SHT 06 Solutions · Module · Cards & Credentials

A badge is a secret. Treat it like one.

Unencoded cards are copied by a £30 device in seconds. Encrypted cards are only as strong as the keys behind them, and most estates don’t know where those keys live.

Unencoded prox cards broadcast a static ID that a £30 copier can read and rewrite to a blank in seconds. We replace the card, and we own the keyring that replaces it.
Unencoded UID-ONLY PROX
ID: 0x3A2F.04C1 UID only · unencoded 10110 01101 11010 00111 PROXMARK readout ready
read → copy → walk in.
Encrypted + keyed DESFire EV3 · AES-128
ENCRYPTED AES-128 · 3-pass auth K = PRF(M, UID) stored: HSM → challenge: 7F3A... ← response: D4E1... ✓ no-match → abort PROXMARK MAC FAIL
rejected. no key, no read, no copy.

01 Threat landscape

Five token threats. NPSA-defined. All real.

Per NPSA “User Guide on Token and Reader Technology - Level 2” (eis0006), p.14. Unencoded cards broadcast a static ID a £30 copier can read and rewrite. Strong cards plus owned keys close all five.

01 · UNAUTHORISED READING
The pocket grab
“I stood next to you on the Tube”
UID-only tokens have no mechanism to refuse a read. An attacker with an active reader walks past you - in a queue, a lift, against a pocket - and lifts the credential. Authentication-mode cards demand a shared secret first.
02 · EMULATION / CLONING
Duplication of credentials
“Any blank can be you”
Any device that presents the right UID and returns the expected DATA looks genuine to the reader. Blank tokens can be programmed to be anyone. UID-only and UID-plus-DATA tokens are duplicated wholesale.
03 · RELAYING (MITM)
The long arm
“Your card is here. You are not.”
A reader at the door and an emulator near the victim bridge the radio exchange in real time. Every token configuration is vulnerable - even fully encrypted conversations relay unmodified, because no decryption is needed for the attack to succeed.
04 · SNIFFING
Listening on the wire
“I captured the conversation”
A third party intercepts the conversation between token and reader. In non-authenticated mode, passwords and data fall straight out. Even encrypted tokens may yield to cryptographic attack with commercially available kit.
05 · UNAUTHORISED WRITING
Modifying the credential
“Same card. New rights.”
Keys recovered through sniffing let an attacker rewrite a genuine credential - changing access rights, monetary value, expiry. UID-and-DATA tokens not locked to read-only can be tampered with even without recovering keys.

02 Key management

Encryption is a promise. Keys are how you keep it.

A DESFire card is strong because it shares a secret with the reader. Lose control of the secret, who made it, where it sleeps, when it rotates, and you’re back to prox. We own the lifecycle end to end.

01 · Generate
Born in the vault
Master keys generated inside a Common Criteria EAL‑6 certified HSM. The raw key never exists in software, never touches an admin laptop.
02 · Store
Sleeps in the HSM
Diversified per‑card keys derive from the master on demand. Every card carries a unique secret. Extract one, learn nothing about the others.
03 · Rotate
Changes while you sleep
Scheduled rotation across the reader fleet, zero‑downtime overlap windows, audit log per door. A compromise in October doesn’t outlive October.
04 · Decommission
Gone means gone
When a site closes or a supplier leaves, the key is retired, not archived. Attestation report, signed, minuted. No dormant backdoor.
< 3 S
RevokeDenial at the door

03 The vault

Your keys in your hardware. Yours, not ours.

COMMON CRITERIA · EAL 6

Split custody, by design.

Master keys stay inside a tamper‑evident HSM on your estate or in your cloud tenant. We operate it under a split‑custody agreement: two keyholders to rotate, four eyes to decommission, zero keys in spreadsheets.

HSM rack - key feed to card printer, issue in under 90 seconds Elevation of a 19-inch rack containing a certified HSM with two key switches annotated two keyholders, a cable run carrying the key feed to a card printer in side elevation issuing a card, dimensioned at under 90 seconds. RACK A1 HSM - CC EAL6 TWO KEYHOLDERS KEY FEED CARD PRINTER ISSUE < 90 S
HSM rack · Rack A1 · Key feed to printer, two-keyholder ceremony

04 Proof & path

Audit‑ready today. Re‑credentialed by the next board meeting.

COMPLIANCE MAP

What encryption unlocks on paper

Every framework asks “is the credential tamper‑resistant, is the key under control, is there an audit trail?” Strong cards plus our keyring answer all three, in the language of each auditor.

ISO 27001 A.8.24 cryptography · A.5.16 identity · A.8.2 privileged access, all evidenced by HSM attestation and per‑reader key logs.
NIS2 Art. 21(2)(i) cryptography and key management: documented policy, rotation schedule, incident playbook tied to credential estate.
GDPR Art. 32 security of processing. A cloned badge is a data breach; strong cards close a class of reportable incidents outright.
CC EAL 6 Common Criteria EAL‑6 certified HSM underneath. Auditors see a certificate, not a claim. The key estate inherits the posture.
MIGRATION PLAYBOOK

Multi‑site, multi‑reader, zero downtime

Nobody replaces 6,000 badges on a Friday. The move from prox to encrypted happens a reader at a time, a cohort at a time, with both credentials live until the last one leaves.

Baseline the estate

We scan every reader, flag the downgrade paths, and map which doors share which keyspace. You see the risk before you touch a card.

Dual‑credential window

Readers accept both the old prox and the new DESFire for a defined overlap, typically 30 to 90 days. No big‑bang, no locked‑out staff on Monday morning.

Re‑issue by cohort

Starting with privileged and high‑traffic sites. Self‑service kiosks, mobile wallet where estate allows, printed‑and‑encoded where it doesn’t.

Cut the old key

Once every reader reports green and every cohort is migrated, the legacy key is retired from the HSM. Attestation signed. Audit closed.

Independently certified: ISO 9001, ISO/IEC 27001 and TISAX (DEKRA-certified), with GDPR / NIS2 / DORA support. The key estate inherits the posture.