Think your smartcards are secure?

March 2017 Editor's Choice, Access Control & Identity Management

As we move into 2017, it is widely known that most legacy access control cards and smartcards in the industry are easily copied and cloned. But it is important to remember that even if you are using a secure technology (like EV1), cards can still be copied if there is careless use of the smart card ‘keys’.

Not only can you buy traditional card cloning machines, but you can now also buy open hardware to exploit poorly written code that extracts AES smartcard keys in a matter of minutes. If these smartcard keys become known, then ID cards can be recreated (even if businesses are using the highly secure EV1 technology).

There is also the realisation in the industry that when many thousands of cards are issued with a common numbering scheme and key structure, effective key management and lifecycle strategies need to be developed. So the question is – how do we ensure that our smartcard keys remain secure and uncompromised at all times?

To increase key security at the manufacturer level, leading smartcard providers can offer a secure object, which is written to the smartcard using a separate set of keys. Although this provides customers with a layer of protection, if these keys become known the system security is still ‘at risk’ as cards can be freely created. So, to mitigate against this vulnerability, Lumen ID recommends that customers look internally at their ‘Key Generation Ceremony’ and process.

Very often smartcard migration project success involves ensuring that smartcard key structure and code is both written and managed in the most secure, anonymous and auditable way. Because after all, isn’t it audit that drives behaviour? Questions such as how the keys are generated, how they are kept secret and how they are disseminated in global corporate environments, require robust answers to ensure that access control security is maintained.

An end-to-end security management process for securing and protecting smartcard keys can be easily achieved using multiple, independent factors such as:

1. The generation of a private, anonymous key structure that’s only known by the customer.

2. Key rotation.

3. Credential management software for the allocation of unique identifiers and to connect to existing access control systems and databases.

4. Use of encrypted card printers and credential encoders.

1. Generation of an anonymous, private key structure

Although customers are assigned random and unique shipping ‘keys’ by the card manufacturer, it is important that keys can then be subsequently changed by the customer to an anonymous keyset; thus ensuring the utmost level of security and autonomy.

Historically, smartcards were supplied completely personalised with all the information necessary for the card to function included within the card. For security and costs reasons however, the growing trend now is for most cards to be supplied minimally personalised, with further personalisation then required on-site.

The first step in the deployment of a truly secure smartcard credential starts with the creation of a unique, private key structure that never leaves the client’s secure area. During the customer’s initial ‘key generation ceremony’ Lumen ID recommends that smartcard keys and passwords never exist in human readable form. They should never be written down and indeed no one person should know the pre-curser to regenerate the keys.

It is best practice to create a keyset that is derived using multiple paraphrases from numerous members of security staff. This ensures ‘distribution of trust’ as no one person knows the complete passphrase. From the combined passphrases, a unique customer keyset is then created, along with a set of secure ‘Key Configuration’ cards (eg. Admin and Key change cards) that are used to initiate readers and other security devices so that they can all operate seamlessly using the same keyset.

The benefit here is that the manufacturer only knows the initial card shipping keys. But because they don’t know the customer’s active cards and the unique paraphrase cards, the keys will always remain anonymous.

2. Key rotation

It is recommended that keys be capable of being changed periodically and recreated by the customer as and when required. Smartcard suppliers should never be able to recreate the customer’s active keys, ensuring a degree of separation from the key management process. Opt for secure readers that can be used across different platforms and which allow key rotation. New keys should be capable of being distributed securely into the system using a secure reader key change configuration card.

At Lumen ID, we also recommend that keys do not reside on the access control readers directly. This rationale is also supported by recent government standards bodies for access control in the UK – CPNI (Centre for the Protection of National Infrastructure) and NIST (National Institute of Standards & Technology), in the USA. These bodies emphasise the importance of not holding keys in the reader in case it’s stolen and keys examined and extracted over time. Instead they recommend that keys should be held in the secure location of an access control door control panel.

As an added layer of security and to eradicate any risk of key extraction or interface replaying, Lumen ID recommends the use of a smart ‘Cipher box‘ (that sits between the card reader and the door control panel) to independently hold the keys.

3. Credential management software to allocate unique identifiers to the credential

Ensuring key autonomy is made further difficult for enterprise customers that often have problems such as the use of multiple card technologies and multiple access control systems per region. How can they create a common global credential that’s unique and highly secure, irrespective of its regional environmental differences?

