include information representative of at least one of an identity of the physical object, an authenticity of the physical object, a provenance of the physical object, a description of the physical object, a description and / or information associated with an organization entity. A user- perceptible output specifying the unique identifier, authenticity, and / or provenance of the physical object can be generated (e.g., at a reader or other output device) based on the results data and / or the response from the external verification network.
[0104] Effectively external verification engine 702 allows parties producing items to expose binding transactions in a public and transparent network that could be used by anyone to verify ifan item is authentic and potentially the identity of the item if that information were included in the binding transaction committed to the external transaction network.
[0105] In view of the foregoing, the systems and methods described herein provide one or more of the following:1) A mechanism for entities to attach polymer-based labels to items, providing a unique unclonable identifier2) A mechanism to read those UIDs into digitized form that is globally unique, supporting systems to match quickly and efficiently against potentially billions of other items.3) A set of mechanisms and processes to associate the UID with an item, verify the item’s UID at any point after the binding to either closed or open-ecosystem entities4) A mechanism taking that digitized version of the UID and find an exact match within a data store of billions of items.5) An optional capability to support external transaction verification using blockchain (public or private blockchain) and the mechanism to determine inconsistencies between the external transaction verification and the closed ecosystem verification.
[0106] Some additional benefits of the systems and methods described herein can include:1) Open via cloud based commercial infrastructure vs. proprietary DB or blockchain reliance;2) Aid to supply chain by simplifying sponsor establishment of a system, rules, and multi-part integration;3) Open support to multiple reader types (dedicated, embedded, consumer - and across multiple vendors for further openness)
[0107] FIG. 18 is a high-level system 800 that highlights the relationships between the various cloud, on-premises and software elements that can be implemented in a cloud-based security system (e.g., system 100). The following table provides example descriptions of the various parts shown in the system 800 to provide additional context.
[0108] Many of the concepts within the system 800 may provide the infrastructure required for security principles covering zero trust, secure access, secure connections and so on. In many respects, Secure Service Edge (SSE) or other technologies may embody the certain aspects of the cloud-based security system.
[0109] Cloud Controller: The software running in the cloud that is only accessible by Cloud Core operational staff. Web-based portal to allow provisioning, monitoring, audit. . .etc. of all Cloud Core functions for that instance of the controller. Backend admin / auditing of all microservices supporting the controller and customer instances.
[0110] Bind Reader - The physical device that reads UID and sends binding packages to the customer instance.
[0111] Verify Reader - The physical device that reads an item for its UID and works with the customer instance to confirm a UID matches.
[0112] Lookup Reader -The physical device that reads an item for its UID and works with the customer instance to confirm a UID is legitimate. For lookup the customer instance acts a proxy to other customers in the cloud to answer the question rather than using itself to answer the question.
[0113] Site Controller - The software running locally on a customer site that interfaces between all site readers (binding, verification & lookup) and acts as a conduit to the customer instance software in the cloud (or on-premise). If the site controller is not deployed then all readers communicate directly with the Cloud Controller. A primary function of the site controller is robustness / reliability in case of internet delays / outages where the site controller can provide certain queued functions. The site controller will replicate most of the main functions of the customer instance but will do it for a subset of the functions provided in the cloud. The site controller can provide the following functionality:1) Caching of customer UIDs storage so that the site controller can provide local verification answers without having to ping the cloud each time.2) Can store binding submissions if cloud offline, that are subsequently sent to the cloud upon reconnection.3) Queues all binding / verification requests to the cloud for both reliability and potentially performance / scaling throttling as signified by the Customer Instance.4) Eventually maintains local cache of site specific UIDs, which can be generated over time during system operation.5) Provides sync between cloud and site controller for the predetermined UID data (e.g., a database). Support running as background process on Linux and support TLS server (for the readers to talk to) and TLS client (to the cloud). Must support X.509 Certificate mutual authentication (e.g., using X.509 Certificates) for both readers and cloud communication authentication.
[0114] The following examples of FIGS. 19-21 provide descriptions of the business solutions that can be implemented using the systems and methods described herein.Example 1 : Handbag Manufacturer and Supplier (FIG. 19)
[0115] Background: A high-end handbag manufacturer, supplier and distributor wishes to use the systems and methods described herein to identify and track handbags. The handbags are produced on their behalf by a manufacturing sub-contractor in one region of the world, handbags arc then shipped from the manufacturer to a US-based distribution center. The distribution center then distributes directly to the handbag manufacturer premium outlets and affiliated premium outlets that are not directly owned by the handbag manufacturer throughout the US.
[0116] There are 4 points through this supply chain that the systems and methods herein can support.Point 1: Non-US-based sub-contractor manufacturing handbags can implement unique ID binding.- This point requires the UID Bind use case where an entity associates a UID with a manufactured item- Additional integration with the sub-contractor's chosen supply chain software may be required (e.g. to indicate a produced item is ready to ship to the US distributor, track production line materials projections. . .etc.) and / or to the Handbag Manufacturer who is the owner / sponsor of this supply chain.Point 2: US -based distribution center verification of received goods from sub-contractor- This point requires the UID Verification use case where an entity verifies the item received is a legitimate UID associated with the manufacturer- Additional integration with the manufacturer’s chosen supply chain software tracking is likely required (e.g. to update an item has been received in the distribution center)Point 3: US-based handbag manufacturer-owned premium outlet verification of received goods from distribution center- This point requires the UID Verification use case where an entity verifies the received item from the distribution supplier is a legitimate UID associated with the manufacturer.- Additional integration with the manufacturer’s chosen supply chain store software tracking is likely required (e.g., to update an item that has been received from the distribution center, when, by whom. . .etc.).Point 4: US-based affiliated premium outlet verification of received goods from distribution center- This point requires the UID Lookup use case where an affiliate verifies the received item from the distribution supplier is a legitimate UID associated with the originating manufacturer.- Additional integration with the affiliate’s chosen supply chain software tracking is likely required (e.g. to update an item has been received for the store's inventory system and ready for sale).- Additional integration with the manufacturer’s chosen supply chain software tracking is likely required (e.g. to update an item has been received by the affiliate and is no longer part of the manufacturer’s distribution system)Example 2: Parts Manufacturer and Supplier (FIG. 20)
[0117] Background: An aircraft part manufacturer and supplier wish to use the systems and method herein to identify and track high value aircraft parts. The aircraft parts are produced on their behalf by a manufacturer in one US state, parts are then shipped from the manufacturer to the plane manufacturer in another US state for assembly of the plane. Further where parts are shipped by either organization to an airline maintenance facility, or a maintenance facility under contract to the airline.
