Introduction to PlyQR
PlyQR is a high-assurance dual-channel QR code engine developed in Rust. It enables embedding an encrypted, authenticated, and covert secondary payload inside a fully compliant ISO/IEC 18004 QR code.
When scanned with an off-the-shelf smartphone camera or commercial barcode scanner, a PlyQR symbol behaves exactly like an ordinary QR code, cleanly outputting the public message. Only authorized readers equipped with the 256-bit cryptographic key can extract and verify the hidden private payload.
The Challenge
Section titled “The Challenge”Standard QR codes are fundamentally unauthenticated and readable by anyone:
- Public Visibility: Every byte encoded in a standard QR code is visible to any scanner.
- Proprietary Hardware Lock-In: Traditional dual-layer QR codes (such as DENSO Wave SQRC) rely on proprietary optical scanner hardware and closed firmware keys.
- Counterfeiting & Tampering: Standard barcodes can be cloned, modified, or forged with ease.
PlyQR solves these challenges with pure software-defined cryptography and algebraic error-correction modulation, requiring zero specialized scanner hardware.
Dual-Channel Architecture
Section titled “Dual-Channel Architecture”PlyQR divides the capacity of an ISO/IEC 18004 QR symbol into two orthogonal channels:
+-------------------------------------------------------------+| PlyQR Symbol || || +---------------------------+ +------------------------+ || | Public Channel | | Private Channel | || | - Standard Byte Mode | | - 22-byte Magic Header| || | - ISO/IEC 18004 Compliant| | - ChaCha20-Poly1305 | || | - Any Camera/Scanner | | - RS Parity Modulation| || +---------------------------+ +------------------------+ |+-------------------------------------------------------------+1. The Public Channel
Section titled “1. The Public Channel”- Encoded using standard QR Byte Mode.
- Followed by a strict 4-bit standard terminator (
0000) and byte alignment. - Decodable by 100% of standard QR readers (iOS Camera, Android Google Lens, handheld laser scanners).
2. The Private Steganographic Channel
Section titled “2. The Private Steganographic Channel”- Padding Embedding: The unused area after the public terminator carries the protocol header and the primary segment of the private ciphertext.
- Differential RS Modulation: Larger payloads modulate Reed-Solomon error correction parity codewords in controlled budgets, leaving sufficient noise margins for physical scratch/stain tolerance.
- Authenticated Encryption: Sealed with ChaCha20-Poly1305 AEAD, binding the public content, QR version, and private payload together. Tampering with the public content invalidates the private payload.
Target Use Cases
Section titled “Target Use Cases”- Anti-Counterfeit Product Authentication: Brand luxury goods, pharmaceuticals, and automotive parts with a public verification URL while storing manufacturing secrets and cryptographically verifiable digital signatures in the private layer.
- High-Security Ticketing & Access Control: Public transit, concerts, and secure facilities. Scanners read basic seat info publicly, while gate validators verify cryptographic validity offline.
- Supply Chain Confidentiality: Public tracking numbers on carton labels, with confidential customer identity, price tiers, and customs data hidden in the private layer.
- Offline Cryptographic Tokens: Physical identity cards, air-gapped credentials, and multi-factor authentication tokens.