ResortBands

Home / Technology / Security and cloning

Tech 09

Cloning, keys and how much security you need

Any credential that answers a reader can, in principle, be studied. The useful question is not whether a band can be cloned in a laboratory but what somebody gains by cloning yours, how much effort it takes, and whether your system would notice.

At a glance
Fixed serial numberReadable by anything; reproducible with effort
Key-based chipsReader must prove it holds the key
Practical defenceDetection and revocation, not just chip choice
Key custodyA property responsibility, not a supplier one
Security and cloning

A fixed identifier is a name, not a secret

Simple credentials transmit an identifier to anything that asks. Nothing about that is secret, and hardware capable of reproducing such an identifier is inexpensive and freely available. For a staff gate this may be entirely acceptable — the identifier still records who went where, and the risk is unauthorised entry to a corridor rather than to a safe. For anything authorising money, understand plainly that the identifier alone is not protecting it.

Key-based authentication changes the question

More capable chips will not release protected memory until the reader demonstrates it holds the correct key, through a challenge-and-response exchange in which the key itself is never transmitted. Copying such a credential is a materially harder problem than copying a fixed number. It is not a guarantee — implementations have weaknesses, and the specifics belong in a conversation with your access-control vendor — but it moves the effort required from trivial to substantial.

Detection usually matters more than the chip

A cloned band produces a signature your system can see: the same credential opening two doors at opposite ends of a property within a minute, or a band presenting after it was reported lost. Properties that monitor for impossible sequences and can revoke a credential quickly are in a far better position than properties running expensive chips with no monitoring and no revocation process. Security here is operational at least as much as it is technical.

Specify proportionately, and say what you are protecting

A day band that opens a pool gate does not need cryptographic protection; a staff band that opens a stock store might; a band that authorises spending against a folio needs a spend limit and a dispute process more than it needs a better chip. The productive conversation starts from what a compromised band would let somebody do, and it is worth having with whoever runs your access system before deciding anything about the band.

Before this becomes a specification

Compatibility is subject to confirmation of your lock system, credential technology and encoding requirements.

All third-party marks are the property of their respective owners. Any reference indicates compatibility only and does not imply affiliation or endorsement.

Security and cloning

No obligation · reply within one working day

Discuss a proportionate security specification.

Send the reader or lock details with your enquiry. We confirm what is possible in writing before anything is manufactured, and say so plainly where it is not.