RFID Access Control
RFID Access Control
Cards, Fobs & Readers
Quick answer
On most rollouts, RFID access control systems use contactless RFID cards, key fobs and wristbands to grant or restrict entry to buildings, rooms, parking areas and secure zones. Proud Tek supplies the RFID credentials (from legacy 125 kHz EM4100 / HID Prox baseline through MIFARE Classic 1K mid-tier up to AES-128 MIFARE DESFire EV3 and HID iCLASS Seos enterprise-grade) that integrate with every major PACS platform — Genetec Synergis, Lenel S2 NetBox, Honeywell Pro-Watch, Software House C·CURE 9000, AMAG Symmetry, Bosch AEC, Gallagher Command Centre. Over OSDP v2.2 Secure Channel or legacy Wiegand, sized to UL 294 and NIST SP 800-116 Rev 1 PACS guidance.
- Credential options for every security level — 125 kHz proximity cards for basic access, MIFARE Classic for standard security, and MIFARE DESFire EV3 for high-security encrypted access.
- Multi-form-factor support. Standard ISO cards, key fobs, wristbands, and stickers that all work with your existing reader infrastructure.
- Compatible with the major access-control ecosystems in the installed base. Credentials regularly programmed for HID iCLASS / SEOS, Gallagher, Salto, Keri, Honeywell, Bosch and ASSA ABLOY reader families — send us a sample credential or the reader model and we confirm the chip and encoding format before production.
Featured Access Control Products
SKUs we typically deploy for access control. Tap a card for specs and samples.
At a glance
Use these short answers to decide whether this page matches the project before moving into the detail.
Credential silicon library — 4 security tiers from EM4100 to AES-128
Tier-1 LF baseline (EM4100 / HID Prox 26-bit / T5577 rewriteable / Indala FlexSecur) at 125 kHz: no cryptography, susceptible to commodity cloners, retained only for rep...
Form-factor catalogue — credentials we supply for every PACS endpoint
ISO ID-1 PVC card (CR-80, 0.76 mm) — printable employee badge with photo + ANSI INCITS 322 lifecycle. Composite PET-G / PVC card — 5-year cycle for student / hospital ID...
Next step
Ready to move forward? Start your inquiry to get specific answers for this project.
Order access control credentials- Reader hardware ecosystem — how credentials reach the PACS panel
-
- HID multiCLASS SE / OMNIKEY / Signo readers: 125 kHz + 13.56 MHz multi-frequency, OSDP v2.2 + Wiegand outputs, BLE / NFC mobile credential support.
- ASSA ABLOY Aperio wireless lock + IN120 standalone + HES electric strikes for door hardware integration.
- Allegion Schlage XE360 / NDE / LE wireless locks pairing to ENGAGE gateway and AD-Series readers.
- Salto SVN (Salto Virtual Network) and KS (Keys-as-a-Service) data-on-card / data-on-network architectures.
- Boon Edam revolving doors and turnstiles + dormakaba 540 / Argus tripod arrays for high-throughput entrances.
- PACS head-end systems — software platforms credentials enrol against
-
- Genetec Synergis (with Security Center unification of access + video + ALPR) for enterprise multi-site campuses.
- Lenel S2 NetBox / OnGuard (now part of HID-Carrier) for federal, healthcare and Fortune-500 enterprise.
- Honeywell Pro-Watch + WIN-PAK for industrial and commercial mid-market deployments.
- Software House C·CURE 9000 (Tyco / Johnson Controls) for global enterprise with deep video integration to American Dynamics / exacqVision.
- AMAG Symmetry, Gallagher Command Centre, Bosch Access Easy / AMS — additional regional and vertical-specialised PACS heads.
- Reader-to-controller protocol — OSDP v2.2 vs legacy Wiegand
-
- OSDP v2.2 (SIA-OSDP, IEC 60839-11-5): RS-485 multi-drop with AES-128 Secure Channel, bidirectional, supports firmware update, tamper monitoring and large card formats up to 2048 bits.
- Legacy Wiegand: unidirectional 5–12 V open-collector, capped at 26-bit / 37-bit formats, no encryption between reader and panel — vulnerable to ESPKey-class wire-tap attacks.
- Migration playbook: replace Wiegand panels with OSDP-capable controllers (Mercury LP-series, HID VertX V1000, ISONAS Pure IP-Reader) during normal refresh; keep dual-output readers during transition.
- OSDP Verified programme: SIA certifies readers / panels for v2.2 conformance — list of verified products is the procurement starting point.
- Mobile credentials — phone-as-badge alternative to plastic
-
- HID Mobile Access (Seos over BLE / NFC) — issued via HID Origo cloud, consumed by HID Signo / iCLASS SE multiCLASS readers.
- Apple Wallet employee badge (corporate) and student ID (Duke / Johns Hopkins / Univ. of Alabama early adopters) over NFC.
- Google Wallet pass on Android with secure-element NFC — pilot deployments since 2023.
- LEGIC mobile + Salto JustIN Mobile + Allegion Mobile Access — vendor-specific BLE mobile alternatives.
- Plastic credentials remain primary in industrial / construction / healthcare patient — phone is a complement, not a replacement, in 2026.
- Compliance, safety and accessibility framework
-
- UL 294 Standard for Access Control System Units — North American baseline for door-control hardware safety and reliability.
- NIST SP 800-116 Rev 1 — federal PIV credential use in PACS (mandates PKI-CAK / PKI-AUTH transactions for high-assurance areas).
- FIPS 201-3 Personal Identity Verification — credential issuance for federal employees and contractors.
- IEC 60839-11-1 / -11-2 — international functional and environmental requirements for electronic access control.
- ADA 2010 Standards — door operating force ≤5 lbf and reader mounting height 15–48″ for accessibility compliance.
