Technology

Why Cryptographically Signed QR Codes Can't Be Forged

How cryptographic signing gives every product a tamper-proof digital identity that counterfeiters cannot replicate.

AM
Aisha Mwangi
6 min read

"Secure QR code" is a phrase that gets used loosely enough to be meaningless. A QR code is only a way of writing data down — it is a font, not a lock. What determines whether a code can be forged is entirely what the data says and who can produce a valid version of it.

This article explains what cryptographic signing actually does, in plain terms, and — just as importantly — what it does not do.

The problem with an ordinary serial number

Suppose you print a unique serial on every unit: PRD-000001 through PRD-500000, and you keep a database of which serials are genuine. A shopper scans, you look up the serial, and you report back.

This fails immediately. The numbering scheme is guessable. A counterfeiter who buys two genuine units sees PRD-014823 and PRD-014824, infers the pattern, and prints half a million sequential codes. A large fraction will collide with real serials in your database and validate perfectly.

Randomising the serials helps but does not solve it. Long random identifiers are hard to guess, yet the system still has a single point of failure: anyone who obtains a copy of your database — an insider, a contractor, a breach — can mint unlimited valid codes. The security rests on a secret that many systems and people need read access to.

What a digital signature changes

A digital signature works on a different principle. Instead of checking membership in a list, you check a mathematical proof.

The system holds a matched pair of keys. The private key is held only by the code-generation service and never leaves it. The public key can be shared with anyone — it is not a secret at all. The relationship between them is asymmetric in a specific and useful way:

  • Only the private key can produce a valid signature for a given piece of data.
  • The public key can verify that a signature is valid, but cannot be used to create one.
  • Changing even a single character of the signed data invalidates the signature.

So when a code is generated, the payload — product identifier, batch, serial, intended region — is signed with the private key, and the signature travels inside the QR code alongside the data. Verification is then a mathematical check rather than a database lookup.

Why the payload matters as much as the signature

Signing proves a code was issued by you. It says nothing about whether the code is on the right product. That is why the signed payload includes context, not just an identifier.

Because the product, batch, and intended market are part of the signed data, they cannot be altered without breaking the signature. A code issued for a 200ml bottle in one batch cannot be edited to read 500ml, and one issued for a particular market cannot be quietly re-pointed at another. Verification returns not only "this is genuine" but "this is genuinely *this* product, from *this* production run, intended for *this* market" — and any mismatch between what the code says and what the shopper is holding becomes visible.

What signing does not solve

Here is the limit, stated plainly, because vendors who gloss over it are selling you a false sense of security.

Signing prevents *forgery*. It does not prevent *copying*. A counterfeiter who photographs one genuine label can reprint that exact code — signature and all — onto a hundred thousand fakes. Every one of those codes is cryptographically valid, because it is a bit-for-bit copy of something you really did sign.

Any system that stops at signing has this hole. Closing it requires watching how codes behave after they enter the world.

Closing the gap with scan intelligence

A genuine unit has a characteristic scan signature: verified once or a small number of times, in roughly one place, within its intended market, in a plausible time window after the batch shipped. Duplicated codes break that pattern in ways that are hard to disguise:

  • One serial scanned far more often than a single physical unit plausibly would be.
  • The same serial scanned in several distant locations within a period too short for the item to have travelled between them.
  • Scans concentrated well outside the batch's intended distribution region.
  • A sudden burst of first-time scans of codes from a batch that shipped long ago.
  • Many distinct devices scanning the same serial in rapid succession.

When these fire, the consumer's verification result changes from a clean pass to an explicit warning, and the brand gets an alert with the locations attached. The copy attack still happens — but it converts itself into evidence, and it stops fooling the shopper.

The security model, summarised

Two mechanisms, addressing two different attacks:

  1. 1Cryptographic signing makes inventing codes impossible without the private key.
  2. 2Scan-pattern analysis makes copying codes detectable, and turns each detection into intelligence about where the counterfeit operation is running.

Neither alone is sufficient. Signing without intelligence is bypassed by a photocopier. Intelligence without signing drowns in noise, because there is no reliable ground truth about which codes were legitimately issued. Together they leave a counterfeiter with no move that is both effective and quiet — which is the actual goal.

Protect your products with VerifyGuard

Generate cryptographically signed QR codes, let customers verify in one scan, and see counterfeit activity as it happens.