Protocols About 2 min read

Access control protocols and credentials

These pages cover reader communication, credential formats and mobile credential technologies. Use them alongside the access control system references.

Overview#

This section separates four concepts that are often conflated: the reader to controller interface, the credential to reader radio/contact interface, the credential's application/data model, and the authorisation decision made by the access control system.

Reading map#

Module Coverage
OSDP SIA OSDP 2.2.2, RS485 topology, ACU/PD exchanges, Secure Channel, deployment, migration, and defensive diagnostics
Legacy reader interfaces Wiegand signaling and bit formats, Clock and Data, limitations, compensating controls, and migration
Contactless and smart card standards ISO/IEC 14443, ISO/IEC 15693, ISO/IEC 7816, APDUs, applications, and secure messaging boundaries
NFC, BLE, and UWB Discovery, transport, ranging, version status, radio threat model, and access system use
Credential formats and mobile credentials Identifier layouts, smart credentials, public key/mobile designs, lifecycle, privacy, and authorisation mapping

System model#

text
person/device
    │ presents or proves possession
credential / secure element / mobile wallet
    │ contact, NFC, BLE, or UWB
reader or lock
    │ OSDP, legacy interface, IP, or vendor link
access-control unit / decision service
    │ events, policy, identity and audit APIs
management and identity systems

Security can be lost at any hop. A cryptographically strong credential sent as an unprotected static number over a legacy reader link has a weaker end to end result. Conversely, OSDP Secure Channel can't repair a clonable upstream credential or an authorisation policy that accepts stale identities.

Engineering defaults#

  • Prefer OSDP Secure Channel on a supervised, segmented bus; use unsecured mode only for controlled initialisation when required.
  • Prefer credentials that perform challenge response or signed proof over exposed, replayable identifiers.
  • Treat a UID, CSN, serial number, facility code, card number, phone identifier, BLE address, or UWB range result as an input, not as authorisation by itself.
  • Bind proof to the intended reader/session and freshness context; reject replays and stale lifecycle state.
  • Keep credential keys out of readers where a secure element or managed cryptographic boundary can hold them.
  • Design issuance, activation, suspension, revocation, replacement, expiry, recovery, and audit before enrolment begins.
  • Preserve life safety egress and local code requirements independently from cyber controls.

Safety and examples#

This is a defensive developer reference. It doesn't provide credential cloning, bypass, key extraction, or unauthorised entry procedures. Synthetic bit layouts and APDUs are for parser and data model understanding only. Use implementation and validation techniques only on equipment you own or are explicitly authorised to test.

V1 on this index is a manual documentation review. Child protocol pages use V2 where claims were checked against official standards and program documentation. Product certification and site acceptance require the relevant standards body, manufacturer, laboratory, and local authority processes.

Section overview · Wiki home