Overview
ISO 22381:2018 - Security and resilience - Authenticity, integrity and trust for products and documents - provides guidelines for establishing interoperability among object identification and authentication systems. It supports planners and implementers in designing interoperable environments that deter counterfeiting and illicit trade while remaining open to legacy systems and new identification methods. The standard is a guidance document (not a prescriptive data-transfer protocol) and explicitly excludes the permanent transfer of data from one system to another.
Key topics and technical requirements
ISO 22381 focuses on governance, architecture and operational controls needed to achieve secure interoperability (I-OP) of independently functioning object identification and authentication systems (OIAS). Core topics include:
- Stakeholder identification and analysis: map interests, obligations and capabilities (brand owners, regulators, users).
- Organizing stakeholders: appoint a lead stakeholder, define roles and responsibilities and set up onboarding/leaving processes.
- Contractual framework: document responsibilities, data categories, access rights, ownership, security levels, liabilities and risk mitigation (fraud, legal compliance, system failures).
- Architecture planning: select participating OIAS and functional blocs, define attributes and ownership, specify trusted entry points (TEPs), access rules, and trust levels; design how information is returned to sources.
- Operational planning: agree data exchange formats, delimit inputs/outputs, define storage and custodianship, assign operational responsibilities, plan failure responses, alarm handling and pilot testing.
- Review and continuous improvement: periodic review of stakeholder expectations, operations, security and technology.
Relevant concepts and abbreviations used in ISO 22381 include UID (unique identifier), OIAS, I-OP, TEP, OEF (object examination function), and attribute data management.
Practical applications and users
ISO 22381 is applicable across industries and can be used globally or in limited environments. Typical use cases:
- Supply chain integrity and anti-counterfeiting for pharmaceuticals, cosmetics, electronics, automotive parts and luxury goods.
- Regulatory compliance and customs enforcement to detect illicit trade.
- Brand protection and authentication services that need to interoperate with third‑party verification platforms.
- Public‑private initiatives that aggregate multiple identification schemes while retaining legacy systems.
Primary users: standards implementers, IT and security architects, brand owners, regulators, anti‑counterfeit task forces, system integrators and technology vendors.
Related standards
- ISO 16678 - Functional units and principles for systems based on unique identifiers (referenced by ISO 22381).
- ISO 22300 - Security and resilience vocabulary (normative reference used in ISO 22381).
Keywords: ISO 22381, interoperability, object identification systems, counterfeiting, illicit trade, UID, authentication, trusted entry point, legacy systems, supply chain security.