SHT 06 Solutions · Module · Cards & Credentials
A badge is a secret. Treat it like one.
Unencoded cards are copied by a £30 device in seconds. Encrypted cards are only as strong as the keys behind them - and most estates don't know where those keys live.
01 The clone test
Same cloner. Two cards. One way in.
Unencoded prox cards broadcast a static ID that a £30 copier can read and rewrite to a blank in seconds. We replace the card, and we own the keyring that replaces it.
02 Threat landscape · NPSA eis0006
Five token threats. NPSA-defined. All real.
The same £30 copier from section 01 sets the baseline threat. The NPSA defines five threat classes against tokens. Strong cards plus owned keys close all five.
The pocket grab
UID-only tokens have no mechanism to refuse a read. An attacker with an active reader walks past you - in a queue, a lift, against a pocket - and lifts the credential. Authentication-mode cards demand a shared secret first; unencoded cards don't.
Duplication of credentials
Any device that presents the right UID and returns the expected DATA looks genuine to the reader. Blank tokens can be programmed to be anyone. UID-only and UID-plus-DATA tokens are duplicated wholesale.
Your card is here. You are not.
A reader at the door and an emulator near the victim bridge the radio exchange in real time. Every token configuration is vulnerable - even fully encrypted conversations relay unmodified, because no decryption is needed for the attack to succeed.
Listening on the wire
A third party intercepts the conversation between token and reader. In non-authenticated mode, passwords and data fall straight out. Even encrypted tokens may yield to cryptographic attack with commercially available kit.
Modifying the credential
Keys recovered through sniffing let an attacker rewrite a genuine credential - changing access rights, monetary value, expiry. UID-and-DATA tokens not locked to read-only can be tampered with even without recovering keys.
Threat categories per NPSA “User Guide on Token and Reader Technology - Level 2” (eis0006), p.14.
03 Key management
Encryption is a promise. Keys are how you keep it.
A DESFire card is strong because it shares a secret with the reader. Lose control of the secret - who made it, where it sleeps, when it rotates - and you're back to prox. We own the lifecycle end to end.
Born in the vault
Master keys generated inside a Common Criteria EAL-6 certified HSM. The raw key never exists in software, never touches an admin laptop.
Sleeps in the HSM
Diversified per-card keys derive from the master on demand. Every card carries a unique secret. Extract one, learn nothing about the others.
Changes while you sleep
Scheduled rotation across the reader fleet, zero-downtime overlap windows, audit log per door. A compromise in October doesn't outlive October.
Gone means gone
When a site closes or a supplier leaves, the key is retired, not archived. Attestation report, signed, minuted. No dormant backdoor.
04 The vault · Common Criteria · EAL 6
Your keys in your hardware. Yours, not ours.
Master keys stay inside a tamper-evident HSM on your estate or in your cloud tenant. We operate it under a split-custody agreement: two keyholders to rotate, four eyes to decommission, zero keys in spreadsheets.
Common Criteria EAL-6 certified HSM. Auditors see a certificate, not a claim. The key estate inherits the posture.
05 Compliance map
What encryption unlocks on paper.
Every framework asks “is the credential tamper-resistant, is the key under control, is there an audit trail?” Strong cards plus our keyring answer all three, in the language of each auditor.
Cryptography, identity and privileged access - all evidenced by HSM attestation and per-reader key logs.
Cryptography and key management: documented policy, rotation schedule, incident playbook tied to credential estate.
A cloned badge is a data breach. Strong cards close a class of reportable incidents outright.
Common Criteria EAL-6 certified HSM underneath. Auditors see a certificate, not a claim. The key estate inherits the posture.
06 Migration playbook
Multi-site, multi-reader, zero downtime.
Nobody replaces 6,000 badges on a Friday. The move from prox to encrypted happens a reader at a time, a cohort at a time, with both credentials live until the last one leaves.
Baseline the estate
We scan every reader, flag the downgrade paths, and map which doors share which keyspace. You see the risk before you touch a card.
Dual-credential window
Readers accept both the old prox and the new DESFire for a defined overlap, typically 30 to 90 days. No big-bang, no locked-out staff on Monday morning.
Re-issue by cohort
Starting with privileged and high-traffic sites. Self-service kiosks, mobile wallet where estate allows, printed-and-encoded where it doesn't.
Cut the old key
Once every reader reports green and every cohort is migrated, the legacy key is retired from the HSM. Attestation signed. Audit closed.
07 Related sheets
Continue through the drawing set.
Are you confident in the security level of your credentials?
Tell us what readers you have and we'll tell you which of your cards can be cloned with a £30 copier. It's usually more than you'd hope.