Home / ItemShield / ItemShield Specification
ItemShield
Secure Identity for Every Physical Product.
ItemShield is an open source specification for securely identifying, authenticating, tracking, and protecting physical products throughout their lifecycle. It provides manufacturers with a framework for assigning unique cryptographically verifiable identities to products and connecting those identities to physical carriers such as QR codes, barcodes, Data Matrix codes, NFC tags, RFID tags, and other machine-readable identifiers.
ItemShield is designed to establish trust from the point of manufacture through distribution, retail, sale, and customer verification. The specification combines cryptographic product identities, authenticated lifecycle events, chain-of-custody records, inventory tracking, point-of-sale verification, fraud detection, and anti-theft capabilities. The physical barcode or tag is treated as a carrier for a verifiable product identity rather than the root of trust.
Purpose
ItemShield provides a standardized framework for manufacturers and authorized supply-chain participants to:
- Establish a unique identity for individual physical products.
- Associate products with SKUs, models, batches, and lots.
- Cryptographically sign product identities and lifecycle events.
- Track products through manufacturing, distribution, retail, and sale.
- Record authorized custody and location changes.
- Verify products through consumer and organizational scanning.
- Detect cloned identifiers, duplicate identities, suspicious movement, and unauthorized activity.
- Identify products that have been recalled, stolen, missing, compromised, suspended, or invalidated.
- Preserve an auditable history of product events.
- Support investigations, recovery efforts, insurance claims, and compliance processes.
- Provide a vendor-neutral foundation that can be implemented across different organizations and systems.
Design Principles
Secure Product Identity
Every serialized product should receive a unique cryptographically verifiable product identity. The identity should be generated and issued by an authorized manufacturer or other trusted issuing authority.
Cryptographic Verification
Product identities and authorized lifecycle events should support digital signatures and cryptographic verification. Verification should establish whether an identity was legitimately issued and whether recorded events were authorized.
Lifecycle Integrity
Product status should reflect the known lifecycle of the physical item. Authentication should consider both cryptographic validity and lifecycle consistency.
Chain of Custody
Product movements should be recorded through authenticated events that establish known custody, locations, transfers, shipments, receipts, and sales.
Tamper Evident Records
Lifecycle records should use append-only event semantics and cryptographic integrity protections. Corrections should be recorded as new authenticated events rather than silently modifying historical events.
Privacy
Consumer information and confidential supply-chain information should be protected. Product verification should provide useful authenticity information without unnecessarily exposing private customer, commercial, or investigative data.
Human Verification
Consumer-facing verification should provide clear and understandable results without requiring customers to understand cryptographic systems, supply-chain infrastructure, or technical terminology.
Vendor Neutrality
ItemShield should not require a particular vendor, database, hosting provider, blockchain, distributed ledger, barcode provider, or application platform.
Technology Neutrality
The specification defines capabilities, data relationships, security requirements, and operational behavior without requiring a particular implementation technology.
Human Governance
Organizations should retain human control over product status changes, fraud investigations, theft reports, legal notifications, and other consequential decisions.
Legal Accuracy
ItemShield records verifiable events and product statuses. The specification should not automatically convert an event into a legal conclusion. Product status such as reported stolen, recalled, or suspicious should remain distinct from conclusions about criminal or civil liability.
Core Modules
Product Identity Module
The Product Identity Module defines the identity assigned to each protected product.
Capabilities include:
- Manufacturer identity.
- Product identity.
- Unique item identifier.
- SKU or model identifier.
- Serial number.
- Batch identifier.
- Lot identifier.
- Manufacturing date.
- Manufacturing location.
- Expiration date where applicable.
- Product classification.
- Product state.
- Product identity version.
- Association with physical identification carriers.
The module should support both serialized products and products managed at batch or lot level where individual serialization is not required.
Cryptographic Product Token Module
The Cryptographic Product Token Module defines the secure token associated with a product identity.
A token may contain or reference:
- Manufacturer identity.
- Product identity.
- Unique item identifier.
- SKU or model.
- Batch or lot.
- Manufacturing event.
- Issuance timestamp.
- Product status.
- Expiration information where applicable.
- Token version.
- Signing key identifier.
- Digital signature.
The module should support token generation, signing, verification, versioning, key rotation, and invalidation.
Manufacturing Registration Module
The Manufacturing Registration Module establishes the initial trusted identity of a product.
Capabilities include:
- Registering products at manufacture.
- Generating unique product identities.
- Issuing cryptographic product tokens.
- Associating products with batches and lots.
- Recording manufacturing events.
- Recording manufacturing locations.
- Recording manufacturing timestamps.
- Establishing the initial lifecycle state.
- Associating physical carriers with product identities.
- Recording authorized issuing entities.
Barcode and Carrier Module
The Barcode and Carrier Module defines how physical products are associated with machine-readable identifiers.
