Blockchain Review: Reza Ebrahimi on Blockchain-Based Product Authentication
Description
Blockchain Review: Reza Ebrahimi on Blockchain-Based Product Authentication
An interview with blockchain technology researcher Reza Ebrahimi
Blockchain technology is increasingly being explored as a way to improve the traceability and verification of products. But can a blockchain actually prove that a physical product is genuine? In his recent article, “Blockchain-Based Product Authentication: Concepts, Architecture, Applications, and Limitations,” blockchain technology researcher Reza Ebrahimi examines the architecture behind blockchain-based product authentication while emphasizing an important distinction: a blockchain can preserve and verify a digital record, but it cannot independently determine whether the physical object associated with that record is genuine.
For Blockchain Review, Noah Jansen discusses the subject with Reza Ebrahimi.
Noah Jansen: What led you to focus on blockchain-based product authentication?
Reza Ebrahimi: Product authentication is becoming increasingly important as commerce becomes more digital. Consumers may purchase products without interacting directly with the original manufacturer, while resellers, insurers, service providers, and other participants may later need evidence of provenance.
Traditional approaches such as serial numbers, certificates of authenticity, QR codes, RFID, centralized databases, and physical inspection can all play an important role. My interest is in understanding where blockchain can strengthen these existing mechanisms rather than treating blockchain as a complete replacement for them.
Noah Jansen: What does blockchain actually contribute to product authentication?
Reza Ebrahimi: The main contribution is the ability to create a persistent record that can be independently inspected and against which later information can be compared.
For example, an issuer can record a certificate identifier, product identifier, timestamp, issuer address, or cryptographic hash on a blockchain. A verifier can then compare information associated with the product against the blockchain record.
If the relevant cryptographic values correspond, we can establish that the checked information matches the recorded information. But that is different from proving that the original information was truthful.
Blockchain preserves a record; it does not independently determine whether the issuer entered false information.
Noah Jansen: So does a blockchain prove that a physical product is genuine?
Reza Ebrahimi: Not by itself. This is one of the most important distinctions in blockchain-based authentication.
A blockchain can strengthen the integrity and verifiability of an authentication record. However, the credibility of the original product information depends on the issuer, the data-collection process, the physical identification mechanism, and the governance surrounding the system.
If a counterfeit product can use a copied QR code or another duplicated identifier, the existence of a valid blockchain record does not necessarily mean that the physical object being inspected is the original object.
Noah Jansen: What role do smart contracts play?
Reza Ebrahimi: Smart contracts can provide the rules and operations required for certificate management.
For example, they can be used to register certificates, associate identifiers with issuers, record status changes, and implement rules concerning verification, transfer, freezing, or revocation.
However, smart contracts are not automatically secure simply because they run on a blockchain. They require secure development, appropriate access controls, management of privileged operations, and mechanisms for dealing with erroneous or compromised inputs.
Noah Jansen: Why shouldn’t all product information simply be stored on the blockchain?
Reza Ebrahimi: Storing every document directly on a blockchain is often inefficient or inappropriate. Blockchain networks can have storage limitations, transaction costs can increase with data volume, and sensitive information may not be suitable for public disclosure.
A hybrid architecture is therefore often more practical. The blockchain can store compact verification information, while larger or sensitive records are maintained elsewhere.
For example, distributed storage such as IPFS can be used for larger information objects, while the blockchain maintains references and verification-related values.
Noah Jansen: What is the most important connection between a physical product and its blockchain record?
Reza Ebrahimi: The physical-to-digital binding is critical.
A system needs a reliable method of connecting the physical product to its digital record. Depending on the application, this could involve serial numbers, QR codes, NFC tags, RFID, secure labels, embedded identifiers, or digital certificates.
The challenge is that a digital identifier can potentially be copied or transferred. Therefore, stronger authentication can benefit from tamper-resistant identifiers and procedures that make duplication or unauthorized transfer more difficult.
Noah Jansen: What would a typical blockchain-based authentication process look like?
Reza Ebrahimi: A general workflow can be described in several stages.
First, an authorized issuer creates the product identity and associated certificate. Relevant product or provenance information is then collected, and where appropriate, encrypted. A cryptographic hash or another compact verification value can be recorded on the blockchain.
Detailed documents may be stored off-chain. The customer or verifier then accesses the certificate through a QR code, identifier, web interface, or another mechanism. The verification system retrieves the relevant blockchain record and compares the supplied information with the recorded values.
Finally, the system presents the verification result together with information about the issuer and certificate status.
Noah Jansen: Which industries could benefit from this type of system?
Reza Ebrahimi: There are several potential applications, particularly where provenance and trust are important.
These include luxury goods, watches, jewellery, collectibles, limited editions, artworks, premium accessories, and other products where provenance can affect resale value.
The technology can also support warranty administration, authorized resale, service histories, and business-to-business supply-chain documentation. In e-commerce, authentication records can be associated with products or orders and made available to customers after purchase.
Noah Jansen: What are some of the biggest security concerns?
Reza Ebrahimi: Key management is particularly important. If an issuer loses control of a signing key, an attacker could potentially create records that appear legitimate.
A robust system therefore needs secure key storage, role separation, revocation procedures, monitoring, and recovery mechanisms. Smart-contract vulnerabilities can also affect certificate issuance and certificate-status management.
Privacy is another important consideration. Public blockchains should generally not be used to store unnecessary private information directly on-chain. A more privacy-conscious architecture can store hashes, references, or minimal verification data on-chain while keeping sensitive information under appropriate access controls.
Noah Jansen: What is the biggest misconception about blockchain-based authentication?
Reza Ebrahimi: I would say the misconception is that putting information on a blockchain automatically makes that information true.
Blockchain can provide integrity and auditability after information has been recorded. It does not guarantee that the information entered by an issuer was truthful, nor does it eliminate counterfeit products.
The complete authentication process depends on the entire chain of trust—from product identification and data collection to issuer authorization, blockchain recording, storage, and final inspection.
Noah Jansen: Where do you see the technology developing next?
Reza Ebrahimi: Future systems can combine blockchain records with more secure physical identifiers, decentralized identifiers, digital signatures, privacy-preserving cryptography, and interoperable product-data standards.
The objective should be to establish stronger connections between physical objects and their digital records while reducing the amount of sensitive information that needs to be exposed publicly.
The broader direction is therefore not simply “put authentication on a blockchain,” but to build a complete verification architecture in which blockchain is one component of a larger technical and governance system.
Noah Jansen: Finally, if you had to summarize your view of blockchain-based product authentication in one idea, what would it be?
Reza Ebrahimi: Blockchain-based product authentication should be understood as a verification architecture rather than a standalone anti-counterfeiting technology.
Blockchain can provide persistent and independently inspectable records. Smart contracts can automate rules. Distributed storage can accommodate larger information objects, while traceability structures can organize lifecycle information.
Together, these components can strengthen the integrity and auditability of product certificates. But successful authentication still depends on the credibility of the issuer, the product-identification mechanism, secure key management, privacy controls, and reliable governance.
The central distinction remains between proving that a digital record corresponds to a recorded issuer and proving that a physical product is genuine. Blockchain can materially support the former and contribute to the latter, but it does not independently solve the entire authenticity problem.
Blockchain Review
Interview conducted by Noah Jansen
About the researcher: Reza Ebrahimi is a blockchain technology researcher whose work examines blockchain architecture and its practical applications, including product authentication, traceability, smart contracts, distributed storage, and digital verification.

