
Summary:
Product authentication is only part of the brand protection challenge. This blog explains how Digimarc's covert digital identifiers and Illuminate® platform transform authentication scans into actionable risk intelligence, helping pharmaceutical brands detect diversion, identify emerging threats, and gain real-time visibility across their supply chains.
Key Takeaways:
Digimarc has been at the forefront of product authentication innovation for decades, offering a covert digital identification and authentication layer that embeds covert digital identifiers into packaging inks and varnishes that counterfeiters can’t re-originate. Implementation requires no visible change to the existing physical product packaging or manufacturing process—but it transforms the product authentication process. Brand inspectors simply scan packaging with a phone camera running Digimarc’s Validate app for instant, high-confidence verification against brand records, anytime and anywhere.
This digital authentication capability can complement and strengthen serialization and traditional, overt physical security features such as 2D bar codes, specialized inks, and holograms. But the technology platform our solution runs on can also support other critical needs for brands. For example, in industries such as pharmaceuticals, we’re seeing an evolution that cybersecurity underwent a decade ago: what started as a compliance-and-enforcement function is increasingly becoming a source of much-needed risk intelligence. Pass/fail catch rates and periodic seizure reports are great, but today, executives, general counsel, and enterprise risk functions are asking harder questions such as:
Answering these types of questions requires data that does more work than authentication alone—or serialization or spot-checks—were ever designed to do.
The good news is that the same cloud architecture that Digimarc uses to help close the counterfeit-detection gap explored in our white paper, The Counterfeit Detection Gap: How Pharma Brand Protection Quietly Became a Liability Question, can also be the source of risk-intelligence data needed to answer these questions. When one of our covert, unique digital identifiers is embedded into the packaging of each unit as it’s manufactured in a supported implementation, it can be linked to a data record in our cloud-based Illuminate® platform, where brands can associate data such as production date, batch, intended market, authorized channel, distributor of record, and any other supported data field.
This means the same brand inspector, supply chain monitor, or in-store worker or customer scan that verifies the detected identifier and associated data in the field can also enable diversion detection and continuous risk intelligence across the distribution network. Scan data from the field can be aggregated centrally through the Illuminate platform, where it can be enriched with any product-level metadata the brand chooses to associate with metadata stored on the Illuminate platform, such as intended market, authorized channel, production date, batch, or distributor of record.
This turns authentication scans into a live risk view into geographic clustering of failed verifications, diversion patterns surfaced automatically when a unit is scanned outside its authorized market, and leading indicators of counterfeiting activity that surface weeks before conventional recall triggers would fire.
Let’s take a closer look at these opportunities.
A pure authentication check answers one question: Does the detected identifier and associated data match brand records? It does not answer a second question that is often just as consequential: Is this package where it’s supposed to be?
The IMFINZI cases described earlier in this paper illustrate the point directly. Two of the falsified batches identified by the World Health Organization carried genuine lot numbers—lots that AstraZeneca had authorized for distribution only in India and Egypt. But they were reused on product diverted far outside those markets. A check that relies only on cloned or legitimate-looking lot-level data may not flag the issue, because the underlying lot data may appear valid even when used on a counterfeit package. The failure mode is not counterfeiting in the strict sense. Rather, it is authorized product surfacing in the wrong market, sometimes with falsified packaging built around it, and sometimes not.
When Digimarc’s covert identifier is embedded into a product’s packaging during production and associated with metadata on the Illuminate platform (for example, about its intended market and authorized channel), brands can use the data captured in the field (from scans carried out by inspectors, supply chain players, and even pharmacists) to compare this data against where and when the scan is actually happening.
So, a unit authorized for Egypt, scanned by a distributor in Uzbekistan, can flag immediately — even where a serialization or lot-level check, taken in isolation, may not reveal the market mismatch. This is the diversion-detection capability that lot-and-batch data alone cannot deliver, because lot-and-batch records were never designed to encode geographic authorization at the unit level.
A single scan verifies the detected identifier and associated data for a single unit. Ten thousand scans across markets, distributors, and time reveal patterns that no individual verification can. When every scan, not only the failed ones, is logged to a central platform with its location, timestamp, device, and result, the aggregate becomes a live view of a brand's real-world exposure.
Think of it like weather sensors. A single sensor tells the temperature in one place. A network of connected sensors tells you where the storm is forming, which direction it is moving, and how fast. Individual authentication scans are single sensors; the analytics layer is the network view that lets a brand see the storm.
Digimarc enables this network view that supports investigations that would otherwise be impossible. This is possible because:
These insights can help companies take informed actions that protect their revenues, their brand, and their customers.
And finally, Digimarc’s approach to enabling package-level authentication can complement DSCSA and EPCIS-based serialization through its interoperability with these standards. Specifically, our covert authentication layer can sit on top of DSCSA-compliant serialization and the EPCIS trading-partner data exchange those systems rely on, enabling Digimarc to help address the specific failure mode neither was designed to catch: cloned or legitimate-looking lot-level data may not, by itself, reveal falsified packaging or unauthorized market movement.
Two conditions turn these “art-of-the-possible" examples into a real-world operational capability businesses need today:
Both conditions are within every brand's control. Together, they turn covert authentication from a defensive feature into an intelligence system that empowers brand protection teams and protects their customers.