- Vertical application matrix — where each tier deploys
-
- Corporate office: DESFire EV3 / Seos employee badge with photo, integrated time-and-attendance, secure print release and cashless vending.
- Residential MDU: MIFARE Classic / Plus key fob for main entrance, parking garage, gym, pool and trash room — managed by property-management cloud (RealPage / Yardi / AppFolio).
- Hotel / hospitality: MIFARE Plus EV2 or DESFire EV2 guest key for room doors, elevators, pool gates and gym (see hotel-key-cards solution for full PMS integration).
- Education K-12 + higher ed: composite PET-G student ID (5-year cycle) for dorm, library, dining hall, transit, athletics and campus print quota.
- Healthcare: DESFire EV3 staff badge with role-based access to medication rooms, narcotics safes (DEA 1306.07), operating theatres and patient ward doors.
- Industrial / construction: rugged epoxy fob or wristband for site gate, equipment rooms and ATEX Zone 2 areas — paired with biometric for two-factor.
- Anti-cloning and credential-security threat model
-
- EM4100 / HID Prox: cloneable in seconds with $30 Proxmark / Flipper Zero — recommended only for non-sensitive perimeters.
- MIFARE Classic Crypto-1: 2008 academic break (Garcia / de Koning Gans) — sector keys recoverable in minutes; avoid for new deployments.
- MIFARE DESFire EV1: deprecated (Random ID + 3DES vulnerable to side-channel) — replace with EV3 baseline.
- DESFire EV3 + Seos: AES-128 mutual auth + Secure Messaging EV3 + Random UID + Originality Signature — no public crack as of 2026.
- Operational defences: turn off Wiegand exposure (replace with OSDP), enable card-data diversification, disable open-format read, monitor for sequential CSN scans.
- Operational ROI and TCO drivers
-
- Credential lifecycle cost: $0.50–$1.00 per LF prox vs $3–$8 per DESFire / Seos card — but security incidents cost $25k–$500k each.
- Lost-card replacement: 8–15 % annual rate per US workforce — automated self-service kiosks (HID Crescendo / Idemia MorphoAccess) reduce help-desk load.
- Reader installation labour: $150–$400 per door depending on existing wiring; OSDP retrofits reduce subsequent re-cabling.
- Maintenance contracts: PACS head-end vendors charge 18–22 % annual SMA on licence; mobile credentials shift OPEX from plastic-card to subscription model.
- Audit and compliance: NIST 800-53 PE-3 / PE-4 / PE-6 and SOC-2 CC6.4 require documented physical access logs — PACS reporting modules deliver.
- Programming, encoding and personalisation services
-
- Card-body printing: Zebra ZC10L / ZXP Series 9 retransfer + Fargo HDP6600 + Evolis Avansia for full-colour photo ID with HoloKote / overlaminate.
- Chip encoding: HID Asure ID + Salto ProAccess SPACE + Lenel BadgeDesigner + EasyLobby Visitor encoding sequences.
- Pre-personalised supply: Proud Tek encodes facility code + cardholder ID range to PACS spec before despatch — no on-site encoding required.
- Anti-passback configuration: timed (regional / hard) and PACS-level enforcement — relevant for parking / data-centre cage / pharmaceutical clean-room access.
- Credential disposal: cross-cut shredding for printed cards; chip-destroy step optional for DESFire / Seos to satisfy ISO 27001 A.8.10 secure disposal.
- What this solution is NOT — adjacent scope clarifiers
-
- NOT a hotel guest key programme — see /solutions/hotel-key-cards/ and /solutions/hotel-rfid-access-control/ for PMS-integrated guest credentials with check-in / check-out lifecycle.
- NOT a parking / vehicle gate solution — see /solutions/rfid-parking-management/ and /solutions/vehicle-rfid-identification/ for UHF Gen2v2 hands-free vehicle access.
- NOT an event / festival wristband programme — see /solutions/rfid-event-access-control/ and /solutions/rfid-event-wristbands/ for Intellitix / Connect&GO / Tappit wristbands.
- NOT a key fob standalone product page — see /products/rfid-keyfobs/rfid-abs-keyfob/ family for SKU-level fob specs.
- NOT a logical access (computer / VPN / SSO) programme — covered under FIDO2 / smart-card login (PIV / CAC) systems outside this scope.
RFID credentials for access control systems
Every access control system is asked to do two contradictory things at once: keep the wrong people out, and never once make the right people wait at the door. A credential is the small object caught in the middle of that argument — it has to be cheap enough to hand out by the thousand, and hard enough to forge that nobody bothers. Most of the decisions below are really about where you want to sit on that line.
125 kHz proximity
EM4100 and HID-compatible cards for basic door access with legacy readers.
MIFARE Classic
13.56 MHz cards with sector-based memory for standard office and campus access.
MIFARE DESFire
AES-128 encrypted smart cards for government, data centers and hospitals.
Key fobs
ABS, epoxy, silicone and leather fobs for keychain-based access.
Wristbands
Silicone, fabric and PVC bands for gyms, water parks and events.
Dual-frequency
125 kHz + 13.56 MHz cards for legacy-to-modern system transitions.
Access control applications by sector
The credential family barely changes between verticals — what changes is which failure gets expensive. An office badge that misreads costs a few seconds of lobby grumbling; a medication-room door that fails open costs an audit finding. The notes below map each tier to the sector where it earns its keep — key-ring form factors get fuller treatment under RFID key fobs for access control, and elevator wiring specifics in RFID elevator floor access.
