A destination change is a custody act — and it should be signed
The destination field is not an administrative detail
Changing a destination changes who may receive the goods, which route is legitimate, where the carrier's responsibility ends and which party takes custody next. If that decision exists only in an email, a phone call or an overwritten TMS field, a fraudulent instruction can look like a routine update. The question is no longer only “what is the new address?” but “who had authority to redirect this lot, with what evidence and under which conditions?”.
Every change should create a new signed act
Instead of silently editing the previous record, the system should create an immutable event containing the lot identifier, previous destination, new destination, reason, requesting organisation and person, timestamp, sequence number, approval policy applied and a cryptographic reference to the preceding event. A digital signature binds the statement to an identity and makes later alteration detectable; it does not replace verification that the person was authorised to make the decision.
Strong authentication before signature
A signature is only as trustworthy as control of the account and key that produced it. A destination change should require step-up authentication proportionate to risk: at least two factors for sensitive operations, explicit confirmation of the content being signed and, for high-value loads or high-risk lanes, phishing-resistant authenticators and hardware-protected keys. NIST SP 800-63B distinguishes assurance levels and requires two factors at AAL2; AAL3 requires phishing-resistant authentication with a non-exportable key. These levels are a technical benchmark, not a universal transport mandate.
Authentication is not enough: authorisation matters
The system must verify that the signer represents an authorised organisation, that their role permits a change to that lot and whether its value, product or lane requires dual approval. A four-eyes rule can pair the shipper with the cargo owner, or the logistics operator with a pre-registered customer contact. Acceptance by the new consignee should generate another signed act without erasing the earlier instruction. Revocations, refusals and corrections enter as new events.
Blockchain preserves the lot-linked sequence
Each act can remain off-chain under access control while its hash, identifier, version and timestamp are anchored on blockchain. Sensitive commercial data can therefore remain selectively shared, while an authorised auditor can verify that the presented document is the one that was signed and identify which event preceded it. Blockchain does not prove that the signer was correct or stop a compromised credential; it makes the sequence, changes and conflicts harder to hide.
A seven-step operating flow
- Identify the lot, cargo unit, current destination and plan version.
- Accept the request only through an authenticated channel, never as a free-form email reply.
- Show the requester the previous destination, new destination, reason and impact before confirmation.
- Apply step-up authentication and authorisation or dual-approval policies.
- Sign the act, link its hash to the previous event and anchor the proof on blockchain.
- Send the instruction to the carrier and obtain signed acceptance from the new custodian.
- Compare the digital instruction with location, geofence, door, seal and time; any mismatch opens an exception.
Europe is already moving toward authenticated, auditable freight data
The eFTI Regulation creates a framework for electronic freight transport information. The European Commission describes certified platforms, secure links, access by authorised partners and selective sharing; the EUR-Lex summary also refers to authenticated access, operation logs and protection against corruption and theft. eFTI does not mandate blockchain or automatically classify a destination change as a custody act, but it confirms the direction: structured, controlled and auditable transport data.
Digital evidence must reach the road
The signed instruction defines legitimate intent; telemetry verifies execution. If the vehicle leaves the authorised route before a valid act exists, the door opens at an incompatible location or the cargo unit moves toward another geofence, the system should stop automatic acceptance and alert pre-validated parties. Connecting decision and behaviour narrows the window in which fraudulent diversion can look normal.