Plain-language summary

If the system asks “is this the same factory-made chip?” do not use a tag whose chip identity field can be edited. If the system asks “can I test how software behaves when MB10 contains a chosen value?” the special tag may be appropriate. The feature is useful in a controlled lab and risky as a shortcut in production.

The quickest suitability test

Ask what would go wrong if two tags returned the same chosen MB10 value. If the answer includes unauthorized entry, false authenticity, broken chain of custody, incorrect payment, safety risk or an untraceable record, a user-changeable TID should not be the identity foundation.

Then ask whether EPC, User memory or a backend mapping solves the real requirement. If it does, choose the standard mechanism. Special memory behavior is justified only when it is itself the object of an authorized test.

Application matrix: risk, failure mode and safer direction

ScenarioWhy changeable TID is a poor fitSafer engineering direction
Anti-counterfeit or brand authenticationThe design often assumes TID is manufacturer-controlled. User editability removes that evidence and a static value can be copied.Use a documented authentication-capable IC, controlled issuance and backend verification matched to the threat model.
Door, vehicle or equipment access controlA chosen static identifier is not proof of authorization. Reader range and orientation may also be uncontrolled.Use a credential system with appropriate cryptographic authentication, revocation and audit controls.
Toll, parking or third-party passage identityChanging another system's identifier can be unauthorized; higher power/shorter range also conflicts with moving portals.Use only identifiers issued by the system owner and hardware qualified for the lane or gate.
Pharma, medical, aviation or safety-critical traceabilityUndocumented silicon, writable identity and unqualified retention/lot behavior weaken validation and change control.Use documented, qualified components and a validated traceability architecture under the applicable quality system.
Immutable chain of custodyA user-controlled identity cannot by itself establish that the same physical IC remained attached throughout the record.Bind a factory-serialized or authenticated tag to signed, auditable backend events and physical controls.
High-speed conveyor encodingProgramming needs energy and dwell time; the stated special tag has shorter, reader-dependent range.Use production inlays and encoders qualified at real line speed, then verify every write.
Long-range gate or portal inventoryGeneration and antenna limitations can reduce margin; a best-case read does not prove repeatable passage performance.Select an inlay tuned for the object and portal, then conduct a site survey and population test.
Metal or liquid mountingA thin general-purpose inlay can detune or lose energy near these materials.Use an on-metal, spacer or application-specific construction tuned and tested on the real object.
Mixed-vendor middleware using MDID/TMNChanged model fields can cause capability lookup or custom-command selection to be wrong.Preserve genuine IC identity and store application identifiers in EPC/User memory.
Frequently changing business stateRepeated MB10 writes add energy, endurance and support uncertainty.Put state in a backend; use User memory only if offline portability is essential.

Why writable identity is not authentication

Authentication answers whether a party can prove possession of a secret or another property that an attacker cannot feasibly reproduce. A static memory value—even a long one—is merely data returned by the tag. If the value can be chosen and copied, equality proves only that two responses match.

A factory-permalocked serialized TID can strengthen a backend consistency check, but GS1's memory structure does not by itself turn TID into a cryptographic protocol. A changeable-TID tag removes even the manufacturer-controlled part of that assumption. It should therefore never be advertised as “more secure because the TID can be customized.”

Why chip discovery can fail when model fields are rewritten

GS1 reserves the MDID and TMN fields to identify the tag designer and model/capability set. Middleware may read those fields before enabling an optional or custom command. If an experimental tag returns the identifier of another model without implementing that model's behavior, the host can apply the wrong memory map or command sequence.

Controlled-lab rule

If a compatibility test needs a chosen MDID/TMN pattern, isolate the reader, tag population and data. Label the result as emulated/user-controlled. Do not introduce it into a production population where software treats the value as real chip discovery.

Why moving and long-range systems deserve a separate “no”

The supplied tags are reported to consume more power and to have shorter range than ordinary non-changeable-TID products. A fixed laboratory bench can compensate with distance, alignment and a high-power reader. A moving vehicle, conveyor or uncontrolled portal cannot guarantee those conditions.

At the edge of a portal field, a tag may inventory but fail a write. Polarization changes with object orientation, nearby material detunes the antenna, and dwell time is finite. If the business process needs only identification, a standard high-sensitivity production tag is the more direct and supportable choice.

Scenarios that can be appropriate

LAB

Authorized reader/software development

Exercise how a controlled application parses selected MB10 values and error states.

MIGRATION

Owned-system transition testing

Reproduce a legacy data shape in an isolated environment while designing a standards-aligned replacement.

OEM

Special component evaluation

Characterize memory, RF and command behavior for a defined product where the special semantics are documented.

EDU

Memory-model demonstration

Show the difference between transport commands and memory policy without presenting the tag as a normal factory TID.

Even in these cases, use the buyer's authorized identifiers, keep experiments isolated, and validate the exact sample, reader, firmware, antenna and lock behavior.

A procurement screen before requesting samples

  • The requirement specifically needs user-controlled MB10 behavior.
  • The application does not depend on TID being immutable or factory unique.
  • The buyer controls and can log the reader command path.
  • Short, reader-dependent write range is acceptable.
  • The tag will not be used to impersonate a third-party credential or identity.
  • A pilot can test memory boundaries, cold persistence and RF margin.
  • The quotation records generation, form factor, lot, exclusions and acceptance criteria.

If any of the first five checks fails, stop and redesign the data architecture before ordering.

Claims we will not make

Defensible

What can be measured

  • Selected MB10 words accept a defined payload
  • The value persists after a documented cold restart
  • A named reader/firmware succeeds under stated RF conditions
  • A pilot lot meets written acceptance criteria
Not defensible

What editability cannot prove

  • Factory uniqueness after the value is changed
  • Authentication or anti-cloning by itself
  • Compatibility with every Gen2 reader
  • Safety, regulatory or portal qualification without testing
Bottom line

Use a changeable-TID tag when you need to study changeable TID. Do not use it as a shortcut for security, traceability, access, long-range inventory or ordinary item numbering. In those jobs, the feature either removes a property you need or adds complexity you do not.

Validate a suitable experiment: Use the step-by-step changeable-TID test protocol ↗

Primary references and related analysis