- Week 1 — Audit existing credential and reader inventory
Walk every door, log existing reader make / model / firmware / wiring (Wiegand vs OSDP), credential chip family (EM4100 / HID Prox / MIFARE Classic / DESFire / Seos), facility-code and cardholder-ID range. Identify ESPKey-vulnerable Wiegand runs and any MIFARE Classic populations slated for replacement.
- Week 2 — Define credential specification and chip-family decision
Pick the target tier per security zone — DESFire EV3 baseline for general office, Seos for federal / contractor mix, Plus EV2 for staged migration without forklift reader replacement — then fix the card / fob / wristband split and photo-ID printing needs per population.
- Week 3 — Select reader and panel hardware against PACS head-end
Match readers (HID Signo / OMNIKEY 5427CK / multiCLASS SE) and panels (Mercury LP-1502 / LP-2500, ISONAS Pure IP) to the incumbent head-end — Genetec Synergis, Lenel S2, Honeywell Pro-Watch, C·CURE 9000, AMAG Symmetry or Gallagher — and verify OSDP v2.2 conformance on the SIA OSDP Verified list.
- Week 4 — Pilot 5–10 doors and validate end-to-end transaction
Pilot one entrance, one secure-zone door, one elevator, one revolving door and one ATEX / industrial cabinet. Validate AES Secure Channel transactions, OSDP tamper events, photo-ID workflow, lost-card hot-list propagation, anti-passback and two-person rule.
- Month 2 — Personalise and despatch credential population in waves
Print + encode in waves of ≤500 to manage helpdesk load; ship pre-personalised with facility code + cardholder-ID range encoded; hook provisioning to the HR feed (Workday / SuccessFactors / SAP HCM); issue temporary credentials at the security desk for visitor / contractor / replacement workflows.
- Month 3 — Cut over Wiegand-to-OSDP and decommission legacy
Replace Wiegand cabling segment by segment; enable OSDP Secure Channel with a rotated install-key; retire legacy MIFARE Classic populations via dual-credential transition; push PACS and reader firmware OTA via OSDP.
- Month 4 — Mobile-credential rollout for early-adopter cohort
Enable HID Mobile Access (Origo) or vendor mobile (Salto JustIN / Allegion Mobile / LEGIC mobile) for executive + IT + facilities + frequent-visitor cohorts; validate Apple Wallet employee-badge issuance where the reader fleet is Apple-Wallet-Verified. Plastic remains primary; phone is the opt-in complement.
- Quarter 2 onward — Operate, audit and refresh on 5-year cycle
Quarterly PACS audit (SOC-2 CC6.4 / NIST 800-53 PE-3 / ISO 27001 A.7.2 evidence pull); annual credential reissue for damaged / lost cards; 5-year card-body refresh for student / hospital ID populations; 7–10-year reader hardware refresh; continuous OSDP firmware OTA.
- Corporate offices: employee badges with MIFARE DESFire for door access, elevator control, time and attendance, secure printing and cashless vending.
- Residential buildings: apartment access cards or key fobs for main entrance, parking garage, gym, pool and common area doors.
- Hotels and resorts: guest key cards for room doors, elevators, pool gates, gym access and spa facilities, encoded for check-in to check-out duration.
- Education: student and staff ID cards for building access, library entry, meal plans, printing credits and campus transit.
- Healthcare: staff badges for restricted area access, medication rooms, operating theaters and patient ward doors with role-based permissions.
- Industrial and construction: rugged key fobs and wristbands for site gate access, equipment rooms and restricted zones in harsh environments.
Credential silicon deep-dive — four security tiers explained
Four tiers, one question: how expensive is the attack you are defending against? The ladder below runs from silicon a hobbyist tool clones during a coffee break up to AES-128 mutual authentication with no public break — and the bullets put part numbers to every rung.
- Tier-1 (125 kHz LF) — EM4100 / EM4102 / HID Prox 26-bit H10301 / HID ProxII / Indala / Casi-Rusco / AWID / Keri PSK / KeriPRX: simple LF inductive coupling at 125 kHz, ISO 11784/11785 lineage, 64-bit manufacturer ID + 26-bit Wiegand facility code. No cryptography. Cloneable in <60 seconds with $30 Proxmark3 RDV4 / Proxmark Easy / Flipper Zero / Iceman fork. Retained only for legacy maintenance — every NIST SP 800-116 Rev 1 audit flags LF as a deficiency for sensitive areas.
- Tier-2 (13.56 MHz HF Classic) — NXP MIFARE Classic 1K / 4K (S50 / S70 silicon): ISO/IEC 14443-A air interface, 1KB or 4KB EEPROM partitioned into sectors with Crypto-1 stream-cipher 48-bit keys. Crypto-1 academically broken in 2008 (Garcia, de Koning Gans, Verdult — Radboud University Nijmegen) — sector keys recoverable in <1 minute via nested + darkside + hardnested attacks (mfoc, mfcuk, hardnested). Still widely installed but recommended for replacement during next refresh cycle.
- Tier-3 transitional (13.56 MHz HF AES) — NXP MIFARE Plus EV1 / EV2 (X / SE / S variants): backwards-compatible MIFARE Classic emulation mode + AES-128 SL3 mode. SL3 (security level 3) provides AES mutual authentication while SL1 keeps Crypto-1 compatibility so legacy readers still read the card during migration. Common procurement pattern for organisations doing reader refresh without forklift swap.
- Tier-4 enterprise (13.56 MHz HF AES + file-based) — NXP MIFARE DESFire EV2 / EV3 (D40 → D41 → D81 silicon): ISO/IEC 14443-A + ISO/IEC 7816-4 file-based directory (up to 28 apps × 32 files per app), AES-128 mutual authentication, 3DES legacy mode, Secure Messaging EV2, Random UID, Originality Signature. EV3 adds Transaction Timer + SUN message + Proximity Check against relay attacks. No public break as of 2026.
