# HXP-007 — Tamper, Transfer and Environmental Qualification

Status: Validation Protocol 0.1
Public article edition: 2026-09-09

## The question a tamper claim must answer

A signed carrier can retain valid data after it has been moved. Digital verification alone cannot establish that the carrier remains attached to the work with which it was commissioned. Tamper and transfer qualification evaluates this physical continuity: whether an attempted removal or substitution is reliably reflected in the signals that a verifier is required to inspect.

This protocol defines an evaluation framework. It does not declare any material, adhesive, carrier, or attachment assembly qualified merely because it appears in the platform. A useful claim identifies the particular attachment profile, substrate, service conditions, observation method, and evaluated attack set. A general assertion that a label is tamper-proof is outside this protocol.

Environmental qualification is inseparable from this question. Normal service must not routinely look like malicious transfer, while aging must not quietly make the assembly easier to move without detection. Both security behavior and ordinary durability need evidence.

## Define the commissioned assembly

The evaluated unit is the commissioned assembly, not an isolated sticker. It includes the carrier, its retention or attachment method, the relevant substrate or mounting component, and the signals expected to remain associated with that assembly. An optical feature that survives on a detached carrier can still identify the carrier while saying nothing about its present host.

Before testing, the dossier identifies the assembly's reference state, permitted installation variation, and intended service life or review interval. The identification should allow later readers to determine whether their assembly falls within the tested profile. Changes in substrate finish, mounting geometry, material formulation, or installation procedure may alter the result and require separate evaluation.

[HXP-008](/standards/conservation) defines candidate attachment families. Its artwork profile defaults to a frame, backing, mount, case, or transport capsule. A result about one of those components must not be presented as direct proof about the artwork's surface.

## Meaning of tamper-destructive

In this protocol, “tamper-destructive” means that a qualified removal attempt irreversibly breaks NFC continuity, invalidates registered optical fiducials or response, or both. The term is prohibited until the named attachment profile passes its dossier. Visible damage by itself is insufficient if the verification procedure ignores it or still accepts all required signals.

The detection mechanism and the claim must agree. If a profile relies on optical disruption, a successful NFC read alone cannot conclude that the attachment is intact. If a profile requires both channels, losing one channel is not permission to substitute the other without reporting the missing requirement.

Destruction is also a material consequence, not simply a software status. An application can record that a carrier was retired or replaced, but that record does not establish how the physical assembly behaved during removal. Physical tests and digital history support different parts of the evidence chain.

## Attack classes and the success condition

A successful undetected transfer is an attack that moves the commissioned identity to a non-enrolled host while all required verification signals still pass. This definition focuses evaluation on the security outcome rather than whether a particular removal looked difficult or left cosmetic damage.

| Attack family | Evaluation question |
| --- | --- |
| Peel, lift, cut, and delamination | Can identity-bearing parts leave the enrolled assembly without a required signal failing? |
| Heat, cold, humidity, and solvent exposure | Can altered material behavior defeat the attachment's continuity signal? |
| Antenna bridging or adhesive replacement | Can restoration of one component conceal the relevant transfer? |
| Carrier or optical-window transplantation | Does the verifier distinguish a moved valid component from the original assembly? |
| Package reconstruction and combined slow attacks | Does the claimed relationship survive a sequence beyond a single simple removal? |

The complete matrix also includes abrasion, flex, and impact. These are public test categories, not instructions for defeating a particular product. Confidential fabrication details, sensitive fixture settings, and operational exploitation recipes are not necessary for explaining the outcome being tested.

## Preregister the study and preserve failures

The study should define the attack set, specimen allocation, stopping rules, observations, and exclusion criteria before final evaluation. Each result must remain associated with its profile version and specimen history. A failed sample cannot be replaced without accounting for the failure simply because another specimen produces the desired behavior.

Controls are essential. Untreated genuine assemblies establish ordinary read behavior. Legitimately aged or handled assemblies show whether service conditions create false alarms. Known disrupted assemblies help establish whether the required verification procedure can recognize the intended failure state. Where feasible, blinded assessment reduces the risk that an operator's knowledge of treatment influences the reported outcome.

