Skip to content

Security

The card number is not a credential

Most badge systems authenticate by reading a number off a card and comparing it to a list. That is an identifier, not proof of anything, and the federal standard that governs the largest deployment of badges in the country removed the equivalent mechanism outright.

5 min readComputing America

In short

  • Presenting a card number proves possession of something that broadcasts a number. It is identification; treating it as authentication is a category error that the door hardware cannot detect.
  • FIPS 201-3 removed the CHUID authentication mechanism and states that relying systems must not use it, while keeping the CHUID data element itself mandatory. Reading the number is still fine; trusting it to open a door is not.
  • The reader-to-panel link is the part nobody looks at. The legacy Wiegand interface carries the number in clear and is unsupervised, so a device spliced into the run is indistinguishable from a reader.
  • OSDP with Secure Channel is the replacement, is bidirectional and supervised, uses AES-128, and has been an IEC standard since 2020, so this is a procurement decision rather than a research project.
  • Sequence the migration by consequence, not by floor plan. The doors worth doing first are the ones where a false entry is expensive, and they are rarely the ones nearest reception.

A badge system does something that looks like authentication and usually is not. A card comes near a reader, the reader gets a number out of it, the number travels to a panel, the panel checks a list, and a door opens. Every step is doing its job. The system as a whole has established that something in the vicinity of the reader was willing to emit a number that appears on a list.

That is identification. Authentication is the demonstration that the holder possesses a secret they could not have obtained by watching, copying or standing near the original. The difference is not academic and it is not new; it is the difference between a name badge and a signature, and the reason it survives in buildings is that the failure mode is silent. A cloned card produces an ordinary access event with an ordinary name on it. The log looks like the log.

The federal government already worked this out, in public

The most useful thing to point a skeptical facilities manager at is not a vendor white paper, it is FIPS 201-3 (opens in a new tab), the standard behind the PIV cards carried by federal employees and contractors. It records the exact move this article is arguing for, in the standard’s own vocabulary, and it records it as a removal rather than a recommendation.

“The CHUID authentication mechanism (Section 6.2.5) was previously deprecated in FIPS 201-2 and has been removed from this version of the Standard. Therefore, relying systems must not use this authentication mechanism.”
FIPS 201-3, Personal Identity Verification (PIV) of Federal Employees and Contractors (opens in a new tab)

The precision matters, and it is where facilities teams misread the standard. The card holder unique identifier is a data element and it is still mandatory; the card still carries it and reading it is still legitimate. What was removed is treating that read as an authentication. The same revision also deprecated the visual credential as a stand-alone mechanism, while allowing it alongside others, which is the same distinction applied to a guard looking at a photograph.

For the pairing of authentication mechanism to door, the companion document is NIST SP 800-116 Rev. 1 (opens in a new tab), which sets out a risk-based way to choose which mechanism applies where rather than mandating the strongest one everywhere. That posture is the transferable part for a commercial building, where the answer is never one mechanism on every door.

The wire between the reader and the panel

Assume for a moment the credential is strong. There is a second exposure that no card upgrade touches, and it is the run of cable from the reader on the outside wall to the panel in the closet. On legacy Wiegand that link carries the card number in the clear, in one direction, with no authentication of the reader and no supervision of the line. A panel cannot distinguish a reader from anything else presenting well-formed data on those conductors, and the reader is by definition on the untrusted side of the door.

The replacement is not exotic. The Security Industry Association describes OSDP (opens in a new tab) as an open standard between access-control panels and peripherals designed as a more capable alternative to the legacy Wiegand interface, with bidirectional communication and a Secure Channel using AES-128 encryption. It was approved as an international standard by the IEC in May 2020 and published as IEC 60839-11-5, and SIA released version 2.2.2 in October 2024. This is settled, purchasable technology, which changes the character of the conversation: the question is scheduling and budget, not whether a solution exists.

Sequencing, for a building that cannot be re-badged this quarter

The reason these estates stay unimproved for a decade is that the honest full answer (new credentials, new readers, new panels, one identity source) is a capital project, and the alternative offered is usually nothing. There is a middle, and it is ordered by consequence rather than by geography.

  1. 1.List the doors by what is behind them, and be specific about the loss. A door onto a bonded store, a laboratory holding controlled material, a plant room where an unaccompanied person can cause an outage. Most estates find the count is under ten.
  2. 2.For those doors only, fix the credential and the link together. Upgrading one without the other is the most common half-measure and buys much less than it costs, because the weaker of the two is what an attacker is choosing between.
  3. 3.Add a second factor where a door protects something whose loss is not recoverable, rather than everywhere. A keypad on eleven doors that people prop open is worse than a keypad on one that they do not.
  4. 4.Tie the directory to one identity source, so that a leaver loses the building on the day they lose the network. This is the change that most often finds the real defect, which is a list of active credentials whose owners no longer work here.
  5. 5.Only then work outward to the perimeter and the interior doors, where a clone gets somebody into a corridor rather than into a consequence.

Step four is worth dwelling on because it is the cheapest and it is the one that gets deferred. Physical and logical identity being separate systems is normal, and it means offboarding is two processes maintained by two teams with two failure modes. The badge that still opens the door eight months after the person left is not a cryptography problem, and no reader upgrade addresses it.

Where this argument stops

Cloning a badge requires proximity to a person or to a reader, and for most buildings the realistic adversary is not carrying a cloner; they are following somebody through a door that was held open for them. Tailgating defeats every credential described here and is a facilities and culture problem, not a hardware one. A firm that upgrades its readers and props its side door has bought nothing, and should be told so before the quotation is prepared.

It is equally true that a badge system is not a vault and does not have to be. Its job in most buildings is to make entry accountable and to make removal fast, and those two properties come mostly from the directory being correct and the logs being kept, which are cheap. The hardware argument matters at the small number of doors where entry itself is the harm. Spend there, say plainly that the rest are identification rather than authentication, and do not sell a building a posture it did not ask for.

Sources

  1. 1.FIPS 201-3: Personal Identity Verification (PIV) of Federal Employees and Contractors (opens in a new tab), NIST
  2. 2.SP 800-116 Rev. 1: Guidelines for the Use of PIV Credentials in Facility Access (opens in a new tab), NIST
  3. 3.Open Supervised Device Protocol (OSDP) (opens in a new tab), Security Industry Association

Next step

Send us a photo of the reader.

A picture of the reader by one door you care about, plus what the panel is, is usually enough. We will tell you what protocol that pairing implies, whether the link between them is supervised, and what the cheapest honest improvement would be.

Reply
A person replies, not a sequence: within one business day, from someone who would be on the engagement.