- Tier-4 alternative — HID iCLASS Seos: HID's proprietary AES-128 credential on Seos silicon (Infineon SLE 78), programmed via HID Origo or HID-managed encoding. Same trust level as DESFire EV3; backwards-compatible with iCLASS legacy (Pico / Standard / SE) on multiCLASS SE readers; federal PIV-Auth / PKI-CAK / PKI-AUTH compliant.
- Tier-4 alternative — LEGIC advant (Kaba Group, Switzerland): 13.56 MHz file-based credential, AES-128 + 3DES; common in European corporate / hotel / leisure estates, with LEGIC Connect managing the credential lifecycle.
- Newer entrant — NTAG 424 DNA (NFC Type 4, AES-CMAC SUN message): consumer-grade NFC tag with cryptographic per-tap signing — used for brand-protection and tap-to-verify access in low-volume executive / VIP applications. NOT a direct DESFire EV3 substitute for high-throughput PACS doors.
- Newer entrant — Apple Wallet / Google Wallet credential: phone secure-element-backed, provisioned via HID Origo / Salto JustIN / Allegion Mobile / LEGIC Connect. Cryptographically Tier-4 AES-128 equivalent, but requires an Apple-Wallet-Verified or Google-Wallet-compatible reader fleet.
PACS head-end integration — Genetec / Lenel / Honeywell / C·CURE / AMAG / Bosch / Gallagher
A credential is only as trustworthy as the head-end that enrols it. The stack below traces the full path — credential to reader to panel to PACS software — and the platform notes that follow say which vendors dominate each estate, so you can buy cards that match the software you already run instead of discovering the encoding format after despatch.
| Platform | Estate / positioning | Panels + readers | Video & mobile hooks |
|---|---|---|---|
| Genetec Synergis (Security Center) | Unified enterprise — access + Omnicast video + AutoVu ALPR + Mission Control + KiwiVision; Federation for multi-site; Cloud Link hybrid | Mercury LP-1502 / LP-2500 / LP-4502; ISONAS Pure IP; HID multiCLASS SE / Signo / iCLASS Seos | OSDP v2.2 + Wiegand; AES mobile credentials via HID Origo |
| Lenel S2 OnGuard / NetBox | Fortune-500, federal + healthcare default; Carrier-owned (HID Global merged into Carrier Global 2024); OnGuard on Windows Server, NetBox = SMB / mid-market | Mercury LP; Lenel LNL-X / LNL-3300 | Milestone XProtect + Genetec Omnicast video; BlueDiamond mobile + LNL-Wave readers |
| Honeywell Pro-Watch + WIN-PAK | Pro-Watch = enterprise tier (Windows Server + SQL); WIN-PAK = SMB | PW6K1IC / PW5K2 (Pro-Watch); NetAXS / NetAXS-123 (WIN-PAK); HID + Honeywell IFP readers | Honeywell MAXPRO VMS; Pro-Watch Mobile |
| Software House C·CURE 9000 | Tyco / Johnson Controls global enterprise; Windows Server | iSTAR Ultra / iSTAR Edge / iSTAR Pro; HID readers | American Dynamics victor + exacqVision; C·CURE Go Reader mobile |
| AMAG Symmetry | Allied Universal-owned (ex-G4S); transportation, utilities, UK government | EN-2DBC panels; HID + AMAG M2150 readers | Symmetry CONNECT mobile; Visitor Management + GUEST workflows |
| Bosch AMS / BIS | AMS = modern enterprise tier (replaces legacy APE); BIS unifies access + fire + intrusion + video | Bosch AMC2 / AMC IP controllers; Bosch + HID readers | BIS building-wide integration |
| Gallagher Command Centre | New Zealand vendor; critical infrastructure, prisons, mining, government | Gallagher Controller 6000; T-series + HID readers | Mobile Connect; Class 4 / Class 5 perimeter-fence integration |
| Cloud-first mid-market | Brivo (cloud-only SMB + property management), Openpath (now Avigilon Alta), Kisi, Verkada (cloud + video unified), Feenics (now Honeywell Pro-Watch Cloud), ProdataKey, DMP Entré | Vendor-specific cloud panels | Cloud dashboards; unified video (Verkada) |
OSDP v2.2 migration from Wiegand — why and how
Wiegand is a 1974 protocol still guarding 2026 doors, and it shows: unencrypted, one-way, and tappable with a device that costs less than the door it defeats. The comparison below makes the case for OSDP v2.2; the bullets underneath are the migration playbook, cabling and pitfalls included.
Wiegand (1974)
- Two-wire D0 + D1 open-collector 5–12 V; unidirectional reader → panel
- Formats: H10301 26-bit / H10302 37-bit / HID Corporate 1000 35-bit — 64-bit practical ceiling
- No encryption, no tamper detection, no firmware update path
- ESPKey wire-tap (~$200) captures every credential read at panel-side wiring
- Cabling: 18 AWG 6-conductor + drain; max ~500 ft per run
- Reader draw 50–150 mA at 12V
OSDP v2.2 (SIA 2020 / IEC 60839-11-5)
- RS-485 multi-drop; up to 32 readers per home-run; bidirectional messaging
- Large card formats up to 2048 bits
- AES-128 Secure Channel + tamper events + firmware OTA + biometric template push
- LED + buzzer control and ICMP-style ping supervision
- Cabling: 22 AWG twisted-pair shielded RS-485 (Belden 1502R or equiv); max ~4000 ft — existing 6-cond Wiegand cable can carry OSDP on the 2 unused pairs with terminators at each end
- Reader draw 100–250 mA; PoE+ (802.3at) to the panel, PoE++ (802.3bt) for biometric readers (HID Signo Bio, Suprema FaceStation)
- OSDP Verified — SIA certifies readers + panels for v2.2 conformance via independent lab test (UL / Intertek); the verified list at sia.org/osdp is the procurement starting point. Major verified vendors: HID Signo, Mercury LP, ISONAS Pure IP, Allegion AD-Series, Identiv uTrust, Farpointe Pyramid.