Supported carriers may include:
- QR codes.
- Data Matrix codes.
- Standard barcodes.
- NFC.
- RFID.
- Other machine-readable identification technologies.
The module should distinguish the physical carrier from the cryptographically trusted product identity. Copying a carrier should not create a legitimate second product identity.
Distribution Center Module
The Distribution Center Module provides product tracking and custody management for distribution centers, warehouses, fulfillment facilities, and other authorized inventory locations.
Capabilities include:
- Receiving products.
- Scanning incoming products.
- Acknowledging custody.
- Recording facility locations.
- Recording inventory quantities.
- Recording batch and lot information.
- Recording individual serialized items.
- Recording outbound shipments.
- Recording transfers between facilities.
- Verifying product identities during receipt and release.
- Identifying unexpected or unauthorized inventory.
Inventory and Chain of Custody Module
The Inventory and Chain of Custody Module records the known movement and custody history of products.
Capabilities include:
- Current known product location.
- Previous product locations.
- Authorized custody.
- Distribution center transfers.
- Warehouse transfers.
- Shipment events.
- Delivery events.
- Retailer receipt.
- Expected destination.
- Source and destination relationships.
- Custody timestamps.
- Unexpected location detection.
- Chain-of-custody reconstruction.
Point of Sale Module
The Point of Sale Module records the authorized sale of serialized products.
Capabilities include:
- Retailer product verification.
- Product scan at sale.
- Sale event creation.
- Product state transition to SOLD.
- Retail location recording.
- Authorized seller identification.
- Sale timestamp.
- Post-sale status verification.
Customer identity should not be required to establish that a product was sold unless an implementation specifically requires customer registration.
Customer Verification Module
The Customer Verification Module provides a consumer-facing product verification experience.
A customer should be able to scan a product and receive a clear result such as:
- AUTHENTIC PRODUCT.
- SUSPICIOUS PRODUCT.
- INVALID PRODUCT.
- RECALLED PRODUCT.
- STOLEN PRODUCT ALERT.
- STATUS REQUIRES REVIEW.
Verification should consider cryptographic validity, lifecycle state, scan history, chain-of-custody consistency, and other relevant risk indicators.
The customer interface should avoid exposing confidential manufacturing, distribution, security, or investigative information.
Product Lifecycle Module
The Product Lifecycle Module defines recognized product states and authenticated transitions between states.
Possible states include:
- ISSUED.
- MANUFACTURED.
- RELEASED.
- IN DISTRIBUTION.
- AT DISTRIBUTION CENTER.
- IN TRANSIT.
- AT RETAILER.
- SOLD.
- CUSTOMER REGISTERED.
- RETURNED.
- RECALLED.
- SUSPENDED.
- FRAUD SUSPECTED.
- STOLEN.
- MISSING.
- COMPROMISED.
- RECOVERED.
- INVALIDATED.
Implementations may define additional states provided that state definitions and transitions remain explicit and auditable.
Scan Event Module
The Scan Event Module records product verification and operational scans.
Events may include:
- Manufacturing scans.
- Distribution scans.
- Inventory scans.
- Transfer scans.
- Shipment scans.
- Delivery scans.
- Retail receipt scans.
- Point-of-sale scans.
- Customer verification scans.
- Warranty scans.
- Return scans.
- Investigation scans.
- Theft verification scans.
A scan event may include:
- Event identifier.
- Item identifier.
- Token identifier.
- Scan type.
- Timestamp.
- Authorized actor.
- General location.
- Product state.
- Verification result.
- Event source.
- Relevant metadata.
Immutable Ledger Module
The Immutable Ledger Module maintains an append-only record of authenticated product lifecycle events.
Ledger events may include:
- Product manufacture.
- Token issuance.
- Product activation.
- Distribution receipt.
- Distribution release.
- Warehouse transfer.
- Shipment.
- Delivery.
- Retail receipt.
- Point-of-sale transaction.
- Customer registration.
- Product return.
- Product replacement.
- Recall.
- Fraud alert.
- Theft report.
- Product recovery.
- Product suspension.
- Product invalidation.
- Authorized verification scans.
Each ledger event should support appropriate integrity information, including:
- Event identifier.
- Item identifier.
- Token identifier.
- Event type.
- Previous event reference.
- Timestamp.
- Authorized actor.
- Source.
- Destination.
- Product state before the event.
- Product state after the event.
- Relevant metadata.
- Cryptographic hash.
- Preceding ledger reference.
- Digital signature.
- Signing key identifier.
The ledger should preserve historical events rather than silently rewriting them. Corrections should be represented as new authenticated events that reference the original event.
Fraud Detection Module
The Fraud Detection Module identifies activity that may indicate counterfeit production, identifier cloning, diversion, unauthorized resale, tampering, or other product security risks.
