ISO 22383:2020

Security and resilience – Authenticity, integrity and trust for products and documents – Guidelines for the selection and performance evaluation of authentication solutions for material goods

ISO 22383:2020 provides guidance for organisations on how to go about selecting the most appropriate ‘authentication elements’ (devices used as part of an authentication solution) to validate the authenticity of their material goods and sets out criteria that can be used to analyse and compare different options. This Standard does not prescribe any one exclusive means of authentication. The guidance it contains is universally applicable, irrespective of material good, environment or authentication technology used.
 

Description
 

ISO 22383:2020 is part of a wider framework of standards relating to authenticity, integrity and trust for products and documents. It is a set of guidelines designed to help organisations identify which category or categories of ‘authentication element’ they should be using to combat counterfeiting. It does this by:

  • laying down the basic principles involved in defining an anti-counterfeiting strategy;
  • describing the different categories of technology that exist;
  • presenting performance criteria; and
  • showing how these criteria can be used to assess the effectiveness of authentication elements and overall solutions.


>> Basic principles
 

According to the Standard, the factors that will determine the most suitable authentication elements and solutions, and therefore form the foundation of the anti-counterfeiting strategy, are:

  • an assessment of the counterfeiting-related risks;
  • the context of implementation and usage; and
  • technical, logistic and financial criteria.

These factors (a full list of which is included in the document) provide the basis for defining the performance requirements for authentication elements and solutions, and for assessing their effectiveness.

This assessment should also consider both processes involved in an authentication solution: the creation process (in which the authentication elements are defined, made and integrated into or onto the product) and the inspection process (in which the elements are verified by trained inspectors with the appropriate tools, where tools are needed).

The Standard recommends following a ‘security-by-design process’ to design the solution.

 

>> Categorisation of Technologies
 

The Standard identifies three categories of technology – ‘overt’, ‘covert’ and ‘forensic’ technologies. These can be analysed and compared based on the following characteristics:

  • provision of knowledge: the way in which general or good-specific knowledge is provided to the inspector;
  • sourcing and production of authentication elements and tools: the types of security measures in place to audit providers and protect production processes against knowledge transfer and theft;
  • inspection: whether inspection is carried out via human senses, an authentication tool or forensic analysis.

 

>> Performance criteria
 

The Standard sets out performance criteria for rights holders to use to evaluate how well authentication elements and solutions may perform in relation to the risks identified in the risk assessment. The performance requirements are defined by comparing the performance criteria to the risk assessment.

For authentication elements performance criteria include:

  • physical characteristics (size, material, flexibility, viscosity, durability and resistance to environmental conditions, etc.);
  • attack resistance (resistance to tampering and alteration, data breaches, interception of communication and obsolescence);
  • integration process (how secure the process of integrating the element to the material good is).


For authentication solutions performance criteria include:

  • location and environment for the authentication process (availability of power resources, environmental conditions such as temperature or humidity, exposure to hazards, etc.);
  • authentication parameters (the time it takes to process authentication, accuracy rate and speed, the time it takes to get a result, etc.);
  • security policy (the measures that need to be taken to secure all components of the solution, the supply chain, etc.);
  • compliance with relevant regulations (including governmental or those issued by regulatory agencies – especially if the solution is intended for implementation in international markets).

 

>> Effectiveness Assessment

 

The effectiveness of an authentication element or solution can be assessed by evaluating how well it meets the requirements that have been defined for each set of criteria. ISO 22383:2020 simplifies this assessment by providing a grid in the annex that contains all the performance criteria and allows the user to indicate the performance requirement for each one, as well its relevance.


Uses
 

ISO 22383:2020 is intended for all organisations that need to be able to validate the authenticity and integrity of material goods with authentication elements and solutions anywhere in the supply chain. It can be used by organisations of any type and any size. Authentication solutions can be used for anti-counterfeiting, preventing product fraud and preventing diversion.

 

Cost
 

All the latest pricing and purchasing information can be found on the ISO website and the websites of its national members.