Home / Technology / Security and cloning
Tech 09
Cloning, keys and how much security you need
Any credential that answers a reader can, in principle, be studied. The useful question is not whether a band can be cloned in a laboratory but what somebody gains by cloning yours, how much effort it takes, and whether your system would notice.
| Fixed serial number | Readable by anything; reproducible with effort |
|---|---|
| Key-based chips | Reader must prove it holds the key |
| Practical defence | Detection and revocation, not just chip choice |
| Key custody | A property responsibility, not a supplier one |
A fixed identifier is a name, not a secret
Simple credentials transmit an identifier to anything that asks. Nothing about that is secret, and hardware capable of reproducing such an identifier is inexpensive and freely available. For a staff gate this may be entirely acceptable — the identifier still records who went where, and the risk is unauthorised entry to a corridor rather than to a safe. For anything authorising money, understand plainly that the identifier alone is not protecting it.
Key-based authentication changes the question
More capable chips will not release protected memory until the reader demonstrates it holds the correct key, through a challenge-and-response exchange in which the key itself is never transmitted. Copying such a credential is a materially harder problem than copying a fixed number. It is not a guarantee — implementations have weaknesses, and the specifics belong in a conversation with your access-control vendor — but it moves the effort required from trivial to substantial.
Detection usually matters more than the chip
A cloned band produces a signature your system can see: the same credential opening two doors at opposite ends of a property within a minute, or a band presenting after it was reported lost. Properties that monitor for impossible sequences and can revoke a credential quickly are in a far better position than properties running expensive chips with no monitoring and no revocation process. Security here is operational at least as much as it is technical.
Specify proportionately, and say what you are protecting
A day band that opens a pool gate does not need cryptographic protection; a staff band that opens a stock store might; a band that authorises spending against a folio needs a spend limit and a dispute process more than it needs a better chip. The productive conversation starts from what a compromised band would let somebody do, and it is worth having with whoever runs your access system before deciding anything about the band.
Before this becomes a specification
Compatibility is subject to confirmation of your lock system, credential technology and encoding requirements.
All third-party marks are the property of their respective owners. Any reference indicates compatibility only and does not imply affiliation or endorsement.
Related
Read next.
Tech 08
Chip memory and sectors
Serial number only, or writable protected memory. This distinction decides most of what a band can and cannot do.
ReferenceTech 03
Low frequency at 125 kHz
The older standard still running on plenty of properties. Simpler, more tolerant, and with almost no security.
ReferenceTech 12
Transponder lifecycle
The chip outlives the band by years. What limits a programme is the construction, the register and the disposal route.
Reference
No obligation · reply within one working day
Discuss a proportionate security specification.
Send the reader or lock details with your enquiry. We confirm what is possible in writing before anything is manufactured, and say so plainly where it is not.