A new era of credential security threats
Modern buildings now face the same access security threats that have transformed vehicle theft in recent years. Criminals no longer need to rely on force to gain entry; instead, they exploit weak credential technologies using inexpensive tools and widely available techniques. Offices, hospitals, residential developments, universities, and data centres continue to depend on outdated access technology that was never designed for today’s evolving threat landscape. Wireless attacks such as relay attacks, replay attacks, signal jamming, and credential cloning have become increasingly common, particularly through older 125 kHz proximity cards and weak Bluetooth-based mobile credential systems.
The weaknesses of legacy access credentials
Why 125 kHz proximity cards are vulnerable
Legacy 125 kHz proximity cards remain one of the most widely deployed credential technologies in the world. These cards simply broadcast an unencrypted facility code and card number whenever they are energized by a reader. There is no authentication, encryption, or challenge-response mechanism.
As a result, malicious actors can capture the credential data and clone it onto a blank card within minutes using inexpensive hardware. From the access control system’s perspective, the cloned card is indistinguishable from the legitimate credential.
Researchers have repeatedly demonstrated these weaknesses at major security conferences using low-cost tools such as the Proxmark 3, iCopy-XS or Flipper zero. Today, the barrier to entry is extremely low. A credential cloning attack can cost less than $100 and requires only basic technical skill, with tutorials widely available online.
Vulnerabilities in early smart cards and mobile credentials
Even newer smart card systems have experienced compromise. Early-generation multi-technology cards were reverse-engineered, allowing attackers to extract and duplicate credentials. Similarly, some first-generation mobile credentials rely on static or weak rotating identifiers that can be intercepted and replayed using Bluetooth sniffing tools.
The issue extends beyond individual credentials. Many legacy access control systems use symmetric security models in which credential secrets are stored on central servers. If the database is breached, every credential associated with the system may be compromised simultaneously.
Public Key Open Credential (PKOC): A modern asymmetric approach
What is PKOC?
PKOC – Public Key Open Credential was developed by the Physical Security Interoperability Alliance (PSIA) to address these vulnerabilities using asymmetric cryptography.
Unlike traditional symmetric credentials that rely on shared secrets or static identifiers, PKOC uses unique public and private key pairs for every credential.
Under the PKOC model, the private key is securely generated and stored on the user’s device, such as a smartphone secure enclave. The private key never leaves the device and is never transmitted. The access control system stores only the corresponding public key.
How PKOC prevents cloning and replay attacks
When a user presents a credential, the reader issues a unique asymmetric cryptographic challenge. The credential signs the challenge using its private key, and the system verifies the response using the registered public key.
Because every challenge is unique, intercepted data cannot be replayed. Since the private key never leaves the device, credential cloning becomes effectively impossible.
This architecture removes many of the vulnerabilities associated with relay attacks, replay attacks, credential cloning, and database compromise that continue to affect legacy access systems.
PKOC also aligns with broader modern security standards, including FIDO2 and emerging digital identity frameworks.
The business and security benefits of PKOC
For organizations, the business case for modernizing access credential technology is increasingly clear. Physical security breaches can result in operational disruption, financial loss, reputational damage, and regulatory exposure.
In high-security environments such as healthcare facilities, critical infrastructure sites, and data centres, unauthorized access may also create significant safety risks.
By adopting cryptographically secure credentials, organizations can significantly reduce the risk associated with outdated access technologies, while improving long-term security resilience.
PKOC mass enrollment synhronization is now here
Up until recently there was no other way to enroll users with PKOC credentials other than manual one-by-one roll out of PKOC physical cards. This meant it was not practical for enterprises to embrace this credential technology, and meant they continued to invest in symmetric credential technology that was practical and easy to roll out even though it kept them at risk of relay and credential cloning attacks.
Now a mass enrollment service for PKOC physical and mobile access credentials is available to enterprises. This unique service that is set to change the credential security landscape can be simply added to compatible access control infrastructure via a software integration from Sentry Interactive.
PKOC mass enrollment is enabling organizations to embrace the next generation of credential security, with the ability to roll it out fast and at scale. From one centralized cloud access control system, enterprises can remotely provision thousands of PKOC credentials to users across multiple locations, just as easily as one.
Moving beyond legacy credentials
The physical security landscape has changed dramatically. The techniques now used to steal modern vehicles are equally applicable to outdated building credentials.
Continuing to rely on static-code proximity cards or weak symmetric mobile credentials exposes organizations to unnecessary and preventable risk.
PKOC provides a practical, open-standard solution built around modern asymmetric cryptography. By ensuring that private keys never leave the credential holder’s device, PKOC removes the weaknesses that attackers once relied upon.
Organizations can now adopt this next generation of credential security using the compatible access control infrastructure which they may already own, helping facilities transition from vulnerable legacy credentials to credentials authenticated with asymmetric cryptography.
As physical and digital security continue to converge, organizations that modernize credential security today will be better positioned to protect people, assets, and operations in the future.