SHT 06 Solutions · Module · Cards & Credentials
A badge is a secret. Treat it like one.
Unencoded cards are copied by a £30 device in seconds. Encrypted cards are only as strong as the keys behind them, and most estates don’t know where those keys live.
01 Threat landscape
Five token threats. NPSA-defined. All real.
Per NPSA “User Guide on Token and Reader Technology - Level 2” (eis0006), p.14. Unencoded cards broadcast a static ID a £30 copier can read and rewrite. Strong cards plus owned keys close all five.
02 Key management
Encryption is a promise. Keys are how you keep it.
A DESFire card is strong because it shares a secret with the reader. Lose control of the secret, who made it, where it sleeps, when it rotates, and you’re back to prox. We own the lifecycle end to end.
03 The vault
Your keys in your hardware. Yours, not ours.
Split custody, by design.
Master keys stay inside a tamper‑evident HSM on your estate or in your cloud tenant. We operate it under a split‑custody agreement: two keyholders to rotate, four eyes to decommission, zero keys in spreadsheets.
04 Proof & path
Audit‑ready today. Re‑credentialed by the next board meeting.
What encryption unlocks on paper
Every framework asks “is the credential tamper‑resistant, is the key under control, is there an audit trail?” Strong cards plus our keyring answer all three, in the language of each auditor.
Multi‑site, multi‑reader, zero downtime
Nobody replaces 6,000 badges on a Friday. The move from prox to encrypted happens a reader at a time, a cohort at a time, with both credentials live until the last one leaves.
Baseline the estate
We scan every reader, flag the downgrade paths, and map which doors share which keyspace. You see the risk before you touch a card.
Dual‑credential window
Readers accept both the old prox and the new DESFire for a defined overlap, typically 30 to 90 days. No big‑bang, no locked‑out staff on Monday morning.
Re‑issue by cohort
Starting with privileged and high‑traffic sites. Self‑service kiosks, mobile wallet where estate allows, printed‑and‑encoded where it doesn’t.
Cut the old key
Once every reader reports green and every cohort is migrated, the legacy key is retired from the HSM. Attestation signed. Audit closed.
Independently certified: ISO 9001, ISO/IEC 27001 and TISAX (DEKRA-certified), with GDPR / NIS2 / DORA support. The key estate inherits the posture.
05 Related sheets
Continue through the drawing set.
Are you confident in the security level of your credentials?
From £30-copier prox to keyed DESFire, a reader at a time, with both credentials live until the last one leaves.