Sample independence also needs attention. Many attempts against a single assembly can reveal useful failure modes, but they do not automatically represent many independent manufactured units. Lot, substrate, installer, and treatment dependencies should be disclosed rather than hidden behind one large total test count.

## Environmental service envelope

Environmental evaluation covers service temperature, humidity, ultraviolet exposure, cleaning agents, skin oils and sweat, abrasion, bending and torsion, impact, corrosion, dye or plasticizer migration, residue, staining, and optical drift. The relevant categories depend on the declared use case. A protected gallery mount and a frequently handled leather item should not inherit identical assumptions.

The dossier records the permitted service envelope and what happens outside it. A carrier that still reads after a brief test may nevertheless have unacceptable long-term material interaction or altered security behavior. Conversely, an intact genuine assembly may become unreadable under an out-of-profile condition without having been transferred.

| Evaluation dimension | Required distinction |
| --- | --- |
| Function | Can the intended reader obtain a usable observation? |
| Security | Does a transfer cause a required signal to fail? |
| Material compatibility | Does the assembly damage or contaminate the host? |
| Stability | Does behavior remain within the declared envelope over exposure? |
| Recovery | Is replacement or service documented without inventing continuity? |

Profiles are qualified independently. Evidence from metal does not qualify leather, paper, paint, or artwork. Even within one substrate family, coatings and surface treatments can change the attachment's behavior.

## Combined aging and transfer tests

Security evaluation should consider specimens after relevant aging or handling, not only newly commissioned assemblies. Environmental exposure can change adhesion, brittleness, optical response, electrical continuity, or the relationship between components. Those changes may affect both legitimate usability and transfer resistance.

The order of events matters. A field-relevant sequence might include installation, ordinary handling, environmental exposure, inspection, and then an evaluated transfer attempt. The protocol should identify the actual sequence and its rationale. Results from different sequences should not be pooled as though they represented identical conditions.

Accelerated exposure is evidence under the chosen method; it is not automatically proof of an arbitrary number of years in every real environment. Any service-life interpretation needs a justified relationship between the test and the intended conditions. The article does not prescribe proprietary material recipes or unsupported acceleration factors.

## Conservation, repair, and replacement

An attachment can be difficult to remove while being inappropriate for an artwork. Security and conservation objectives sometimes conflict: irreversible destruction may be desirable in a disposable carrier but unacceptable on an original painted or paper surface. Qualification must therefore consider where destruction occurs and whether the host is protected.

A permitted repair or replacement changes the evidence story. The history should preserve the prior assembly, the authorized intervention, and the new relationship. It should not imply that a replacement carrier is physically continuous with a retired carrier. Inspection of the underlying work may supply additional evidence, but that evidence has its own method and authority.

For example, reframing a painting may legitimately retire a frame-mounted carrier. The artwork's signed digital record can remain valid while the old attachment claim ends and a new assembly is documented. This is an expected lifecycle event, not a reason to rewrite the original credential.

## Acceptance and uncertainty

The candidate certification requirement is no undetected transfer in the preregistered attack set, together with complete publication of sample selection, failures, exclusions, and confidence limits. Passing that requirement is a bounded experimental result. It is not a proof that every conceivable attacker, material variation, or future method will fail.

A public dossier should state which attacks were evaluated, the applicable population, and which conditions remain outside scope. It can publish outcomes and independent-review conclusions while retaining confidential specimen imagery or fabrication information under appropriate controls. Missing tests should appear as missing evidence, rather than being converted into favorable claims.

## Relationship to the wider platform

The verifier should preserve separate digital, carrier, optical, and attachment outcomes as described in [HXP-003](/standards/open-verifier). A genuine signed record with unvalidated physical continuity remains useful digital evidence; it is not sufficient for a claim that requires a qualified attachment.

[HXP-006](/standards/optical-puf) addresses unit-level optical correspondence, and [HXP-009](/standards/conformance) places physical qualification within the broader claim gates. The [ISO 22383:2020 overview](https://www.iso.org/standard/50285.html) provides relevant context for evaluating authentication solutions for material goods. This mapping does not state that Helix has been independently certified to that standard.
