Overview
ISO 22385:2023 - Security and resilience: Authenticity, integrity and trust for products and documents - provides guidelines to establish a framework for trust and interoperability using Electronically Signed Encoded Data Sets (ESEDS). The standard defines a governance and technical model to protect integrity across the supply chain of physical and related electronic documents, products, software and services to mitigate product fraud and counterfeit goods. ISO 22385:2023 is technology‑agnostic, voluntary, and designed to interoperate with existing identification, traceability and authentication systems.
Key technical topics and requirements
- ESEDS concept: structured data sets containing header, payload, signature and optional auxiliary data; can be embedded as printed marks or as machine‑readable codes (MRC), or carried as electronic data.
- Trust architecture: roles and responsibilities defined for the Trust Service Operator (TSO), Trust Service Providers (TSPs) and certificate authorities (CAs).
- Scheme governance: a core governance document created by the TSO that sets membership, roles, obligations and the operational rules for the ESEDS scheme.
- Technical specifications (TS1–TS5): recommended specifications covering confidence in TSOs, TSP service consistency, ESEDS creation interoperability, ESEDS verification interoperability, and document publishing interoperability.
- Organizational and lifecycle measures: documented lifecycle management processes that all actors must follow for secure issuance, update and revocation.
- Internal scheme resources: public, machine‑readable Trust Service List (TSL) and a manifest (use‑case descriptor in XML) to support online and offline verification and presentation.
- Directories and interoperability: four essential directories (e.g., list of participants) to enable global interoperation and unambiguous resolution of unique identifiers (UIDs).
- Verification modes: supports both online and offline verification through signed manifests and trusted entry points (TEP).
Practical applications and who uses the standard
ISO 22385:2023 is applicable to any organization involved in authenticating or protecting products and documents, including:
- Manufacturers and brand owners implementing anti‑counterfeiting measures
- Supply chain participants (distributors, logistics providers, resellers)
- Trust service operators, certificate authorities and TSPs
- Developers of verification tools, universal readers (TEP) and mobile apps
- Regulators, customs and law enforcement performing authenticity checks
- Certification bodies and standards implementers seeking cross‑sector interoperability
Typical applications: product authentication, secure document issuance, offline verification of goods, cross‑sector traceability, and integration of scheme‑agnostic reader apps.
Related standards and references
Keywords: ISO 22385:2023, ESEDS, electronically signed encoded data set, trust, interoperability, authenticity, integrity, counterfeiting, supply chain, TSO, TSP, TSL, manifest, machine‑readable code.