Unlocking the Smart Card
Total Page:16
File Type:pdf, Size:1020Kb
Episode Four: Unlocking the Smart Card This is an excerpt from Unlocked — an ASSA ABLOY podcast series on campus security. Unlocked explores the security issues and challenges that colleges and universities face as they strive to create a safe and secure learning environment. Visit intelligentopenings.com/unlocked to hear more. How We Got Smart Before diving into the current broken cards and physical wear on the credential technologies, it helps to readers. Prox solved these problems. understand where we came from. Lower maintenance costs, increased In 1960, a young engineer from IBM user convenience, and new options named Forrest Parry invented the for form factors like fobs made the magnetic stripe card. Once prox card a winner. But the low- ubiquitous on campus doors, more frequency proximity technology is reliable and secure technologies not without its limitations. are quickly eclipsing the mag stripe. Mag stripe cards are simple. A card gets swiped in a reader. That reader then reads a sequence of numbers Outside of higher stored on the stripe of that card. education and If the number matches what’s stored in the access system’s older hotels, hardly Whether installing a new door access database, the door unlocks. system for your campus or upgrading from a legacy system you have a lot of Many campuses still use the mag anyone still uses decisions to make. stripe card for their door access. This is mainly because the cards are mag stripe cards You first must choose the right access inexpensive, the cost to replace the software and locking hardware. You existing swipe readers is high, and for door access. also need to find a knowledgeable other systems aside from security and trustworthy integrator to install still rely on that technology—namely and service your system. And you campus one-card systems that use need to determine which card the card for dining, laundry, Like the mag stripe, the prox card is technology is right for your campus. vending and other purchases. unencrypted and static—making them easy to clone or forge. You also And this last task is not always as Yet, outside of higher education and can’t encode additional information easy as it might seem. older hotels, hardly anyone still uses onto the prox cards, like multiple IDs. mag stripe cards for door access. A common misunderstanding for In the 90’s the access control Out of these security limitations and campus IT professionals that deal industry made a wholesale shift frustrations came the contactless with physical access security is from mag stripe to the new, “smart card” as we know it today. differentiating between the access contactless technology called The biggest technology difference cards. How do you know which prox—known more officially as between smart cards and prox cards is technology is the right one for you? “low-frequency proximity”. the frequency of the chip inside. Prox cards use a low-frequency 125kHz A lot of technology is packed into When the prox card came on the technology, whereas the new breed of the cards. And there are a lot of scene, everyone was thrilled. smart cards use a high-frequency marketing materials surrounding 13.56 MHz technology. which cards are best for you. It can The mag stripe card was cumbersome be difficult to figure out exactly what and inefficient. Not to mention your campus needs. administrators felt the financial sting and maintenance headaches from And what you don’t. Smart Card vs. Prox Smart “One Cards” Although a massive install base of prox The difference in frequencies between A source of confusion unique to technology exists, the last five years the prox card and the smart card can higher ed when it comes to smart have a seen a transition to smart card also affect performance. But not in the cards, is the term itself “smart card”. technologies. According to Eric Widlitz, way you might think. While smart card is used universally vice president of sales at Vanderbilt in other verticals of the physical Industries, he sees no reason not to Schools that purchase the smart, security industry, in higher ed we make the transition. or contactless, card for the sake of tend to refer to them as convenience for their students can be contactless cards. “You certainly have a gigantic install surprised to find out the read range is base of prox technology that you’ll limited on the smart card. Why? Well here’s a little history continue to support for a long time lesson. A bunch of years ago smart moving forward,” says Widlitz. “But This is because the difference in cards became popular on a handful smart card technologies today from a frequencies on the card can have of large universities for student cost perspective are pretty much the an impact and effect on the card’s purchases like vending and laundry, same price. And in some cases, may read range. You typically get a slight and for meal plans. What we now even cost less money than a reduction in read range with smart call One Card systems. These smart proximity card.” cards. And the read time and the cards were of the contact chip communication time between card variety. The eventual problem with It’s well known that smart cards are a and reader is a little bit longer. them was the money was stored more secure credential than prox. But “offline” on purses on the card. As another advantage that smart cards “You definitely take a little hit on the networked, “online” systems gained have over prox is the ability to store and convenience side on the speed and in popularity these smart card secure other useful information on the read range that you have. But you have systems became irrelevant. card itself. the insurance that your information Just about all those smart card is secure on that card and that people systems have been ripped out and can’t take that information off your replaced on the campuses who card,“ says Widlitz. used them. “From a cost This is something to keep in mind And because of that experience, perspective, today’s when your campus starts discussing the term “smart card” when talking the benefits of smart cards. Fortunately, to campus folks who also deal smart card as people get accustomed to longer with the one card, payment side read times of EMV credit cards they are of the credential has left a bad technologies are less prone to notice the slight increase taste in their mouth. That is why of speed on the contactless cards most vendors dealing with the pretty much the over the prox. payment side refer to the newer technology cards almost exclusively same price as a To recap, here are three reasons to as contactless. choose a contactless smart card over proximity card. In a prox card. Or why you might So you see how confusion can arise consider upgrading from an existing when a one card vendor calls them some cases, they may prox card installation: contactless, and a security vendor calls the same card a smart card. even cost less.” 1. Contactless smart cards are safer. They can’t be copied, Most people in the security industry or “skimmed” in the way prox will use the term smart card to Widlitz explains: “A prox card is kind of cards can. encompass pretty much all types of like a license plate. It will transmit one 2. They can cost the same—or in contactless cards that aren’t prox. ID number to the system and that is all some cases—cost less than prox. it is capable to do. And it’s not secure. 3. They can store additional data On a smart chip, you have multiple and be used for other applications, containers that you can store different like transit systems. applications in. Each one of those containers is secured. Think about it “There is absolutely no good reason like a filing cabinet, and you have a key today—starting with a new, fresh to each one of the drawers on the filing install—why you would ever put in cabinet. There’s an encryption key that proximity technology or put in mag secures the information on the card for stripe technology,” says Widlitz. each one of those applications. It can be used for multiple applications where “You should always think about you can’t use any of the previous types moving forward with some sort of of technologies for that.” smart card technology.” “ If you are considering purchasing a smart card and only plan to use the serial number, it’s no different than using a prox card.” Trust in a Handshake For colleges and universities, one of the And if they authenticate each other, something goes wrong at that initial biggest benefits of smart cards is that then the smart card will start releasing communication, then the card and they are more secure than the prox the information that’s being asked for.” reader will stop communicating and the card. This is because of something door will remain locked. called mutual authentication. So, the card reader performs a couple tests that the smart card Without delving into the details of According to Widlitz, mutual needs to go through to make sure it’s the cryptographic authentication, authentication works like this: “In the communicating with the right type it’s important to know that this secure simplest of terms, a reader will boot up of card. And if they have that correct technology is available today and at a chip, start a chip, they’ll start talking handshake together then the process a comparable cost to older, less to each other.