This is achieved using a top level credential management software interface that talks to the SQL databases of multiple access control systems. The credential management interface remotely manages the allocation of unique identifiers to the global credential. It controls all the key elements in the end-to-end credential solution including; ‘Printer Encoders’ and ‘Card Number Ranges’. It also provides a full audit trail of credential/key management actions and provides real-time alerts of prohibited actions for command and control.

4. Opt for encrypted card readers and printer encoders

Encrypted card printers/encoders which hold the customer’s private keys directly in the SAM of the encoder are also now available. When used in collaboration with key configuration cards and credential management software, printer encoders can successfully allocate a unique identifier to ID cards and ensure that on-card key/data protection is digitally assigned to an end access control credential.

Conclusion

Securing credential key structure and ensuring distribution of trust at all levels of the access control credential process is essential. A robust, continual audit procedure should be put in place to ensure that keys are never compromised. As manufactures and suppliers have no knowledge of the keys generated as part of this anonymous process, it is also essential that they are created and managed in a systematic, secure and auditable fashion. When choosing a smartcard solution provider, ensure they have the software tools available to allocate a unique ID to the credential, program the credential and vitally, to provide a secure audit trail as to the ongoing validity of the credential.

For more information contact Lumen ID, info@lumenid.co.uk, www.lumenid.co.uk





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Impro announces Primo update
News & Events Access Control & Identity Management Integrated Solutions
Impro Technologies recently held a launch event in which it introduced a series of new products, from new readers through to its updated Primo access management software.

Read more...
The AI goldrush has a credibility problem
Refraime Editor's Choice Surveillance AI & Data Analytics
The single most important question a surveillance buyer can ask is deceptively simple: “Was this system programmed or was it trained?” That question alone will reveal more about what you are evaluating than any feature list or marketing video.

Read more...
Crime behaviour insights more important than ever
Leaderware Editor's Choice Surveillance Training & Education AI & Data Analytics
Behavioural surveillance skills are as essential now as they have ever been, especially in situations where quick evaluation of context is needed. Training operators in behavioural recognition skills is a vital part of control room success.

Read more...
Proactive estate security in Cape Town
neaMetrics OneSpace Technologies Technews Publishing SMART Security Solutions Fang Fences & Guards ATG Digital Editor's Choice News & Events Integrated Solutions Infrastructure Residential Estate (Industry)
SMART Security Solutions started the year with our annual SMART Estate Security Conference in Cape Town on 26 February 2026. Held at Anna Beulah Farm, the conference saw a number of delegates enjoying the farm’s excellent cuisine, while listening to outstanding presenters.

Read more...
How AI video is reshaping real estate security
neaMetrics TRASSIR - neaMetrics Distribution Editor's Choice
Globally, property maintenance and facility operations spending is projected to grow to over US$145 billion by 2034, reflecting rising complexity, compliance pressures, and increased exposure to operational costs. AI systems can protect properties, automate access, and optimise building management.

Read more...
Open systems support hybrid surveillance
SMART Security Solutions Axis Communications SA neaMetrics Editor's Choice
Today, end users can select the most suitable surveillance solution for their needs, whether it is on-site, at the edge, or in the cloud; a hybrid approach combining different options is most effective depending on the scenario.

Read more...
Surveillance & AI roundtable
DeepAlert Lytehouse Refraime SMART Security Solutions Technews Publishing Editor's Choice Surveillance Integrated Solutions AI & Data Analytics
SMART Security Solutions held an online roundtable with a few surveillance experts to explore the intersection of surveillance and AI, gaining insights into the market and how control rooms are evolving.

Read more...
Centurion raises the bar at HomeSec Expo
Centurion Systems News & Events Access Control & Identity Management Residential Estate (Industry) Smart Home Automation Commercial (Industry)
Centurion Systems unveiled its latest product lines at HomeSec Expo 2026, introducing SMART+, a simpler way for installers and end users to manage their Centurion installations - as well as a few new products.

Read more...
Access trends for 2026
Technews Publishing SMART Security Solutions RR Electronic Security Solutions Enkulu Technologies IDEMIA neaMetrics Editor's Choice Access Control & Identity Management Infrastructure
The access control and identity management industry has been the cornerstone of organisations of all sizes for decades. SMART Security Solutions asked local integrators and distributors about the primary trends in the access and identity market for 2026.

Read more...
Access data for business efficiency
Continuum Identity Editor's Choice Access Control & Identity Management AI & Data Analytics Facilities & Building Management
In all organisations, access systems are paramount to securing people, data, places, goods, and resources. Today, hybrid systems deliver significant added value to users at a much lower cost.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.