Detection signals may include:
- Duplicate item identifiers.
- Reused product tokens.
- Invalid signatures.
- Sold products appearing as new inventory.
- Unexpected geographic movement.
- Impossible travel times.
- Unauthorized distribution locations.
- Multiple simultaneous locations.
- Repeated scans from unrelated parties.
- Cloned identifiers.
- Replaced or tampered identification carriers.
- Suspended products presented for sale.
- Recalled products presented for sale.
- Stolen products entering unauthorized channels.
Fraud detection should use contextual risk analysis. Legitimate repeat scans by customers, retailers, warranty providers, investigators, or other authorized parties should not automatically be classified as fraud.
Fraud Alert Module
The Fraud Alert Module creates and manages alerts generated from suspicious product activity.
Alert severity may include:
- Informational.
- Warning.
- High Risk.
- Critical.
Alerts may be directed to appropriate parties including:
- Manufacturers.
- Authorized distributors.
- Retailers.
- Supply-chain security personnel.
- Customers.
- Investigators.
- Other authorized parties.
Alert visibility should be controlled according to role, authorization, privacy requirements, and security policy.
Anti Theft Module
The Anti Theft Module provides product status and event management for stolen, missing, hijacked, diverted, or compromised products.
Supported events may include:
- Warehouse theft.
- Distribution center theft.
- Cargo theft.
- Shipment hijacking.
- Retail theft.
- Supply-chain diversion.
- Unauthorized possession.
- Missing inventory.
- Stolen inventory.
- Recovery of stolen goods.
- Compromised product identification.
A stolen product should retain its original cryptographic identity. Theft should change the product’s status and create authenticated events rather than creating a replacement identity.
When a customer scans a product reported stolen, the system should provide an appropriate warning and avoid automatically treating the customer as a participant in wrongdoing.
Legal and Compliance Module
The Legal and Compliance Module provides structured records for legal, regulatory, insurance, and investigative processes.
Capabilities include:
- Stolen product incident records.
- Chain-of-custody documentation.
- Evidence preservation.
- Authorized transaction history.
- Verification timestamps.
- Seller and retailer records.
- Customer notification records.
- Law enforcement notification workflows.
- Insurance documentation.
- Recovery documentation.
- Legal holds.
- Case identifiers.
- Jurisdiction information.
- Compliance audit records.
- Applicable policy references.
The module should distinguish factual product records from legal conclusions and should support jurisdiction-specific policies without assuming that one legal requirement applies universally.
Optional Plugin Modules
Recall Management Plugin
Provides recall creation, product identification, recall status management, customer notifications, distribution notifications, and recall verification.
Warranty Management Plugin
Provides warranty registration, warranty status, service records, authorized service verification, and product history.
Returns and Reverse Logistics Plugin
Provides product return authorization, return scanning, inspection events, replacement tracking, and reverse supply-chain records.
Retailer Management Plugin
Provides retailer registration, authorization, product verification permissions, inventory relationships, and retailer lifecycle management.
Customer Product Registration Plugin
Allows customers to voluntarily associate products with customer accounts while maintaining privacy controls.
Stolen Product Registry Plugin
Provides specialized management of stolen, missing, hijacked, diverted, and recovered products.
Counterfeit Investigation Plugin
Provides investigation records, suspected counterfeit relationships, evidence references, investigator notes, and case management.
Geographic Fraud Analysis Plugin
Provides geographic analysis of product scans, movement anomalies, unexpected locations, and potential distribution diversion.
NFC and RFID Integration Plugin
Extends ItemShield to support NFC and RFID product identification and verification workflows.
IoT Product Integration Plugin
Allows connected products to generate authenticated lifecycle, location, service, condition, and security events.
Distributed Ledger Anchoring Plugin
Allows ledger commitments or selected event proofs to be anchored to independent distributed systems. Distributed ledger technology is optional and is not required by the core specification.
Manufacturer API Plugin
Provides standardized interfaces for manufacturers to integrate ItemShield with existing production, inventory, security, and product management systems.
Retail Point of Sale Integration Plugin
Connects ItemShield verification and sale events with authorized retail point-of-sale systems.
E Commerce Integration Plugin
Provides product verification and lifecycle integration for online retailers, marketplaces, fulfillment providers, and direct-to-consumer commerce.
Shipping Integration Plugin
Connects shipment creation, carrier events, delivery confirmation, and transportation exceptions with ItemShield product identities.
Analytics and Reporting Plugin
Provides operational reporting, product lifecycle analytics, fraud trends, inventory visibility, geographic analysis, and security reporting.
Regulatory Compliance Plugin
Provides configurable jurisdiction-aware compliance workflows, reporting requirements, retention policies, and audit controls.