[0118] There are 2 points through this supply chain that can utilize the systems and methods described herein support.Point 1: Manufacturing of Aircraft Parts unique ID binding and verification.This point requires both the UID Bind and UID Verify use cases where an entity associates a UID with a manufactured item and checks the item prior to shipment to the plane manufacturer. They also scan the item upon shipment tracking.Additional integration with the Parts Manufacturer chosen supply chain software may be required (e.g., to indicate a produced item is ready to ship to the US plane manufacturer, track production line materials projections. . .etc.).Point 2: Plane manufacturer verification of received goods from Parts ManufacturerThis point requires the UID Lookup use case where an entity verifies the item received is a legitimate UID associated with the parts manufacturerAdditional integration with the plane manufacturer’s chosen supply chain software tracking is likely required (e.g., to update an item that has been received from the parts manufacturer).Example 3: Government Equipment Tracking (FIG. 21)
[0119] Background: A military government entity wishes to add UIDs to weapons that it tracks and provides to military agents using systems and methods described herein to identify and track those items but has strict requirements on software supporting this use case. All software must be installed, deployed, provisioned and operated by the military government entity.
[0120] There are 3 points through this supply chain that can utilize systems and methods described herein. Operational responsibility is performed by the Military Government entity.Point 1: Military government - weapon producer binds the UID to the weapon being tracked This point requires the UID Bind use case where an entity associates a UID with a weaponAdditional integration with the military government entity chosen supply chain software may be required (e.g. to indicate a tracked item is ready to ship to other government entities receiving the items, track production line materials projections. . .etc.)Point 2: Military government - weapon producer verification of received weapons during distributionThis point requires the UID Verification use case where an entity verifies the item received is a legitimate UID (i.e. weapon) associated with the weapon’ s producer Additional integration with the weapon producer’s chosen supply chain software tracking is likely required (e.g. to update an item has been received in the distribution center)Point 3: Military government - Weapon user lookup of received weapons from weapon producerThis point requires the UID Lookup use case where a weapon user verifies the received weapon from the weapon producer supplier is a legitimate UID associated with the originating weapon producerEXAMPLE EMBODIMENTS:
[0121] In view of the foregoing, the following includes a set of numbered examples numbered 1-75 that can be implemented in the context of the systems and methods shown and described herein.1. A system includes a reader and a computing system. The reader provides unclonable identifier (UID) data that includes spectra data representative of at least one optical spectrum measured from a portion of a physical object that includes a physicallyunclonable function (PUF). The computing system includes non- transitory memory and one or more processors. The non-transitory memory stores instructions and data. The one or more processors are coupled to the memory and the instructions, when executed by the one or more processors, cause the one or more processors to at least: receive the UID data; execute a compare function to determine a unique identifier, authenticity, and / or provenance of the physical object based on the received UID data and predetermined UID data in a data store; provide results data indicative of the unique identifier, authenticity, and / or provenance of the physical object; and send the results data to the reader, in which the reader is configured to provide a uscr-pcrccptiblc output specifying the unique identifier, authenticity, and / or provenance of the physical object based on the results data.2. The system of example 1, wherein the portion of a physical object is a first portion of the physical object. The reader includes a spectrometry apparatus configured to acquire at least one measure of electromagnetic transmission and / or reflection spectrum or spectra for the first portion of the physical object, which defines the spectra data. The reader also includes an optical imaging apparatus configured to acquire an optical image of at least a second portion of the physical object and provide image data, in which the second portion is the same or different from the first portion of the physical object. The UID data includes the spectra data and the image data.3. The system of example 2, wherein the spectrometry apparatus collects a number of measurements of the electromagnetic transmission and / or reflection spectrum or spectra for the first portion of the physical object. The reader is configured to combine at least some of the measurements of the electromagnetic transmission and / or reflection spectrum or spectra and provide an aggregate measure of the electromagnetic transmission and / or reflection spectrum or spectra. The spectra data of the UID data includes the aggregate measure of the electromagnetic transmission and / or reflection spectrum or spectra.4. The system according to example 2 or 3, wherein the instructions to execute the compare function, further include instructions to determine the unique identifier, authenticity, and / or provenance of the physical object based on the image data and the spectra data, which are included in the received UID data, and based on predetermined UID data that includes and / or is derived from predetermined spectra data and predetermined image data.5. The system according to example 2 or 3, wherein the instructions to execute the compare function, further include instractions to divide the measure of theelectromagnetic transmission and / or reflection spectrum or spectra into a plurality of discrete spectra features. The instructions further can assign a respective spectra feature value to each of the discrete spectra features based on attributes of the respective spectra feature. The instractions further can match, to within a threshold, at least some of the spectra features with predetermined spectra features based on comparing the respective spectra feature values with predetermined spectra feature values that are stored in the data store.6. The system of example 5, wherein the threshold is a first threshold that is configurable responsive to a user input instruction. Also, or as an alternative, the instructions can cause the one or more processors to execute the compare function further to, based on the match, return a list of one or more predetermined images from the data store. The instractions further can further cause the one or more processors to execute an image match function, to within an image match threshold, for each of the one or more predetennined images in the returned list based on a comparison of each of the one or more predetermined images with the optical image of at least the second portion of the physical object to identify a closest image match.7. The system according to example 5 or 6, wherein the data store includes a vector database, in which the vector database stores spectra feature vectors in multidimensional vector space. Each of the spectra feature vectors has one or more values, defining spectra vector embeddings, representative of the predetermined spectra feature values. Each of the predetermined spectra feature values of a given spectra feature vector is representative of one or more attributes of one or more spectra features extracted from a corresponding measure of electromagnetic transmission and / or reflection spectrum or spectra for a respective PUF.8. The system according to example 6 or 7, wherein the image match function includes instractions to divide the optical image of at least the second portion of the physical object into a plurality of discrete images having respective image feature values. The instractions further can compute a confidence score, with respect to a confidence threshold, based on a comparison of at least some of the respective image feature values for the optical image and image feature values determined for each of the one or more predetermined images.9. The system according to example 8, wherein the data store includes an image vector database, in which the image vector database stores image feature vectors in multidimensional vector space. Each of the stored image feature vectors has a number of image feature values, defining image vector embeddings. Each of the image featurevalues of a given one of the stored image feature vectors is representative of one or more attributes of one or more image features extracted from a corresponding image of a respective second portion of a known physical object.10. The system of example 5, wherein the plurality of discrete spectra features into which the measure of the electromagnetic transmission and / or reflection spectrum or spectra is divided include respective wavelengths. The compare function is configured to match at least some of the spectra features with the predetermined spectra features that are divided into at least some of the same respective wavelengths.11. The system of example 10, wherein the compare function is further programmed to cause the one or more processors to perform a comparison of the UID data across all spectra features of UID data that are stored in the data store. The instructions further can cause the one or more processors to compute a confidence value based on each comparison. The instructions further can cause the one or more processors to determine if the UID data matches any stored UID data with a based on the confidence value exceeding a threshold.12. The system according to any one of the preceding examples, wherein the UID data further includes reader profile data, defining physical and / or logical attributes of the reader, to identify the reader within the system. The predetermined UID data in the data store includes a multitude of predetermined UID data sets, and each UID data set is associated with at least one of a known physical object or a known PUF. For example, the reader profile can define a type of reader that is associated with physical and logical attributes of the reader and how it performs its function.13. The system of example 12, wherein the instructions further cause the one or more processors to, based on the reader profile data, filter the predetermined UID data sets in the data store to