The chip that does only one job

A battery is a battery. It holds charge, it delivers current, and a device's firmware can read voltage and capacity directly from the cells. Nothing about that process requires the battery to identify itself to the device — unless the manufacturer has decided that identification is the point.

Authentication chips embedded in printer cartridges, power tools, medical devices and consumer electronics serve a single purpose that has nothing to do with performance: they verify that the accessory was made by, or licensed to, the original equipment manufacturer. A chip that passes the handshake gets to work. One that fails it — a third-party part, a refilled cartridge, a replacement battery from an independent supplier — is rejected. The host device typically displays an error, throttles performance, or refuses to function at all. The hardware may be electrically identical. It does not matter.

The practice is older than smartphones. Printer manufacturers pioneered cartridge authentication in the 1990s as inkjet margins compressed and the economics shifted toward consumables. Lexmark's use of the Digital Millennium Copyright Act to pursue Static Control Components over a chip that bypassed its cartridge authentication reached a federal appeals court; the Sixth Circuit ruled against Lexmark in 2004, finding that the DMCA's anti-circumvention provisions were not designed to lock in consumable markets. The ruling did not stop the practice. It changed the lawyers' approach.

Chronology

  1. 2004Sixth Circuit rules against Lexmark's DMCA use to block third-party cartridge chips
  2. 2021EU Ecodesign rules require spare-parts availability for large appliances; FTC policy statement names firmware and software locks as repair barriers
  3. Early 2020sEuropean Commission begins scrutinising parts-pairing practices under right-to-repair legislative push

How serialisation became the successor

A printer whose cartridges are no longer made by the manufacturer, and whose authentication chip rejects every third-party alternative, is not a printer anymore.

Cryptographic handshakes were the first generation. Serialisation — in which each individual component is paired by software to a specific device at the factory or at the point of service — is the second, and it is harder to route around. Parts pairing of this kind means that a replacement screen, a replacement battery, or a replacement camera module can be electrically genuine, sourced from the same production line, and still trigger a warning or a degraded mode because the serial number embedded in its controller does not match the record held in the host device's secure enclave.

Apple's introduction of parts pairing to the Touch ID sensor was defensible on security grounds — a fingerprint reader that could be swapped without authentication would create a real vulnerability. The same logic applied to Face ID. What attracted sustained criticism from iFixit and repair organisations was the extension of the same mechanism to components with no plausible security function: batteries, displays, cameras. When iOS introduced warnings for non-Apple-matched batteries and later for third-party screens, the security argument had been stretched to cover supply-chain exclusivity. The European Commission and several national regulators began scrutinising these practices as the right-to-repair legislative agenda gathered pace in the early 2020s.

The difference between a security architecture and a lock-in architecture is whether the check is necessary for the device to function safely, or whether it exists to make a functioning part fail. That distinction is not always clear at launch. It tends to become clearer over time, when the manufacturer's own service network cannot supply parts and the authentication system means nothing from the aftermarket will work either.

A disassembled smartphone with battery and circuit boards laid out on a repair mat
Adhesive assembly and proprietary fasteners raise the cost of opening a device far above the cost of the part inside it. Glue instead of screwsPhoto: Fotografia Lui Vlad / Pexels

What it costs when the accessory market collapses

The consumer cost of authentication lock-in is paid slowly and then all at once. For the first year or two of a device's life, first-party accessories are available, they are expensive, and the authentication system is invisible — it only fires when someone tries to use something cheaper. The cost becomes visible when the device is out of warranty and the manufacturer's accessories are discontinued.

A printer whose cartridges are no longer made by the manufacturer, and whose authentication chip rejects every third-party alternative, is not a printer anymore. A power tool whose proprietary battery pack has been discontinued, and whose battery management system refuses to charge a compatible cell from any other source, is a paperweight with a trigger. The device's residual value — whatever it would fetch on the secondhand market, whatever use it still had — collapses the moment the authenticated accessory supply ends. The hardware may have years of physical life remaining. The authentication system ends it early.

Medical devices illustrate this at its sharpest. Insulin pump manufacturers have used proprietary cartridge authentication to prevent patients from using lower-cost supplies; the right-to-repair movement in the United States specifically named medical devices in several state legislative proposals, precisely because the authentication lock-in there has direct clinical consequences, not merely financial ones.

E-waste is the residue. A device bricked by an authentication failure — whether from a discontinued accessory line, a firmware update that tightened the handshake, or a third-party part that used to work and no longer does — becomes e-waste sooner than its physical components would require. The authentication chip does not degrade. The cells, the motor, the printhead, the logic board may all be serviceable. The chip that checks who made them ends their useful life regardless.

The regulatory pressure that is building slowly

The European Commission's Ecodesign Regulation, which covers a widening range of product categories, includes requirements for spare-parts availability and — increasingly — for software not to be used as a barrier to repair. The 2021 rules covering large household appliances required manufacturers to supply spare parts for a defined period after a product's discontinuation. The regulation does not yet mandate that authentication systems be disabled when first-party accessories leave the market, which is the specific failure mode that turns a serviceable device into waste.

In the United States, the Federal Trade Commission's 2021 policy statement on repair restrictions identified software and firmware locks as a recognised barrier, and the agency committed to more active enforcement against practices that restrict repair. That statement covers authentication systems used to foreclose independent repair. Translating a policy statement into enforcement actions against specific products has moved slowly.

The standards bodies offer a partial answer. The Zigbee Alliance — now the Connectivity Standards Alliance ↗ — built a radio protocol whose specification is open enough that accessories and hosts from different manufacturers interoperate without proprietary handshakes. That model works when a standards body can define the interface before manufacturers have an incentive to lock it. In markets dominated by a single platform owner — printing, smartphones, power-tool batteries — the incentive to lock arrived before any neutral party could define an open interface.

What the lock-in mechanism looks like

  • Authentication chip — a microcontroller embedded in an accessory whose sole function is to pass a cryptographic handshake with the host device
  • Parts pairing — serial numbers matched at the factory or service point; a replacement part with a non-matching number triggers warnings or degraded operation even if electrically identical
  • Firmware tightening — a host-device update that raises the bar on the handshake, failing accessories that previously passed
  • Discontinued accessory supply — the point at which the authenticated accessory becomes unavailable and no alternative is accepted; effective end-of-life for the host hardware

The authentication chip that checks who made an accessory will continue to exist as long as the economics reward it. What changes the calculation is legislation that makes the practice expensive, standards that make it unnecessary, and buyers who price the risk before they buy — who ask not just what the device costs today but what the accessory supply looks like in five years, and what happens to the hardware when that supply ends.

A pried plastic seam with adhesive stretched across it, macro
Designed, not accidental — Pairing, firmware and the sealed enclosure.Photo: Mario Spencer / Pexels