- Common pitfalls — install-key left at factory default (the most common audit finding); OSDP v1.x readers (no Secure Channel) mixed with v2.2 panels; unshielded RS-485 run next to PoE cabling; missing termination resistor at the far end of the bus.
- Phase 1 — audit Wiegand runs; flag ESPKey-exposed segments (typically ceiling plenum at panel side)
- Phase 2 — swap readers to OSDP-Verified dual-output (Wiegand + OSDP) so existing panels keep working
- Phase 3 — replace panels (Mercury LP-series / HID VertX V1000 / ISONAS) during normal refresh; switch readers to OSDP-only output
- Phase 4 — enable AES Secure Channel with a rotated install-key per OSDP IS-Key Distribution best practice (don't ship default 0x00 keys)
Mobile credentials — HID Origo / Apple Wallet / Aliro 1.0 unified standard
Phone-as-badge is real and growing — and still a complement to plastic, not a replacement. The map below shows today's vendor-cloud silos and where the Aliro standard is positioned to dissolve them; plan the next reader refresh with that horizon in mind.
- Plastic persists — mobile credential is opt-in for ~10–25% of a population (executive / IT / facilities / frequent visitors). Plastic remains primary where phones don't go: industrial / construction (no phone on body), healthcare patient (sterile / wash protocol), K-12 (phone restriction policy), short-term visitor / contractor (no enrollment time), hospitality guest (Apple Wallet hotel keys still <2% of stays as of 2026).
| Platform | Protocol / tech | Consumed by | Typical estate |
|---|---|---|---|
| HID Mobile Access (Origo cloud) | SEOS-over-BLE proprietary + NFC | HID Signo; iCLASS SE multiCLASS; OMNIKEY 5427CK | Strongest enterprise installed-base as of 2026 |
| Salto JustIN Mobile | BLE proprietary; SVN data-on-card / data-on-network | Salto locks | Hospitality + multi-family residential |
| Allegion Mobile / Schlage Mobile | BLE to ENGAGE-enabled wireless locks | Schlage NDE / LE / Control / XE360 | K-12 + higher-ed |
| LEGIC Connect | BLE / NFC managed platform | LEGIC advant readers | European corporate + leisure |
| Apple Wallet employee badge | NFC + Apple Pay-style express mode (Face ID not required for tap); Apple ID + Apple Business Manager | Apple-Wallet-Verified readers: HID Signo, Schlage, LEGIC, Salto, dormakaba, ASSA ABLOY, Kastle | Corporate since 2022; student ID since 2018 (Duke, Johns Hopkins, U. Alabama, Temple, Vanderbilt + 30+ campuses by 2026) |
| Google Wallet pass | Android secure-element NFC (Trusted Execution Environment) | Pixel + Samsung Galaxy + Xiaomi devices; HID Origo support extended 2024+ | Android enterprise cohorts |
Anti-cloning threat model + operational defences
Every attack on this list has a commercial tool behind it, which is exactly why the defence column matters more than the scare column. The map below pairs each threat with its counter; and if a credential in your estate has already been copied, what to do after an access card is cloned walks through the recovery sequence.
- Threat — LF 125 kHz cloning: Proxmark3 RDV4 / Iceman + Flipper Zero / ChameleonMini reads EM4100 / HID Prox / Indala / Casi-Rusco / AWID / Keri raw card data in <60 seconds; writes to T5577 or replays via Flipper. Defence: migrate to HF DESFire EV3 / Seos; deploy LF + HF dual-tech readers during migration; monitor PACS for unusual access patterns (same credential at two distant doors within window).
- Threat — MIFARE Classic Crypto-1 break (2008+): mfoc nested attack recovers sector keys in 1–5 min with one known key; mfcuk darkside needs none; cloning to blanks or magic-UID cards is trivial. Defence: migrate to DESFire EV3 / Seos / Plus SL3 — or run Classic in UID-only mode and treat it as a Tier-1 surrogate, not a cryptographic credential.
| Threat | Vector / tool | Defence |
|---|---|---|
| Wiegand wire-tap | ESPKey (~$200) clipped to D0 / D1 at panel side; later replay via Proxmark or Flipper | OSDP v2.2 Secure Channel; metal conduit on wire runs; tamper detection on reader back-box |
| Relay attack on HF cards | ProxGrind ChameleonUltra relay-pair extends DESFire / Seos read range across a building | Proximity Check (DESFire EV3 / Seos) RF timing; recent biometric / PIN rule at high-security doors; geo-fence credentials to reader zones |
| Sequential CSN harvest | Brute-force collection of CSN / UID values — visible without authentication on most chips | Random UID (DESFire / Seos) so every transaction returns a different UID; cardholder lookup via encrypted file access |
| Lost / stolen credential | 8–15% annual rate in white-collar workforces | Hot-list propagation to all readers within 1 minute (Genetec / Lenel / Honeywell native); revocation tied to HR offboarding feed (Workday / SuccessFactors); self-service replacement kiosk |
| Insider credential abuse | Door propping, badge sharing, access outside role | Door-prop alarm >30s + tailgating detection (Optex / Boon Edam); quarterly role reviews against HR feed; two-person rule at data-center cage / narcotics safe |
| Reader / panel firmware compromise | Rare but documented — CISA advisories on HID Aero / Mercury / Allegion | Firmware currency via OSDP OTA; vendor PSIRT subscriptions (HID, Allegion); air-gap PACS server where possible; monitor PACS-subnet outbound traffic |
| Cloud PACS account takeover | Phishing or MFA bypass on Brivo / Openpath / Kisi / Verkada admin accounts | FIDO2 / WebAuthn for admin access; SSO conditional access (Okta / Azure AD); separate admin vs enrolment roles; 12+ month audit-log retention |
Compliance + standards — UL 294 / NIST SP 800-116 / FIPS 201 / NDAA 889
Standards are how a PACS purchase survives its audit. The list is long because the estates are varied — federal buyers start at FICAM and FIPS 201-3, commercial buyers at UL 294, and everyone meets the ADA at the door.