provide a subset of the predetermined UID data sets. The compare function can be executed with respect to each of the UID data in the subset of the predetermined UID data sets.14. The system of example 12, wherein the instructions further cause the one or more processors to, based on the reader profile data, perform an indexed query of the predetermined UID data sets, in which the predetermined UID data sets in the data store are indexed based on profile data.15. The system according to any one of examples 12, 13, or 14, wherein the reader profile data is programmable and further includes an operator identifier and metadata, in which the operator identifier is based on an identity of a user of the reader. The metadata can include information representative of at least one of a transactiontimestamp for the UID data, physical location of the reader, and logical location of the reader.16. The system according to any one of examples 1 through 11, wherein the reader is configured to bind the UID data with attributes of the reader including at least one of (a) a unique identifier for the reader, (b) a transaction timestamp, (c) a geographic location of the transaction, (d) logical network location, and / or (e) operator data to provide bound UID data. The reader can be configured to send the bound UID data over a secure communications link to the computing system.17. The system according to any one of examples 1 through 11, wherein the reader is configured to bind the UID data with biometric and / or other data uniquely identifying an operator of the reader to provide bound UID data, in which the operator has been authenticated and authorized to perform the operation on the reader. The reader can be configured to send the bound UID data over a secure communications link to the computing system.18. The system according to any one of the preceding examples, wherein the reader is authenticated and authorized, locally and / or remotely, to perform measurement operations on behalf of an organizational entity who owns and / or controls an instance of the computing system.19. The system of example 18, wherein an operator of the reader is authenticated and authorized, locally and / or remotely, to perform the measurement operations on the authenticated and authorized reader.20. The system according to any one of the preceding examples, wherein the received UID data does not include information describing or identifying the physical object, a supply chain in which the physical object is shipped, and an owner or manufacturer of the physical object.21. The system according to any one of the preceding examples, wherein the portion or the first portion of the physical object that includes the PUF includes a disordered multilayer photonic crystal structure encoding data representative of the UID.22. The system of example 21, wherein the photonic crystal structure includes a polymer film attached to the physical object or embedded within the physical object.23. The system of example 22, wherein the polymer film includes one or more markers on or incorporated within the polymer film.24. The system of example 23, wherein the one or more markers include a randomly generated non-sequential number that is associated with a batch of thepolymer film, a defined image that is assoeiated with the batch of him producing the polymer him UID, and / or an optical feature.25. The system of example 23 or 24, wherein marker data is produced to encode each marker and / or PUF with which the respective marker is associated, and the marker data is securely captured and saved cryptographically in the data store as part of the predetermined UID data.26. The system according to any one of examples 23, 24, or 25, wherein the reader is configured to capture each of markers within the portion or the first portion of the physical object that includes the PUF, and provide captured marker data that is included as part of the UID data, which is sent to the computing system.27. The system of example 25, wherein the instructions further cause the one or more processors to perform a marker comparison of the marker data across all marker data that are stored in the data store and compute a confidence value based on each marker comparison. The instructions further cause the one or more processors to, based on determining that the confidence value does not exceed a confidence threshold, return the results data specifying a negative match indicative of failing to specify the identity, authenticity, and / or provenance for the physical object.28. The system of example 27, wherein the predetermined UID data in the data store includes a multitudinous of predetermined UID data sets, each UID data set is associated with at least one of a known physical object or a known PUF.Based on determining that the confidence value exceeds the confidence threshold, the instructions further cause the one or more processors to determine a marker categorization based on the marker data, and filter the predetermined UID data sets in the data store based on the determined marker categorization to provide a subset of the predetermined UID data sets having the determined marker categorization. The compare function further can be executed with respect each of the UID data in the subset of the predetermined UID data sets.29. The system according to any one of the preceding examples, further including a plurality of instances of the computing system, in which each instance of the computing system has an associated data store and is associated a respective organizational entity.30. The system of example 29, wherein based on determining that the received UID data fails to match the predetermined UID data in the data store, the instructions further cause the one or more processors to create a binding between the received UIDdata set and the physical object, defining a bound data set, and store the bound data set in the data store.31. The system of example 30, wherein based on determining that the received UID data matches the predetermined UID data in the data store, the instructions enable the one or more processors to cause the results data to be returned to the reader.32. The system according to any one of examples 29, 30, or 31, wherein the reader performing the measurement belongs to the same organizational entity that operates and / or controls the instance of the computing system and associated data store.33. The system of example 29, wherein each instance of the computing system and the associated data store includes rules data that defines policies to allow or deny searches from one or more other organizational entities.34. The system of example 33, wherein the reader performing the measurement belongs to a different organizational entity than the organization entity that operates and / or controls a given instance of the computing system and the associated data store. Further, responsive to the given instance of the computing system receiving a request from the reader of the different organizational entity store, corresponding instructions can cause the one or more processors of the given instance of the computing system to allow processing of the UID data by the respective compare function and provide corresponding results data back to the reader based on the rules data.35. The system of example 33, wherein the reader performing the measurement belongs to a different organizational entity than the organization entity that operates and / or controls a given instance of the computing system and the associated data store. Further, responsive to the given instance of the computing system receiving a request from the reader of the different organizational entity store, corresponding instructions can cause the one or more processors of the given instance of the computing system to allow to the compare function to search for match but not provide corresponding results data to the reader.36. The system of example 33, wherein the reader performing the measurement belongs to a different organizational entity than the organization entity that operates and / or controls a given instance of the computing system and the associated data store. Further, responsive to the given instance of the computing system receiving a request from the reader of the different organizational entity store, corresponding instructions can cause the one or more processors of the given instance of the computing system to allow to the compare function to search for match and return a different set of results tothe different organizational entity than would be returned to organizational entity to which the reader performing the measurement belongs.37. The system according to any preceding example, further including further instructions to cause the one or more processors to bind operational transaction data, which includes and / or is associated with the received UID data, to an external verification network, in which the external verification network includes an immutable transaction data store. The instructions further cause the one or more processors to send the operational transaction data to the external verification network through a communication link. A response can be received from the external verification network that can include information representative of at least one of an identity of the physical object, an authenticity of the physical object, a provenance of the physical object, a description of the physical object, a description and / or information associated with an organization entity. The reader is further configured to provide the user-perceptible output specifying the unique identifier, authenticity, and / or provenance of the physical object based on the results data and / or the response from the external verification network.38. A method includes receiving, by one or more processors at a computing system, unclonable identifier (UID) data, in which the UID data includes spectra data representative of at least one optical spectrum measured by a reader from a portion of a physical object that includes a physically unclonable function (PUT). The method also includes determining, by the one or more processors, a unique identifier, authenticity, and / or provenance of the physical object based on a comparison of the received UID data and predetermined UID data stored in a data store. The method also includes generating results data indicative of the unique identifier, authenticity and / or provenance of the physical object and sending the results data to the reader. The reader can be configured to provide a user-perceptible output specifying the unique identifier, authenticity, and / or provenance of the physical object based on the results data.39. The method of example 38, wherein the portion of a physical object