Anti-Cloning Access Cards

Anti-Cloning Access Control: End-to-End Encrypted Access Cards

Trusted by financial institutions and government facilities: SKeyMa’s AES128/3DES encryption with tamper-proof SAM key storage.

30 Years · Est. 1996
ISO 9001:2015
bizSAFE Level 3
BCA ME04 (L3) Registered

Access control encryption

ISO 14443 UIDs Were Never Designed to Be Secure — Here's the Proof

Reading only a smartcard’s Unique Identifier (UID) is not secure, because that number was never designed to be secret. ISO 14443, the international standard for contactless smartcards, defines the UID as unique to the card — but any reader built to the standard can read it, and today’s card-cloning tools can copy it onto a blank card in seconds. An access control system that grants entry based on UID alone is trusting a number anyone with the right reader can duplicate. That’s why an anti-cloning access control system — one that encrypts and authenticates the data on the card, not just its UID — is now essential for modern security.

Anti-cloning access control system
Full heiight turnstiles at one of the wafer fab manufacturing in Singapore

The Real Threat Isn't Outside Hackers — It's Insiders With Card Readers

Most access-card cloning is an inside job. Forbes reports that insiders are behind the large majority of corporate fraud — as much as 55 to 75% — which makes insider threats one of the top concerns for any door access system. An employee motivated by greed may clone a senior executive’s card to commit fraud for personal gain. Industrial espionage adds another motive: competitors and outside actors target access credentials to gain an edge in high-stakes industries. And on the lower-stakes end, maintenance contractors and real estate agents sometimes clone a card simply because carrying one duplicated card is more convenient than requesting extra credentials from the employer.

How anti-cloning encryption secures an access control card

Securing a card against cloning starts with what’s stored on it. The card holds encrypted data, not a plain readable number. When a cardholder presents the card, the reader unlocks it and reads that encrypted data — then decrypts it using a secret key that exists only inside an authorized reader. Because the secret key is never exposed and the data itself stays encrypted in storage and in transit, there’s nothing on the card, or moving between the card and the reader, for a cloning tool to copy and reuse. This is the core mechanism behind every anti-cloning access control card.

Who should hold the encryption keys? Secret key management with SKeyMa

Storing card data behind a strong encryption key only works if the key itself is handled correctly. A single person holding that key is a single point of failure — if they resign, forget it, or act in bad faith, the whole system is exposed. SKeyMa (Secret Key Management) solves this with split-knowledge key generation: a master key is built from pieces contributed by more than one person, so no single individual ever sees the complete key. The generated master key then lives inside a tamper-proof Secure Access Module (SAM) — the key never leaves it, and readers decrypt data dynamically by working with the SAM rather than holding a copy of the key themselves.

On MIFARE DESFire cards, SKeyMa (delivered as the IBSSweb-SKM module) enforces AES128 mutual authentication, with 3DES support kept only for reading older legacy cards during a phased migration — an approach aligned with NIST SP 800-131A guidance. This matters because MIFARE Classic’s older Crypto-1 cipher was broken in 2008 and legacy UID/CSN cards can be copied in seconds; AES128 with a SAM-protected key is what closes that gap.

 

Three cryptographic tiers, matched to your risk profile

Level 2 · PRIME

Plug-and-play

Factory-managed shared key encryption — the fastest path to closing the UID-only gap.

Level 3 · CORPORATE

Dedicated corporate keys

Exclusive keys for your organization, managed through SKC1000 software.

Level 4 · PRIVATE

Maximum autonomy

On-site key generation through SKPX software — the key never leaves your control.

What End-to-End Encryption Actually Protects — And What It Doesn't

An access card is passed around, tapped, and carried every day without much thought for how exposed it is. A genuinely secure access control system has to account for that. Beyond encrypting what’s stored on the card, the data also needs to stay encrypted as it travels from the reader to the door controller and on to the host system — this is what “end-to-end” means in practice. Forbes Technology Council members note that end-to-end encryption protects both the secrecy and the authenticity of a transaction at every stage it passes through — a standard that carries directly over to physical access control. An anti-cloning system built on that standard protects a company’s most basic security control: who gets through the door.

Access control system at SGX Centre 2 Singapore

System architecture: how card, reader, and host stay encrypted end-to-end

IBSSweb LAN / Internet Controller Controller Controller Secure Encryption Reader Secure Encryption Reader Secure Encryption Reader GoENTRA App DESFire Card Non-authorised / clone card

IBSSweb reaches every controller and secure encryption reader over an individually encrypted link (padlock icons). Rows 1–2 show an authorised GoENTRA mobile credential and DESFire card passing through; row 3 shows a non-authorised or cloned card rejected at the reader.

Frequently Asked Questions

Reading only a card’s Unique Identifier (UID) is not secure because that number was never designed to be secret — ISO 14443 makes it readable by any compatible reader, and modern cloning tools can copy it onto a blank card in seconds.

Most access-card cloning is an inside job. Forbes reports that as much as 55 to 75% of corporate fraud involves insiders, and employees sometimes clone a senior executive’s card for personal gain. Industrial espionage and contractors cloning cards for convenience are the other common sources.

A Secure Access Module (SAM) is a tamper-proof hardware module inside an access control reader that stores the master encryption key, so it never has to leave the reader or exist in ordinary software. SKeyMa generates that key from split knowledge, so no single person ever sees the complete key.

PRIME is a plug-and-play tier using a factory-managed shared key. CORPORATE gives an organization its own dedicated keys, managed through SKC1000 software. PRIVATE is the highest-autonomy tier, generating keys on-site through SKPX software. Architects pick a tier to match their risk profile.

End-to-end encryption means data stays encrypted at every stage: on the card, while an authorized reader decrypts it with a secret key, and again as it travels from the reader to the door controller and on to the host system.

Built for Financial, Government, Data Centre & 6 More Sectors

Financial

High-value, high-insider-risk environments where a cloned executive credential is a direct fraud exposure.

Government

Sites secured to the standards ASIS helped shape as part of Singapore's PS21 electronic-security programme.

Data Centre

Server-rack and cage access where a cloned card would defeat the physical layer of a zero-trust posture.

Industrial

Wafer-fab and cleanroom environments where cloned credentials put high-value IP at industrial-espionage risk.

Petrochemical, Oil & Gas

Explosion-rated sites where credential integrity has to hold up alongside intrinsically safe hardware.

Transportation & Logistics

Cargo terminals and transit hubs, where access events tie directly into chain-of-custody records.

Health Care

Controlled-substance and restricted-area access, where only verified staff can be allowed through.

Educational Institution

Shared campuses with multiple independent faculties, each needing credentials that can't be duplicated between zones.

Commercial & Residential

The everyday cloning risk: contractors and agents duplicating a card rather than requesting extra credentials.

Book a Technical Demo With ASIS Technologies' Encryption Team

ASIS Technologies has engineered access control systems since 1996 and is a member of the Kuok Group. Request a demo to see how SKeyMa closes the UID-cloning gap on your current cards.

Have a Question?
For assistance... For assistance... 65 6844 2141