| Standard | What it covers | Why it matters at purchase |
|---|---|---|
| UL 294 (8th edition, 2023) | Access Control System Units — attack resistance, line security, endurance; performance Levels I–IV | North American baseline; required for AHJ approval in most US jurisdictions (AHJ may add UL 1076 / UL 681); enterprise panels + readers ship at Level IV |
| UL 1610 / UL 2050 | Federal SCIF / closed-area applications integrating access control with intrusion alarm | UL 2050 explicitly covers National Industrial Security Systems (DoD-spec) |
| NIST SP 800-116 Rev 1 (2018) | PIV credentials in facility access — PKI-CAK / PKI-AUTH / BIO / BIO-A transactions | High-assurance areas require PKI-AUTH (PIN + biometric + PKI signature) — drives Seos / DESFire AES-128 baseline + PIV middleware (ActivClient, 90Meter) |
| FIPS 201-3 (2022) | Federal PIV credential format, cryptographic baseline, lifecycle | Companion FIPS 140-3 validation required for the HSM behind issuance |
| FICAM / GSA APL | GSA-managed Approved Products List of PACS, readers, panels, middleware | Federal procurement must be from the APL |
| NDAA Section 889 (effective 13 August 2020) | FAR 52.204-25 — bars federal purchase / use of products with Huawei, ZTE, Hytera, Hikvision, Dahua components | Reader OEMs must supply NDAA-compliant attestation (HID, Allegion, Mercury Security publish public attestations) |
| TAA (Trade Agreements Act) | Products must be made in TAA-designated countries (US + EU + Japan + Israel + others; China, Russia, Iran, N. Korea, Cuba, Syria excluded) | Affects card-body printing, lamination and chip sourcing on federal buys |
| GDPR Art. 28 (EU) + CCPA / CPRA (California) | Controller / processor framework for cardholder data — enrolment, access logs, retention | Signed Data Processing Agreement (DPA) required with cloud-PACS vendors (Brivo / Kisi / Openpath / Verkada) |
| ADA 2010 Standards | Door operating force ≤5 lbf; reader mounting 15–48 in above floor; audible + visible feedback on release | ADA-compliant credential-issue process for cardholders with disabilities |
| IEC 60839-11-1 / -11-2 | International functional + environmental requirements for electronic access control | Basis for EU member-state certification |
| ISO/IEC 27001 A.7.2 + A.8.10 | Physical access + secure disposal controls in the InfoSec management system | Pulls PACS logs + credential disposal records into SOC-2 / ISO 27001 audit scope |
Programme economics + TCO + procurement leverage
The credential is usually the cheapest line on the invoice. The cost anatomy below shows where a typical enterprise refresh budget actually lands, and the bullets give the unit-price ranges — and the consolidation levers — to negotiate against.
- Credential unit cost at scale (10K+ qty): EM4100 LF card $0.40–$0.80; MIFARE Classic 1K $0.80–$1.20; MIFARE Plus SE $1.50–$2.50; DESFire EV3 $2.80–$5.50; Seos $3.50–$8.00; printable employee badge (any chip) +$0.20–$0.50 for card body. Key-fob form factor +20–50% on chip cost.
- Year-1 anatomy, 200-door refresh: 5,000 DESFire EV3 cards × $4 = $20K; 200 OSDP readers × $400 = $80K; 25 Mercury LP-2500 panels × $2.5K = $62K; install labour 200 × $300 = $60K; Genetec Synergis perpetual + SMA = $150K Y1; integration services $50K. Year-1 total ~$420K, ~$2.1K per door.
- Annual recurring (Year 2+): SMA $30K; credential replacement (10% annual) 500 × $4 = $2K; mobile-credential subscription 250 cohort × $5 = $1.3K — total ~$33K/year. A self-service kiosk (HID Crescendo + photo + encoder) cuts replacement help-desk minutes from 15 → 3.
- Compliance avoidance value: PCI-DSS physical-access non-compliance fines $5K–$100K per breach; HIPAA physical safeguard non-compliance up to $50K per violation; NIST 800-53 PE-3 / PE-4 / PE-6 deficiency findings drive FedRAMP / FISMA delays worth millions in lost contract value.