is a first portion of the physical object, and the method also includes acquiring, by a spectrometry apparatus of the reader, at least one measure of electromagnetic transmission and / or reflection spectrum or spectra for the first portion of the physical object, which defines the spectra data. The method can also include acquiring, by an optical imaging apparatus of the reader, an optical image of at least a second portion of the physical object and provide image data, in which the second portion is the same or different from the first portion of the physical object. The UID data can include the spectra data and the image data.40. The method of example 39, wherein the spectrometry apparatus collects a number of measurements of the electromagnetic transmission and / or reflection spectrum or spectra for the first portion of the physical object. The reader is configured to combine at least some of the measurements of the electromagnetic transmission and / or reflection spectrum or spectra and provide an aggregate measure of the electromagnetic transmission and / or reflection spectrum or spectra. The spectra data of the UID data can include the aggregate measure of the electromagnetic transmission and / or reflection spectrum or spectra.41. The method according to example 39 or 40, wherein determining the unique identifier, authenticity, and / or provenance of the physical object is based on the image data and the spectra data, which are included in the received UID data, and based on predetermined UID data that includes and / or is derived from predetermined spectra data and predetermined image data.42. The method according to example 39 or 40, wherein determining the unique identifier, authenticity and / or provenance of the physical object further includes dividing the measure of the electromagnetic transmission and / or reflection spectrum or spectra into a plurality of discrete spectra features and assigning a respective spectra feature value to each of the discrete spectra features based on attributes of the respective spectra feature. The method can also include matching, to within a threshold, at least some of the spectra features with predetermined spectra features based on comparing the respective spectra feature values with predetermined spectra feature values that are stored in the data store.43. The method of example 42, wherein determining the unique identifier, authenticity, and / or provenance of the physical object further includes based on the match, returning a list of one or more predetermined images from the data store. The method can also include performing an image match function for each of the one or more predetermined images in the returned list based on a comparison of each of the one or more predetermined images with the optical image of at least the second portion of the physical object to identify a closest image match.44. The method according to example 42 or 43, wherein the data store includes a vector database, in which the vector database stores spectra feature vectors in multidimensional vector space. Each of the spectra feature vectors has one or more values, defining spectra vector embeddings, representative of the predetermined spectra feature values. Each of the predetermined spectra feature values of a given spectra feature vector can be representative of one or more attributes of one or more spectra features extractedfrom a corresponding measure of electromagnetic transmission and / or reflection spectrum or spectra for a respective PUF.45. The method according to example 43 or 44, wherein executing the image match function further includes dividing, by the one or more processors, the optical image of at least the second portion of the physical object into a plurality of discrete images having respective image feature values. The method can also include computing, by the one or more processors, a confidence score based on a comparison of at least some of the respective image feature values for the optical image and image feature values determined for each of the one or more predetermined images.46. The method according to example 45, wherein the data store includes an image vector database, in which the image vector database stores image feature vectors in multidimensional vector space and ach of the stored image feature vectors has a number of image feature values, defining image vector embeddings. Each of the image feature values of a given one of the stored image feature vectors is representative of one or more attributes of one or more image features extracted from a corresponding image of a respective second portion of a known physical object.47. The method of example 42, wherein the plurality of discrete spectra features into which the measure of the electromagnetic transmission and / or reflection spectrum or spectra is divided include respective wavelengths. The method further includes matching, by the one or more processors, at least some of the spectra features with the predetermined spectra features that are divided into at least some of the same respective wavelengths.48. The method of example 47, further including comparing, by the one or more processors, the UID data across all spectra features of UID data that are stored in the data store. The method can also include computing, by the one or more processors, a confidence value based on each comparison. The method can also include determining, by the one or more processors, if the UID data matches any stored UID data based on the confidence value exceeding a threshold.49. The method according to any one of examples 38-48, wherein the UID data further includes reader profile data, defining physical and / or logical attributes of the reader, to identify the reader within the system. The predetermined UID data in the data store can include a multitude of predetermined UID data sets, each UID data set is associated with at least one of a known physical object or a known PUF.50. The method of example 49, further including based on the reader profile data, filtering, by the one or more processors, the predetermined UID data sets in the datastore to provide a subset of the predetermined UID data sets, wherein the comparison of the received UID data and predetermined UID data is performed with respect each of the UID data in the subset of the predetermined UID data sets.51. The method of example 49, further including based on the reader profile data, performing an indexed query of the predetermined UID data sets, in which the predetermined UID data sets in the data store are indexed based on profile data.52. The method according to any one of examples 49, 50, or 51, wherein the reader profile data is programmable and further includes an operator identifier and metadata, in which the operator identifier is based on an identity of a user of the reader, and the metadata includes information representative of at least one of a transaction timestamp for the UID data, physical location of the reader, and logical location of the reader.53. The method according to any one of examples 38 through 48, wherein the reader is configured to bind the UID data with at least one of (a) a unique identifier for the reader, (b) a transaction timestamp, (c) a geographic location for the transaction, (d) logical network location, and / or (e) operator data to provide bound UID data, and the reader is configured to send the bound UID data over a secure communications link to the computing system.54. The method according to any one of examples 38 through 48, wherein the reader is configured to bind the UID data with biometric and / or other data uniquely identifying an operator of the reader to provide bound UID data, in which the operator has been authenticated and authorized to perform the operation on the reader. The reader can be configured to send the bound UID data over a secure communications link to the computing system.55. The method according to any one of examples 38 through 54, further including authenticating and authorizing the reader, locally and / or remotely, to perform measurement operations on behalf of an organizational entity that owns and / or controls an instance of program code executing the method.56. The method of example 55, further including authenticating and authorizing an operator of the reader, locally and / or remotely, to perform the measurement operations on the authenticated and authorized reader.57. The method according to any one of examples 38 through 56, wherein the received UID data does not include information describing or identifying the physical object, a supply chain in which the physical object is shipped, and an owner or manufacturer of the physical object.58. The method according to any one of examples 38 through 57, wherein the portion or the first portion of the physical object that includes the PUF includes a disordered multilayer photonic crystal structure encoding data representative of the UID.59. The method of example 58, wherein the photonic crystal structure includes a polymer him attached to the physical object or embedded within the physical object.60. The method of example 59, wherein the polymer film includes one or more markers on or incorporated within the polymer film.61. The method of example 60, wherein the one or more markers include a randomly generated non-scqucntial number that is associated with a batch of the polymer film, a defined image that is associated with the batch of him producing the polymer him UID, and / or an optical feature.62. The method of example 60 or 61, wherein marker data is produced to encode each marker and / or PUF with which the respective marker is associated, and the marker data is securely captured and saved cryptographically in the data store as part of the predetermined UID data.63. The method according to any one of examples 60, 61, or 62, further including capturing, by the reader, each of markers within the portion or the first portion of the physical object that includes the PUF. The method can also include providing captured marker data that is included as part of the UID data that is received at the computing system.64. The method of example 62, further including performing, by the one or more processors, a marker comparison of the marker data across all marker data that are stored in the data store and computing, by the one or more processors, a confidence value based on each marker comparison. The method can also include, based on determining that the confidence value does not exceed a confidence threshold, causing the one or more processors to return the results data specifying a negative match indicative of failing to specify the unique identifier, authenticity, and / or provenance for the physical object.65. The method of example 64, wherein