SHT 06 Solutions · Module · Cards & Credentials

A badge is a secret. Treat it like one.

Unencoded cards are copied by a £30 device in seconds. Encrypted cards are only as strong as the keys behind them - and most estates don't know where those keys live.

01 The clone test

Same cloner. Two cards. One way in.

Unencoded prox cards broadcast a static ID that a £30 copier can read and rewrite to a blank in seconds. We replace the card, and we own the keyring that replaces it.

Marginal note - the problem Which of your cards would survive this bench? If the answer involves the word “probably”, that is the audit finding.
SIM 06-A - CLONE ATTACK · TWIN BENCH · SYNCHRONISED LOOP
Unencoded UID-ONLY PROX
ID: 0x3A2F.04C1 UID only · unencoded 10110 01101 11010 00111 PROXMARK readout ready 125 kHz COIL
read → copy → walk in.
Encrypted + keyed DESFire EV3 · AES-128
ENCRYPTED AES-128 · 3-pass auth K = PRF(M, UID) stored: HSM → challenge: 7F3A... ← response: D4E1... ✓ no-match → abort PROXMARK MAC FAIL 13.56 MHz COIL
rejected. no key, no read, no copy.

02 Threat landscape · NPSA eis0006

Five token threats. NPSA-defined. All real.

The same £30 copier from section 01 sets the baseline threat. The NPSA defines five threat classes against tokens. Strong cards plus owned keys close all five.

01 · Unauthorised reading

The pocket grab

UID-only tokens have no mechanism to refuse a read. An attacker with an active reader walks past you - in a queue, a lift, against a pocket - and lifts the credential. Authentication-mode cards demand a shared secret first; unencoded cards don't.

02 · Emulation / cloning

Duplication of credentials

Any device that presents the right UID and returns the expected DATA looks genuine to the reader. Blank tokens can be programmed to be anyone. UID-only and UID-plus-DATA tokens are duplicated wholesale.

03 · Relaying (MITM)

Your card is here. You are not.

A reader at the door and an emulator near the victim bridge the radio exchange in real time. Every token configuration is vulnerable - even fully encrypted conversations relay unmodified, because no decryption is needed for the attack to succeed.

04 · Sniffing

Listening on the wire

A third party intercepts the conversation between token and reader. In non-authenticated mode, passwords and data fall straight out. Even encrypted tokens may yield to cryptographic attack with commercially available kit.

05 · Unauthorised writing

Modifying the credential

Keys recovered through sniffing let an attacker rewrite a genuine credential - changing access rights, monetary value, expiry. UID-and-DATA tokens not locked to read-only can be tampered with even without recovering keys.

Threat categories per NPSA “User Guide on Token and Reader Technology - Level 2” (eis0006), p.14.

03 Key management

Encryption is a promise. Keys are how you keep it.

A DESFire card is strong because it shares a secret with the reader. Lose control of the secret - who made it, where it sleeps, when it rotates - and you're back to prox. We own the lifecycle end to end.

01 · Generate

Born in the vault

Master keys generated inside a Common Criteria EAL-6 certified HSM. The raw key never exists in software, never touches an admin laptop.

02 · Store

Sleeps in the HSM

Diversified per-card keys derive from the master on demand. Every card carries a unique secret. Extract one, learn nothing about the others.

03 · Rotate

Changes while you sleep

Scheduled rotation across the reader fleet, zero-downtime overlap windows, audit log per door. A compromise in October doesn't outlive October.

04 · Decommission

Gone means gone

When a site closes or a supplier leaves, the key is retired, not archived. Attestation report, signed, minuted. No dormant backdoor.

< 3 S
Credential revokedDenied at the door

04 The vault · Common Criteria · EAL 6

Your keys in your hardware. Yours, not ours.

Master keys stay inside a tamper-evident HSM on your estate or in your cloud tenant. We operate it under a split-custody agreement: two keyholders to rotate, four eyes to decommission, zero keys in spreadsheets.

Common Criteria EAL-6 certified HSM. Auditors see a certificate, not a claim. The key estate inherits the posture.

HSM rack - key feed to card printer, issue in under 90 seconds Elevation of a 19-inch rack containing a certified HSM with two key switches annotated two keyholders, a cable run carrying the key feed to a card printer in side elevation issuing a card, dimensioned at under 90 seconds. RACK A1 HSM - CC EAL6 TWO KEYHOLDERS KEY FEED CARD PRINTER ISSUE < 90 S
HSM rack · Elevation A1 · Key feed to issuance, print-encode-issue in < 90 s

05 Compliance map

What encryption unlocks on paper.

Every framework asks “is the credential tamper-resistant, is the key under control, is there an audit trail?” Strong cards plus our keyring answer all three, in the language of each auditor.

ISO 27001
A.8.24 · A.5.16 · A.8.2

Cryptography, identity and privileged access - all evidenced by HSM attestation and per-reader key logs.

NIS2
Art. 21(2)(i)

Cryptography and key management: documented policy, rotation schedule, incident playbook tied to credential estate.

GDPR
Art. 32 · security of processing

A cloned badge is a data breach. Strong cards close a class of reportable incidents outright.

CC EAL 6
Certified HSM underneath

Common Criteria EAL-6 certified HSM underneath. Auditors see a certificate, not a claim. The key estate inherits the posture.

06 Migration playbook

Multi-site, multi-reader, zero downtime.

Nobody replaces 6,000 badges on a Friday. The move from prox to encrypted happens a reader at a time, a cohort at a time, with both credentials live until the last one leaves.

Step 01

Baseline the estate

We scan every reader, flag the downgrade paths, and map which doors share which keyspace. You see the risk before you touch a card.

Step 02

Dual-credential window

Readers accept both the old prox and the new DESFire for a defined overlap, typically 30 to 90 days. No big-bang, no locked-out staff on Monday morning.

Step 03

Re-issue by cohort

Starting with privileged and high-traffic sites. Self-service kiosks, mobile wallet where estate allows, printed-and-encoded where it doesn't.

Step 04

Cut the old key

Once every reader reports green and every cohort is migrated, the legacy key is retired from the HSM. Attestation signed. Audit closed.

07 Related sheets

Continue through the drawing set.

Are you confident in the security level of your credentials?

Tell us what readers you have and we'll tell you which of your cards can be cloned with a £30 copier. It's usually more than you'd hope.