Product Lifecycle Management Plugin
Extends product identity and event tracking into broader product lifecycle processes, including service, refurbishment, replacement, retirement, and disposal.
Multi Manufacturer Federation Plugin
Allows independent manufacturers and authorized organizations to exchange verifiable product identity and event information while retaining control over their own systems and data.
Security Requirements
ItemShield implementations should:
- Protect private signing keys.
- Authenticate authorized actors.
- Verify digital signatures before accepting trusted events.
- Prevent unauthorized lifecycle transitions.
- Detect token reuse and identifier duplication.
- Protect ledger integrity.
- Apply appropriate access controls.
- Minimize unnecessary exposure of customer information.
- Protect confidential supply-chain information.
- Record security-relevant events.
- Support key rotation and revocation.
- Provide mechanisms for compromised credentials and signing authorities.
- Preserve evidence relevant to security investigations.
- Prevent unauthorized modification of historical lifecycle records.
Fraud and Counterfeit Model
ItemShield should not treat possession of a valid token as absolute proof that the physical product is genuine. A counterfeit product may reproduce the identifier of a legitimate product.
Authenticity assessment should therefore combine:
- Cryptographic token verification.
- Product identity verification.
- Lifecycle state.
- Chain of custody.
- Scan history.
- Location consistency.
- Timing consistency.
- Distribution authorization.
- Sale status.
- Theft status.
- Recall status.
- Other applicable risk indicators.
A valid cryptographic identity with inconsistent lifecycle or location information should be capable of producing a suspicious result.
Stolen Product Workflow
A typical stolen product workflow may include:
Manufacturer → Distribution Center → Shipment → Hijacking → STOLEN
The original product identity remains unchanged. The system records the hijacking or theft event, updates the product status, preserves the event history, and generates appropriate alerts.
If an unknown seller subsequently presents the product to a customer, the customer can scan the product. ItemShield verifies the cryptographic identity, retrieves the applicable product status, identifies the stolen status, records the verification event, and generates an appropriate anti-theft alert.
The system should preserve the complete sequence of authenticated events so authorized parties can reconstruct the product’s history.
Evidence Preservation
ItemShield should support reconstruction of significant product events, including:
- Manufacture.
- Product registration.
- Distribution.
- Shipment.
- Delivery.
- Retail receipt.
- Sale.
- Theft or diversion.
- Stolen status assignment.
- Subsequent verification.
- Fraud detection.
- Customer notification.
- Recovery.
- Investigation.
- Final disposition.
Evidence records should preserve event relationships, timestamps, authorized actors, cryptographic integrity information, and relevant metadata according to applicable retention and privacy policies.
Specification Branding License (SBL)
Standard
- Fully AGPL-3.0+ compliant system.
- Copyleft enforced for network deployments.
- Required attribution:
- Roxanne Ardary.
- roxanneardary.com.
Optional
- Specification Branding License (SBL)
- Attribution-free commercial deployment.
- Pricing based on scale, usage, and deployment scope.
License & Notice Requirements
ItemShield is released under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).
By contributing to any Open Arsenal project, you agree that your contributions will also be released under this license.
Please note the following:
- All contributions must comply with the AGPL-3.0+ terms.
- Under Section 7 of the license, all redistributions, forks, and derivative works must preserve attribution to Roxanne Ardary and roxanneardary.com.
- ItemShield specifications are free to use with attribution. A Specification Branding License can be negotiated upon request.
- The project’s notice.md file tracks attribution requirements and contributor acknowledgments. Any update that adds new contributors or modifies attribution should also update
notice.md. - When submitting a pull request, ensure that any new files maintain the attribution headers where applicable.
- Network-deployed versions of this software must also remain fully AGPL-3.0+ compliant, including exposure of source code modifications when applicable under the license.
For full legal details, please refer to the AGPL-3.0+ license and the project’s notice.md file.
Notice – ItemShield
Attribution Requirement: Under Section 7 of the AGPL 3.0+ license, all redistributions, forks, and derivative works, including network-deployed versions of this project, must provide attribution to Roxanne Ardary and roxanneardary.com.
Contributors
This file tracks contributors and their specific contributions to the project.
- Roxanne Ardary, roxanneardary.com – September 5, 2026
Created the repository for ItemShield. Created the ItemShield specification for securely identifying, authenticating, tracking, and protecting physical products throughout their lifecycle. - [Add other contributors here] – [Date]
[Describe contribution in one sentence]
License – ItemShield
This repository is licensed under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).
Key Points:
- You are free to use, modify, and distribute the code.
- All redistributions, forks, and derivative works or network-deployed versions must also be licensed under AGPL-3.0+ and provide attribution to Roxanne Ardary and roxanneardary.com as required under Section 7 of the license.
- The software is provided “as is,” without warranty of any kind.
For the full license text, see GNU AGPL-3.0 License.