the predetermined UID data in the data store includes a multitude of predetermined UID data sets, in which each UID data set is associated with at least one of a known physical object or a known PUF. The method can also include, based on determining that the confidence value exceeds the confidence threshold, determining a marker categorization based on the marker data. The predetermined UID data sets in the data store can be filtered based on the determined marker categorization to provide a subset of thepredetermined UID data sets having the determined marker categorization, and the comparison of the received UID data and predetermined UID data is performed with respect each of the UID data in the subset of the predetermined UID data sets.66. The method according to any one of the examples 38 through 65, wherein an instance of the method is performed at each of a plurality of instances of the computing system, in which each instance of the computing system has an associated data store and is associated with a respective one of a plurality of organizational entities.67. The system of example 66, wherein based on determining that the received UID data fails to match the predetermined UID data in the data store, the method further includes creating, by the one or more processors, a binding between the received UID data set and the physical object and defining a bound data set based on the created binding. The bound data set can be stored in the data store.68. The method of example 67, wherein based on determining that the received UID data matches the predetermined UID data in the data store, the method further includes enabling the computing system to return the results data to the reader.69. The method according to any one of examples 66, 67, or 68, wherein the reader performing the measurement belongs to the same organizational entity that operates and / or controls the instance of the computing system and associated data store.70. The method of example 69, wherein each instance of the computing system and the associated data store includes rules data that defines policies to allow or deny searches from one or more other organizational entities.71. The method of example 70, wherein the reader performing the measurement belongs to a different organizational entity than the organization entity that operates and / or controls a given instance of the computing system and the associated data store. Responsive to the given instance of the computing system receiving a request from the reader of the different organizational entity store, the method can include, based on the rules data, causing the one or more processors of the given instance of the computing system to allow matching of the received UID data and providing corresponding results data back to the reader.72. The method of example 70, wherein the reader performing the measurement belongs to a different organizational entity than the organization entity that operates and / or controls a given instance of the computing system and theassociated data store. Responsive to the given instance of the computing system receiving a request from the reader of the different organizational entity, the method can further include, based on the rules data, causing the one or more processors of the given instance of the computing system to allow searching for match but not providing corresponding results data to the reader.73. The method of example 70, wherein the reader performing the measurement belongs to a different organizational entity than the organization entity that operates and / or controls a given instance of the computing system and the associated data store. Responsive to the given instance of the computing system receiving a request from the reader of the different organizational entity store, the method further can include, based on the rules data, causing the one or more processors of the given instance of the computing system to allow searching for a match and returning a different set of results to the different organizational entity than would be returned to organizational entity to which the reader performing the measurement belongs.74. The method according to any one of the examples 38 through 73, further including binding operational transaction data, which includes and / or is associated with the received UID data, to an external verification network, in which the external verification network includes an immutable transaction data store. The method can also include sending the operational transaction data to the external verification network through a communication link. The method can also include receiving a response from the external verification network that includes information representative of at least one of an identity of the physical object, an authenticity of the physical object, a provenance of the physical object, a description of the physical object, a description and / or information associated with an organization entity. The reader is further configured to provide the user-perceptible output specifying the unique identifier, authenticity, and / or provenance of the physical object based on the results data and / or the response from the external verification network75. One or more non-transitory computer readable medium having instructions, which when executed by one or more processors cause the processor to perform the method according to any one of examples 38 through 74.
[0122] As will be appreciated by those skilled in the art, portions of the systems and methods disclosed herein may be embodied as a method, data processing system, or computer program product (e.g., a non-transitory computer readable medium having instructions executable by a processor). Accordingly, these portions of the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combiningsoftware and hardware. Furthermore, portions of the invention may be a computer program product on a computer-usable storage medium having computer readable program code on the medium. Any suitable computer-readable medium may be utilized including, but not limited to, static and dynamic storage devices, hard disks, optical storage devices, and magnetic storage devices.
[0123] Certain embodiments are disclosed herein with reference to flowchart illustrations of methods, systems, and computer program products. It will be understood that blocks of the illustrations, and combinations of blocks in the illustrations, can be implemented by computerexecutable instructions. These computer-executable instructions may be provided to one or more processors of a general purpose computer, special purpose computer, or other programmable data processing apparatus (or a combination of devices and circuits) to produce a machine, such that the instructions, which execute via the processor, implement the functions specified in the block or blocks.
[0124] These computer-executable instructions may also be stored in a non-transitory computer-readable medium that can direct a computer or other programmable data processing apparatus (e.g., one or more processing core) to function in a particular manner, such that the instructions stored in the computer-readable medium result in an article of manufacture including instructions which implement the function specified in the flowchart block or blocks. The computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks or the associated description.
[0125] What are disclosed herein are examples. It is, of course, not possible to describe every conceivable combination of components or methods, but one of ordinary skill in the art will recognize that many further combinations and permutations are possible. Accordingly, the disclosure is intended to embrace all such alterations, modifications, and variations that fall within the scope of this application, including the appended claims. All references, publications, and patents cited in the present application are herein incorporated by reference in their entirety.
Claims
CLAIMS1. A system comprising: a reader that provides unclonable identifier (UID) data that includes spectra data representative of at least one optical spectrum measured from a portion of a physical object that includes a physically unclonable function (PUF); a computing system comprising: non-transitory memory that stores instructions and data; and one or more processors coupled to the memory, in which the instructions, when executed by the one or more processors, cause the one or more processors to at least: receive the UID data; execute a compare function to determine a unique identifier, authenticity, and / or provenance of the physical object based on the received UID data and predetermined UID data in a data store; provide results data indicative of the unique identifier, authenticity, and / or provenance of the physical object; and send the results data to the reader, in which the reader is configured to provide a user- perceptible output specifying the unique identifier, authenticity, and / or provenance of the physical object based on the results data.
2. The system of claim 1, wherein the portion of a physical object is a first portion of the physical object, and the reader comprises: a spectrometry apparatus configured to acquire at least one measure of electromagnetic transmission and / or reflection spectrum or spectra for the first portion of the physical object, which defines the spectra data; and an optical imaging apparatus configured to acquire an optical image of at least a second portion of the physical object and provide image data, in which the second portion is the same or different from the first portion of the physical object, wherein the UID data includes the spectra data and the image data.
3. The system of claim 2, wherein the spectrometry apparatus collects a number of measurements of the electromagnetic transmission and / or reflection spectrum or spectra for the first portion of the physical object,the reader is configured to combine at least some of the measurements of the electromagnetic transmission and / or reflection spectrum or spectra and provide an aggregate measure of the electromagnetic transmission and / or reflection spectrum or spectra, and the spectra data of the UID data includes the aggregate measure of the electromagnetic transmission and / or reflection spectrum or spectra.
4. The system according to claim 2 or 3, wherein the instructions to execute the compare function, further comprise instructions to: determine the unique identifier, authenticity, and / or provenance of the physical object based on the image data and the spectra data, which are included in the received UID data, based on predetermined UID data that includes and / or is derived from predetermined spectra data and predetermined image data.