- Consolidate SKUs — 3–5 strategic chip + form-factor combos covering 90% of volume: 12–25% unit-price improvement vs fragmented spec sprawl
- Commit multi-year + volume: another 10–20%
- Buy pre-personalised (delivered ready-to-issue): saves $0.50–$2.00 per credential vs on-site encoding
| Line item | Typical range | Notes |
|---|---|---|
| Reader — legacy 125 kHz | $80–$180 | — |
| Reader — HF 13.56 MHz, Wiegand-output | $180–$350 | — |
| Reader — OSDP-Verified multi-tech | $250–$600 | — |
| Reader — biometric | $600–$2,500 | HID Signo Bio and Suprema FaceStation 2; ZKTeco SpeedFace tops out near $2,500. |
| Panel — legacy 4-door | $400–$900 | HID Edge / Allegion AD-300 |
| Panel — enterprise 8-door | $1,800–$3,500 | Mercury LP-2500 / Lenel LNL-X |
| Panel — large enterprise | $4,000–$8,000 | Mercury LP-4502 / HID VertX V1000 at the top of the tier, up to $8,000. |
| Installation labour, per door | $150–$400 (existing wiring) / $400–$900 (new conduit + cabling) | Add $80–$200 per door for OSDP cabling reuse / replacement |
| PACS software — SMB cloud, per door annual | $50–$150 | Brivo / Kisi / Openpath |
| PACS software — enterprise on-prem, per door perpetual | $200–$600 + 18–22% annual SMA | Genetec / Lenel / C·CURE / Pro-Watch / AMAG / Gallagher; federal FICAM adds 30–60% premium |
| Mobile credential, per credential per year | $3–$8 (HID Origo) / $4–$10 (Salto JustIN) / $4–$8 (Allegion) | Apple Wallet corporate: $0 platform fee but requires Apple Business Manager + Apple-Wallet-Verified reader fleet |
Useful next pages
Use these linked product, guide and comparison pages to keep the next click specific and practical.
Access control credential products
Browse RFID cards and fobs for access control.
Industry landings — where these credentials deploy
Sector pages that elaborate access-control chip and reader choices per vertical.
Related comparisons and migration guidance
Compare pages for the chip-family and frequency-band decisions this solution depends on.
FAQ
Which RFID chip should I use for access control?
For basic access (apartment, small office): EM4100 at 125 kHz is the most cost-effective. For standard security (corporate, campus): MIFARE Classic 1K is the most widely deployed but is cryptographically broken — recommended for replacement during refresh. For high security (government, data center, healthcare): MIFARE DESFire EV3 or HID iCLASS Seos with AES-128 mutual authentication is the 2026 baseline per NIST SP 800-116 Rev 1. We help you choose based on your existing readers and security requirements.
Can you supply cards compatible with our existing HID or Gallagher system?
Yes. We produce cards and fobs compatible with HID iCLASS, HID SEOS, Gallagher Command Centre, Salto SVN/KS, Keri, Honeywell Pro-Watch, AMAG Symmetry, Lenel S2 NetBox, Software House C·CURE 9000 and Genetec Synergis. Send us a sample credential or tell us your reader model and PACS head-end, and we will match the chip, encoding format and facility-code/cardholder-ID range exactly.
How secure are RFID access control cards against cloning?
Security varies by chip. EM4100 and HID Prox 26-bit cards have no encryption and can be cloned in seconds with a $30 Proxmark or Flipper Zero — suitable only for low-security perimeters. MIFARE Classic Crypto-1 was academically broken in 2008 — sector keys can be recovered in minutes. MIFARE DESFire EV1 is also deprecated. MIFARE DESFire EV3 and HID iCLASS Seos use AES-128 mutual authentication with Random UID and Originality Signature, with no public crack as of 2026. For any sensitive facility, we recommend migrating to DESFire EV3 or Seos and replacing Wiegand reader-to-panel wiring with OSDP v2.2 Secure Channel.
What is OSDP v2.2 and do I need it?
OSDP (Open Supervised Device Protocol) v2.2 is the SIA standard (also published as IEC 60839-11-5) for reader-to-panel communication that replaces legacy Wiegand. It runs over RS-485 multi-drop, supports AES-128 Secure Channel encryption, bidirectional messaging, tamper detection, large card formats up to 2048 bits and over-the-wire firmware update. Wiegand is unencrypted and vulnerable to ESPKey-class wire-tap attacks — for any new deployment we recommend OSDP-Verified readers and panels (HID Signo, Mercury LP-series, ISONAS Pure IP, HID VertX V1000).
Should we switch to mobile credentials and abandon plastic cards?
In 2026, no — mobile is complementary, not replacement. Mobile credential (HID Origo / Salto JustIN / Allegion Mobile / LEGIC Connect / Apple Wallet / Google Wallet) reaches ~10-25% of typical workforce as opt-in for executives, IT, facilities, frequent visitors. Plastic remains primary for industrial / construction (no phone on body in PPE), healthcare patient (sterile + wash protocol), K-12 education (phone policy restrictions), short-term visitor / contractor, and hospitality guest (Apple Wallet hotel keys <2% of stays in 2026). The CSA Aliro 1.0 unified standard (February 2026) will end vendor-cloud lock-in by mid-2027 and may accelerate mobile adoption — but plastic will remain primary through at least 2028.
Which PACS platform should we pair these credentials with?
Match the credential to your existing PACS or to your security tier. Enterprise multi-site: Genetec Synergis or Lenel S2 OnGuard (now Carrier) or Software House C·CURE 9000 (Tyco / Johnson Controls). Industrial / commercial mid-market: Honeywell Pro-Watch or WIN-PAK. Critical infrastructure / prisons / utilities: Gallagher Command Centre or AMAG Symmetry. SMB cloud: Brivo, Avigilon Alta (formerly Openpath), Kisi, Verkada, Feenics (now Honeywell Pro-Watch Cloud). Federal: FICAM Approved Products List required — Genetec, Lenel, AMAG and Software House C·CURE all maintain APL listings. Tell us your PACS head-end + reader model and we match the chip + encoding format + facility code + cardholder-ID range exactly.
What is NDAA Section 889 and how does it affect RFID credential procurement?
NDAA Section 889 (effective 13 August 2020 via FAR 52.204-25) bars federal agencies and federal contractors from purchasing or using products containing covered telecommunications equipment from Huawei, ZTE, Hytera, Hikvision and Dahua — including subcomponents. For RFID credential procurement this means: reader OEM must publish NDAA Section 889 attestation (HID, Allegion, Mercury Security, ASSA ABLOY all do); chip silicon supply chain must be auditable (NXP, Infineon, ST, EM Microelectronic all clean); card body lamination + printing must be NDAA-compliant facility. Combine with TAA (Trade Agreements Act) requirement for products made in TAA-designated countries. Proud Tek operates NDAA-compliant manufacturing and provides written 889 + TAA attestation for federal contracts.
