Neil Foster, Sales Director, Northern Europe for Integrated Control Technology (ICT) examines hidden weaknesses in access control, from legacy credentials to insecure protocols
Many organisations still rely on 125kHz proximity cards despite their known vulnerability to cloning. Why does this legacy technology persist, and what immediate risks does it introduce?
It is indeed surprising to see how many companies and organisations are still using a technology known for its lack of security. It defeats the purpose of having an access security system if the credentials used to operate it are so weak. 125kHz cards can be cloned in a few seconds using devices sold by main online and high street retailers for less than 20 pounds. But cloning cards is not always done malevolently, it could be done naively by a company to give access to new employees or visitors. Copying an authorised access card means another employee or a total stranger can impersonate an authorised person and access a building or site with all the risks, it implies on assets and intellectual property protection and people safety.
The main reasons for organisations to carry on using them is the lack of understanding of the technology’s vulnerability and, also, the cost and possible inconvenience to upgrade the system in place.
If an organisation has hundreds or thousands of users, the practicalities of replacing the whole fleet of access cards or tags while still operating, can seem complex. End-users can also be reluctant to invest in replacing their legacy systems, however, with the correctly planned phased migration of credentials and readers this can be budgeted for and make the transition easier than anticipated.
Mobile credentials offer convenience but create new exposure points, including sharing between devices. What controls and encryption standards should organisations insist on to prevent misuse or credential proliferation?
Mobile credentials are a very convenient way to give access to users, especially in education, or multitenancy environments where they could be part of an app, allowing other privileges, such as booking common areas, giving passes to visitors etc.
As mentioned above, credentials could be a weak part of a system and it is no different for mobile credentials. The communication between the app holding the mobile credential and the readers should be encrypted and authenticated. Using AES 256 encryption should be the norm as it helps prevent cloning or eavesdropping. In addition to secure communication between App and readers, an additional authentication could be added such as a PIN on the reader, for instance.
The access of a mobile credential on multiple devices should be carefully assessed and managed.
As Mobile credentials are sent electronically, it is important to have a strong identity proofing during enrolment and a clear policy of lifecycle management, like a rapid revocation if the phone is lost or stolen, or if a visitor has a temporary access.
Wiegand continues to appear in active deployments despite its security limitations. What practical security and operational gains do organisations achieve by migrating to OSDP or RS-485, and how should they approach this transition?
The Wiegand interface is simple to use and widely compatible, which still makes it appealing. A lot for external devices, can be easily added to a controller, using simple and low-cost cabling, and generates a trigger to open a gate, a door etc. It is a one-way communication, there is no encryption or authentication, and no device supervision. So, while it can used easily for a wide arrange of applications, it is not secure and should only be used for small and low risk sites.
The RS-485 and OSDP (Open Supervised Device Protocol) protocols provide both an encrypted, secure two-way communication with device management. The RS-485 is unique and locked to the manufacturer bringing high security to a site, with as downside, a lack of flexibility if the users want to use third-party readers.
OSDP (Open Supervised Device Protocol) offers both openness and security and it allows to use any other OSDP compatible devices.
Organisations should approach the transition to OSDP by identifying the security risk of using Wiegand and start with the areas of the site or building with the highest risk. They will have to replace the Wiegand cabling with shielding twisted pair rated for RS-485 and ensure that existing readers, controllers, expanders support OSDP.