5. The system according to claim 2 or 3, wherein the instructions to execute the compare function, further comprise instructions to: divide the measure of the electromagnetic transmission and / or reflection spectrum or spectra into a plurality of discrete spectra features; assign a respective spectra feature value to each of the discrete spectra features based on attributes of the respective spectra feature: and match, to within a threshold, at least some of the spectra features with predetermined spectra features based on comparing the respective spectra feature values with predetermined spectra feature values that are stored in the data store.
6. The system of claim 5, wherein the threshold is a first threshold that is configurable responsive to a user input instruction, and / or wherein the instructions to execute the compare function, further comprise instructions to: based on the match, return a list of one or more predetermined images from the data store; and execute an image match function, to within an image match threshold, for each of the one or more predetermined images in the returned list based on a comparison of each of the one or more predetermined images with the optical image of at least the second portion of the physical object to identify a closest image match.
7. The system according to claim 5 or 6, wherein the data store comprises a spectra feature database, in which the spectra feature database stores spectra feature vectors in multidimensional vector space, each of the spectra feature vectors has one or more values, defining spectra vector embeddings, representative of the predetermined spectra feature values, each ofthe predetermined spectra feature values of a given spectra feature vector is representative of one or more attributes of one or more spectra features extracted from a corresponding measure of electromagnetic transmission and / or reflection spectrum or spectra for a respective PUF.
8. The system according to claim 6 or 7, wherein the image match function comprises instructions to: divide the optical image of at least the second portion of the physical object into a plurality of discrete images having respective image feature values; and compute a confidence score, with respect to a confidence threshold, based on a comparison of at least some of the respective image feature values for the optical image and image feature values determined for each of the one or more predetermined images.
9. The system according to claim 8, wherein the data store comprises an image vector database, in which the image vector database stores image feature vectors in multi-dimensional vector space, each of the stored image feature vectors has a number of image feature values, defining image vector embeddings, each of the image feature values of a given one of the stored image feature vectors is representative of one or more attributes of one or more image features extracted from a corresponding image of a respective second portion of a known physical object.
10. The system of claim 5, wherein the plurality of discrete spectra features into which the measure of the electromagnetic transmission and / or reflection spectrum or spectra is divided include respective wavelengths, and the compare function is configured to match at least some of the spectra features with the predetermined spectra features that are divided into at least some of the same respective wavelengths.1 1 . The system of claim 10, wherein the compare function is further programmed to cause the one or more processors to: perform a comparison of the received UID data across all spectra features of UID data that are stored in the data store; compute a confidence value based on each comparison; and determine if the UID data matches any stored UID data with a based on the confidence value exceeding a threshold.
12. The system according to any one of the preceding claims, wherein the received UID data further comprises reader profile data, defining physical and / or logical attributes of the reader, to identify the reader within the system, the predetermined UID data in the data storecomprises a multitudinous of predetermined UID data sets, each UID data set is associated with at least one of a known physical object or a known PUF.
13. The system of claim 12, wherein the instructions further cause the one or more processors to: based on the reader profile data, filter the predetermined UID data sets in the data store to provide a subset of the predetermined UID data sets, wherein the compare function is executed with respect to each of the UID data in the subset of the predetermined UID data sets.
14. The system of claim 12, wherein the instructions further cause the one or more processors to: based on the reader profile data, perform an indexed query of the predetermined UID data sets, in which the predetermined UID data sets in the data store are indexed based on profile data.
15. The system according to any one of claims 12, 13, or 14, wherein the reader profile data is programmable and further includes an operator identifier and metadata, in which the operator identifier is based on an identity of a user of the reader, and the metadata includes information representative of at least one of a transaction timestamp for the UID data, physical location of the reader, and logical location of the reader.
16. The system according to any one of claims 1 through 11, wherein the reader is configured to bind the UID data with attributes of the reader including at least one of (a) a unique identifier for the reader, (b) a transaction timestamp, (c) a geographic location of the transaction, (d) logical network location, and / or (e) operator data to provide bound UID data, and the reader is configured to send the bound UID data over a secure communications link to the computing system.
17. The system according to any one of claims 1 through 11, wherein the reader is configured to bind the UID data with biometric and / or other data uniquely identifying an operator of the reader to provide bound UID data, in which the operator has been authenticated and authorized to perform the operation on the reader, and the reader is configured to send the bound UID data over a secure communications link to the computing system.
18. The system according to any one of the preceding claims, wherein the reader is authenticated and authorized, locally and / or remotely, to perform measurement operations on behalf of an organizational entity who owns and / or controls an instance of the computing system.
19. The system of claim 18, wherein an operator of the reader is authenticated and authorized, locally and / or remotely, to perform the measurement operations on the authenticated and authorized reader.
20. The system according to any one of the preceding claims, wherein the received UID data does not include information describing or identifying the physical object, a supply chain in which the physical object is shipped, and an owner or manufacturer of the physical object.
21. The system according to any one of the preceding claims, wherein the portion or the first portion of the physical object that includes the PUF comprises a disordered multilayer photonic crystal stmcture encoding data representative of the UID.
22. The system of claim 21, wherein the photonic crystal stmcture comprises a polymer film attached to the physical object or embedded within the physical object.
23. The system of claim 22, wherein the polymer film includes one or more markers on or incorporated within the polymer film.
24. The system of claim 23, wherein the one or more markers include a randomly generated non-sequential number that is associated with a batch of the polymer him, a defined image that is associated with the batch of him producing the polymer him UID, and / or an optical feature.
25. The system of claim 23 or 24, wherein marker data is produced to encode each marker and / or PUF with which the respective marker is associated, and the marker data is securely captured and saved cryptographically in the data store as part of the predetermined UID data.
26. The system according to any one of claims 23, 24, or 25, wherein the reader is configured to capture each of markers within the portion or the first portion of the physical object that includes the PUF, and provide captured marker data that is included as part of the UID data that is received by the computing system.
27. The system of claim 25, wherein the instructions further cause the one or more processors to: perform a marker comparison of the marker data across all marker data that are stored in the data store; compute a confidence value based on each marker comparison; and based on determining that the confidence value does not exceed a confidence threshold, return the results data specifying a negative match indicative of failing to specify the identity, authenticity, and / or provenance for the physical object.
28. The system of claim 27, wherein the predetermined UID data in the data store comprises a multitudinous of predetermined UID data sets, each UID data set is associated with at least one of a known physical object or a known PUF, and wherein based on determining that the confidence value exceeds the confidence threshold, the instructions further cause the one or more processors to: determine a marker categorization based on the marker data. filter the predetermined UID data sets in the data store based on the determined marker categorization to provide a subset of the predetermined UID data sets having the determined marker categorization, wherein the compare function is executed with respect each of the UID data in the subset of the predetermined UID data sets.
29. The system according to any one of the preceding claims, further comprising a plurality of instances of the computing system, in which each instance of the computing system has an associated data store and is associated a respective organizational entity.
