We built our authentication to be understood, not taken on faith alone. We explain how it works in plain language, and we do not dumb it down or ask you to trust our credentials. The cryptography underneath is established and battle-tested. Not all NFC tags can do this. An ordinary tag holds data anyone can copy. Ours prove themselves. Every tag we ship is an NTAG 424 DNA, an NFC Forum Type 4 tag produced exclusively by NXP, with a secure enclave embedded in the chip so it can be authenticated remotely, as many times as it is tapped.
Most NFC tags act as just data storage with no security. They can pop up saved NDEF data and link you to a site or give you access to a door. In the case of door keys, they work just like a metal key cut by a locksmith. It is a pattern or code that can be cloned an unlimited number of times. Counterfeits can be confusing, with impossible to detect clones oftentimes produced by the same or nearby factories that make the genuine product. Our chips have rolling keys that change every time with a non-reversible cryptographic hashing function that uses the master key (MK) at mint time to generate all future keys. Old keys cannot be used again (replayed), and future keys cannot be predicted without knowing the secret used to seed the signing algorithm. Even if you had the MK, you would still need the keys used by NXP to assign the UID to the chip to fully authenticate the tag. It is this level of security that stops counterfeiting attempts before they start.
Every tag we use is verified using NXP's factory-programmed ECC signatures before being minted. We trust our official NXP suppliers, but we verify each tag ourselves in our mint process. There is no trust without a default level of distrust.
Where the Boundary Is
A genuine tag proves the tag is genuine. It does not prove that the tag is still attached to the item it was applied to, and it does not inspect the item. A tag is also a bearer instrument, so whoever holds it can tap it. We build the seals, the counters, and the records to make misuse visible, and we tell you plainly where the boundary is.