How does the Aliro 1.0 unified mobile credential standard change procurement strategy?
Aliro 1.0 was published by Connectivity Standards Alliance (CSA) in February 2026 with founding members including Apple, Google, Samsung, Aqara, Lockly, HID, ASSA ABLOY, Allegion, dormakaba. Aim: one cryptographic credential format any reader can authenticate without proprietary cloud handshake — ending today's vendor-cloud lock-in pattern (HID Origo vs Salto JustIN vs Allegion Mobile vs LEGIC Connect). 2026 status: standard published, first Aliro-Certified products expected H2 2026; broad reader fleet support 2027-2028. Procurement implication: for greenfield deployments late 2026+, specify Aliro-Certified reader fleet (futureproofs against vendor lock-in); for existing deployments, plan Aliro readiness in next reader-refresh cycle. Plastic credential remains unaffected by Aliro.
Sources & references
Primary standards, OEM datasheets and regulatory documents cited by this article. All URLs were verified on the access date shown below.
- ISO/IEC 14443:2018 — Identification cards — Contactless integrated circuit cards — Proximity cards
HF 13.56 MHz proximity-card air interface underpinning MIFARE Classic / Plus / DESFire and HID iCLASS Seos access-control credentials.
- ISO/IEC 18000-63:2015 — UHF Type C / EPC Gen2 air interface (860–960 MHz)
UHF air interface used for long-range vehicle, parking and gate access-control credentials and hands-free speed-lane reads.
- NXP MIFARE DESFire EV3 product brief and security target
AES-128 mutual-authentication HF access credential — current 2026 baseline silicon for enterprise PACS deployments.
- HID Global — iCLASS Seos credential and Signo / multiCLASS SE / OMNIKEY reader portfolio
Market-leading enterprise PACS credential and reader ecosystem — referenced for HID Mobile Access (Origo) and Apple-Wallet-Verified reader fleet.
- EM Microelectronic EM4100 — 125 kHz LF RFID IC datasheet
Legacy 125 kHz LF silicon commonly found in older low-security access-control estates; cited for migration-path discussion.
- NIST SP 800-116 Rev 1 — Guidelines for the Use of PIV Credentials in Facility Access
Federal PACS guidance defining PKI-CAK / PKI-AUTH / BIO / BIO-A transactions for PIV credentials — drives DESFire EV3 / Seos AES-128 baseline.
- FIPS 201-3 — Personal Identity Verification (PIV) of Federal Employees and Contractors
Federal credential format + cryptographic baseline + lifecycle standard — required for federal employee + contractor credentials.
- UL 294 — Standard for Access Control System Units (8th edition)
North American baseline standard for access control hardware safety + reliability + line security; AHJ approval reference.
- SIA OSDP v2.2 — Open Supervised Device Protocol specification
Reader-to-panel protocol with AES-128 Secure Channel replacing legacy Wiegand; mirrored as IEC 60839-11-5:2020.
- Garcia, de Koning Gans, Verdult — Dismantling MIFARE Classic (Crypto-1 break)
Foundational academic break of MIFARE Classic Crypto-1 cipher; basis for recommending DESFire EV3 / Seos migration on all sensitive deployments.
- Connectivity Standards Alliance — Aliro 1.0 mobile access standard
February 2026 unified mobile credential standard with Apple, Google, Samsung, HID, ASSA ABLOY, Allegion, dormakaba founders — ends vendor-cloud lock-in by 2027-2028.
- FAR 52.204-25 — Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment (NDAA Section 889)
NDAA Section 889 implementation barring federal use of Huawei / ZTE / Hytera / Hikvision / Dahua components — drives RFID reader supply-chain attestation requirements.
- GSA FICAM — Approved Products List (APL)
Federal Identity, Credential and Access Management Approved Products List of PACS, readers, panels, middleware required for federal procurement.
- Genetec Synergis — unified access control platform
Quebec-based unified Security Center platform combining access + video + ALPR; major PACS head-end in enterprise multi-site deployments.
- Allegion Mobile Access — Schlage NDE / LE / Control ENGAGE platform
BLE mobile credential ecosystem common in K-12 + higher education, paired with Schlage NDE / LE / Control / XE360 wireless locks.
- Apple — Employee Badge in Apple Wallet (Apple Business Manager)
Apple Wallet employee badge issuance via Apple Business Manager — consumed by Apple-Wallet-Verified readers (HID Signo, Schlage, LEGIC, Salto, dormakaba, ASSA ABLOY, Kastle).
- ASSA ABLOY — Aperio wireless lock platform
Wireless lock platform integrating with PACS via gateway / hub architecture; common door-hardware partner for HID + Lenel + Genetec + Software House.
- Mercury Security — LP-series + EP-series intelligent controllers (HID company)
OEM intelligent controller platform used inside Genetec / Lenel / C·CURE / Pro-Watch / AMAG / Honeywell PACS panels.
- GDPR Article 28 — Controller / Processor framework
Controller / processor obligations triggered by PACS cardholder data + access logs; signed Data Processing Agreement required for cloud PACS.
Proud Tek is a Shenzhen-based RFID & NFC manufacturer supplying hotel chains, transit operators, event venues and retail brands worldwide. Every order includes free samples, RF testing and dedicated project support.
Get a Quick Quote
Tell us about your project and we'll respond within one business day. Fields marked (asterisk) are required.