30. The system of claim 29, wherein based on determining that the received UID data fails to match the predetermined UID data in the data store, the instructions further cause the one or more processors to create a binding between the received UID data set and the physical object, defining a bound data set, and store the bound data set in the data store.
31. The system of claim 30, wherein based on determining that the received UID data matches the predetermined UID data in the data store, the instructions enable the one or more processors to cause the results data to be returned to the reader.
32. The system according to any one of claims 29, 30, or 31, wherein the reader performing the measurement belongs to the same organizational entity that operates and / or controls the instance of the computing system and associated data store.
33. The system of claim 29, wherein each instance of the computing system and the associated data store includes rules data that defines policies to allow or deny searches from one or more other organizational entities.
34. The system of claim 33, wherein the reader performing the measurement belongs to a different organizational entity than the organization entity that operates and / or controls a given instance of the computing system and the associated data store, wherein responsive to the given instance of the computing system receiving a request from the reader of the different organizational entity store, corresponding instructions cause the one or more processors of the given instance of the computing system to allow processingof the UID data by the respective compare function and provide corresponding results data back to the reader based on the rules data.
35. The system of claim 33, wherein the reader performing the measurement belongs to a different organizational entity than the organization entity that operates and / or controls a given instance of the computing system and the associated data store, and wherein responsive to the given instance of the computing system receiving a request from the reader of the different organizational entity store, corresponding instructions cause the one or more processors of the given instance of the computing system to allow to the compare function to search for match but not provide corresponding results data to the reader.
36. The system of claim 33, wherein the reader performing the measurement belongs to a different organizational entity than the organization entity that operates and / or controls a given instance of the computing system and the associated data store, and wherein responsive to the given instance of the computing system receiving a request from the reader of the different organizational entity store, corresponding instructions cause the one or more processors of the given instance of the computing system to allow to the compare function to search for match and return a different set of results to the different organizational entity than would be returned to organizational entity to which the reader performing the measurement belongs.
37. The system according to any preceding claim, further comprising further instructions to cause the one or more processors to: bind operational transaction data, which includes and / or is associated with the received UID data, to an external verification network, in which the external verification network includes an immutable transaction data store; send the operational transaction data to the external verification network through a communication link; and receive a response from the external verification network that includes information representative of at least one of an identity of the physical object, an authenticity of the physical object, a provenance of the physical object, a description of the physical object, a description and / or information associated with an organization entity, wherein the reader is configured to provide the user-perceptible output specifying the unique identifier, authenticity, and / or provenance of the physical object based on the results data and / or the response from the external verification network.
38. A method, comprising:receiving, by one or more processors at a computing system, unclonable identifier (UID) data, in which the UID data includes spectra data representative of at least one optical spectrum measured by a reader from a portion of a physical object that includes a physically unclonable function (PUF); determining, by the one or more processors, a unique identifier, authenticity, and / or provenance of the physical object based on a comparison of the received UID data and predetermined UID data stored in a data store; generating results data indicative of the unique identifier, authenticity and / or provenance of the physical object; and sending the results data to the reader, in which the reader is configured to provide a user- perceptible output specifying the unique identifier, authenticity, and / or provenance of the physical object based on the results data.
39. The method of claim 38, wherein the portion of a physical object is a first portion of the physical object, and the reader comprises: acquiring, by a spectrometry apparatus of the reader, at least one measure of electromagnetic transmission and / or reflection spectrum or spectra for the first portion of the physical object, which defines the spectra data; and acquiring, by an optical imaging apparatus of the reader, an optical image of at least a second portion of the physical object and provide image data, in which the second portion is the same or different from the first portion of the physical object, wherein the UID data includes the spectra data and the image data.
40. The method of claim 39, wherein the spectrometry apparatus collects a number of measurements of the electromagnetic transmission and / or reflection spectrum or spectra for the first portion of the physical object, the reader is configured to combine at least some of the measurements of the electromagnetic transmission and / or reflection spectrum or spectra and provide an aggregate measure of the electromagnetic transmission and / or reflection spectrum or spectra, and the spectra data of the UID data includes the aggregate measure of the electromagnetic transmission and / or reflection spectrum or spectra.
41. The method according to claim 39 or 40, wherein determining the unique identifier, authenticity, and / or provenance of the physical object is based on the image data and the spectra data, which are included in the received UID data, and based on predetermined UIDdata that includes and / or is derived from predetermined spectra data and predetermined image data.
42. The method according to claim 39 or 40, wherein determining the unique identifier, authenticity and / or provenance of the physical object further comprises: dividing the measure of the electromagnetic transmission and / or reflection spectrum or spectra into a plurality of discrete spectra features; assigning a respective spectra feature value to each of the discrete spectra features based on attributes of the respective spectra feature; and matching, to within a threshold, at least some of the spectra features with predetermined spectra features based on comparing the respective spectra feature values with predetermined spectra feature values that are stored in the data store.
43. The method of claim 42, wherein determining the unique identifier, authenticity, and / or provenance of the physical object further comprises: based on the match, returning a list of one or more predetermined images from the data store; and executing, by the one or more processors, an image match function for each of the one or more predetermined images in the relumed list based on a comparison of each of the one or more predetermined images with the optical image of at least the second portion of the physical object to identify a closest image match.
44. The method according to claim 42 or 43, wherein the data store comprises a vector database, in which the vector database stores spectra feature vectors in multi-dimensional vector space, each of the spectra feature vectors has one or more values, defining spectra vector embeddings, representative of the predetermined spectra feature values, each of the predetermined spectra feature values of a given spectra feature vector is representative of one or more attributes of one or more spectra features extracted from a corresponding measure of electromagnetic transmission and / or reflection spectrum or spectra for a respective PUF.
45. The method according to claim 43 or 44, wherein executing the image match function further comprises: dividing, by the one or more processors, the optical image of at least the second portion of the physical object into a plurality of discrete images having respective image feature values; andcomputing, by the one or more processors, a confidence score based on a comparison of at least some of the respective image feature values for the optical image and image feature values determined for each of the one or more predetermined images.
46. The method according to claim 45, wherein the data store comprises an image vector database, in which the image vector database stores image feature vectors in multi-dimensional vector space, each of the stored image feature vectors has a number of image feature values, defining image vector embeddings, each of the image feature values of a given one of the stored image feature vectors is representative of one or more attributes of one or more image features extracted from a corresponding image of a respective second portion of a known physical object.
47. The method of claim 42, wherein the plurality of discrete spectra features into which the measure of the electromagnetic transmission and / or reflection spectrum or spectra is divided include respective wavelengths, and the method further comprises matching, by the one or more processors, at least some of the spectra features with the predetermined spectra features that are divided into at least some of the same respective wavelengths.
48. The method of claim 47, further comprising: comparing, by the one or more processors, the UID data across all spectra features of UID data that are stored in the data store; computing, by the one or more processors, a confidence value based on each comparison; and determining, by the one or more processors, if the UID data matches any stored UID data based on the confidence value exceeding a threshold.
49. The method according to any one of claims 38-48, wherein the UID data further comprises reader profile data, defining physical and / or logical attributes of the reader, to identify the reader within the system, the predetermined UID data in the data store comprises a multitudinous of predetermined UID data sets, each UID data set is associated with at least one of a known physical object or a known PUP.
50. The method of claim 49, further comprising: based on the reader profile data, filtering, by the one or more processors, the predetermined UID data sets in the data store to provide a subset of the predetermined UID data sets, wherein the comparison of the received UID data and predetermined UID data is performed with respect each of the UID data in the subset of the predetermined UID data sets.
51. The method of claim 49, further comprising:based on the reader profile data, performing an indexed query of the predetermined UID data sets, in which the predetermined UID data sets in the data store are indexed based on profile data.
52. The method according to any one of claims 49, 50, or 51, wherein the reader profile data is programmable and further includes an operator identifier and metadata, in which the operator identifier is based on an identity of a user of the reader, and the metadata includes information representative of at least one of a transaction timestamp for the UID data, physical location of the reader, and logical location of the reader.
53. The method according to any one of claims 38 through 48, wherein the reader is configured to bind the UID data with at least one of (a) a unique identifier for the reader, (b) a transaction timestamp, (c) a geographic location for the transaction, (d) logical network location, and / or (e) operator data to provide bound UID data, and the reader is configured to send the bound UID data over a secure communications link to the computing system.
54. The method according to any one of claims 38 through 48. wherein the reader is configured to bind the UID data with biometric and / or other data uniquely identifying an operator of the reader to provide bound UID data, in which the operator has been authenticated and authorized to perform the operation on the reader, and the reader is configured to send the bound UID data over a secure communications link to the computing system.
55. The method according to any one of claims 38 through 54, further comprising authenticating and authorizing the reader, locally and / or remotely, to perform measurement operations on behalf of an organizational entity that owns and / or controls an instance of program code executing the method.
56. The method of claim 55, further comprising authenticating and authorizing an operator of the reader, locally and / or remotely, to perform the measurement operations on the authenticated and authorized reader.
57. The method according to any one of claims 38 through 56, wherein the received UID data does not include information describing or identifying the physical object, a supply chain in which the physical object is shipped, and an owner or manufacturer of the physical object.
58. The method according to any one of claims 38 through 57. wherein the portion or the first portion of the physical object that includes the PUF comprises a disordered multilayer photonic crystal structure encoding data representative of the UID.
59. The method of claim 58, wherein the photonic crystal structure comprises a polymer film attached to the physical object or embedded within the physical object.
60. The method of claim 59, wherein the polymer film includes one or more markers on or incorporated within the polymer film.
61. The method of claim 60, wherein the one or more markers include a randomly generated non-sequential number that is associated with a batch of the polymer him, a defined image that is associated with the batch of him producing the polymer him UID, and / or an optical feature.
62. The method of claim 60 or 61, wherein marker data is produced to encode each marker and / or PUT with which the respective marker is associated, and the marker data is securely captured and saved cryptographically in the data store as part of the predetermined UID data.
63. The method according to any one of claims 60, 61, or 62, further comprising: capturing, by the reader, each of markers within the portion or the first portion of the physical object that includes the PUF; and providing captured marker data that is included as part of the UID data that is received at the computing system.
64. The method of claim 62, further comprising: performing, by the one or more processors, a marker comparison of the marker data across all marker data that are stored in the data store; computing, by the one or more processors, a confidence value based on each marker comparison; and based on determining that the confidence value does not exceed a confidence threshold, causing the one or more processors to return the results data specifying a negative match indicative of failing to specify the unique identifier, authenticity, and / or provenance for the physical object.
65. The method of claim 64, wherein the predetermined UID data in the data store comprises a multitudinous of predetermined UID data sets, each UID data set is associated with at least one of a known physical object or a known PUF, and wherein based on determining that the confidence value exceeds the confidence threshold, the method further comprises: determining a marker categorization based on the marker data.filtering the predetermined UID data sets in the data store based on the determined marker categorization to provide a subset of the predetermined UID data sets having the determined marker categorization, wherein the comparison of the received UID data and predetermined UID data is performed with respect each of the UID data in the subset of the predetermined UID data sets.
66. The method according to any one of the claims 38 through 65, wherein an instance of the method is performed at each of a plurality of instances of the computing system, in which each instance of the computing system has an associated data store and is associated with a respective one of a plurality of organizational entities.
67. The system of claim 66, wherein based on determining that the received UID data fails to match the predetermined UID data in the data store, the method further comprises: creating, by the one or more processors, a binding between the received UID data set and the physical object; defining a bound data set based on the created binding; and storing the bound data set in the data store.
68. The method of claim 67, wherein based on determining that the received UID data matches the predetermined UID data in the data store, the method further comprises enabling the computing system to return the results data to the reader.
69. The method according to any one of claims 66, 67, or 68, wherein the reader performing the measurement belongs to the same organizational entity that operates and / or controls the instance of the computing system and associated data store.
70. The method of claim 69, wherein each instance of the computing system and the associated data store includes rules data that defines policies to allow or deny searches from one or more other organizational entities.
71. The method of claim 70, wherein the reader performing the measurement belongs to a different organizational entity than the organization entity that operates and / or controls a given instance of the computing system and the associated data store, and wherein responsive to the given instance of the computing system receiving a request from the reader of the different organizational entity store, the method comprises: based on the rules data, causing the one or more processors of the given instance of the computing system to allow matching of the received UID data and providing corresponding results data back to the reader.
72. The method of claim 70, wherein the reader performing the measurement belongs to a different organizational entity than the organization entity that operates and / or controls a given instance of the computing system and the associated data store, and wherein responsive to the given instance of the computing system receiving a request from the reader of the different organizational entity, the method further comprises: based on the rules data, causing the one or more processors of the given instance of the computing system to allow searching for match but not providing corresponding results data to the reader.
73. The method of claim 70, wherein the reader performing the measurement belongs to a different organizational entity than the organization entity that operates and / or controls a given instance of the computing system and the associated data store, and wherein, responsive to the given instance of the computing system receiving a request from the reader of the different organizational entity store, the method further comprises: based on the rules data, causing the one or more processors of the given instance of the computing system to allow searching for a match and returning a different set of results to the different organizational entity than would be returned to organizational entity to which the reader performing the measurement belongs.
74. The method according to any one of the claims 38 through 73, further comprising: binding operational transaction data, which includes and / or is associated with the receivedUID data, to an external verification network, in which the external verification network includes an immutable transaction data store: sending the operational transaction data to the external verification network through a communication link; and receiving a response from the external verification network that includes information representative of at least one of an identity of the physical object, an authenticity of the physical object, a provenance of the physical object, a description of the physical object, a description and / or information associated with an organization entity, wherein the reader is configured to provide the user-perceptible output specifying the unique identifier, authenticity, and / or provenance of the physical object based on the results data and / or the response from the external verification network.
75. One or more non-transitory computer readable medium having instructions, which when executed by one or more processors cause the processor to perform the method according to any one of claims 38 through 74.
76. A system as shown and described.
77. A method as shown and described.
78. A reader as shown and described.