IMAJINEERStudio
Smart Access Control Beyond Keycards
All Architecture Articles
ArchitectureJuly 28, 2026 · 5 min read · Sreyna Vale

Smart Access Control Beyond Keycards

A device that copies a 125 kilohertz proximity card sells for under thirty dollars and works in seconds. Smart access control in residential buildings is decided less by the reader at the door than by the credential ledger behind it. This piece examines revocation latency, encrypted credential formats, OSDP wiring, and why a 200-unit building can hold 1,250 live credentials for 500 legitimate residents by year five.

A handheld device that copies a 125 kilohertz proximity card is available online for under thirty dollars, and it completes the copy in a few seconds. It does not need to steal the card. A few centimeters of proximity in an elevator, a parking ramp, or a coffee queue is enough.

That single fact should reorganize how smart access control is evaluated in residential buildings. The reader on the wall is the part everyone can see. The credential ledger behind it is the part that decides whether the building is secure.

Most access conversations in this market start with the hardware. Which reader, which finish, whether the app works. The more useful question is quieter and almost never asked at handover: how long does it take to make a credential stop working, and who has to be called to do it?

What the card actually proves

A 125 kilohertz proximity card transmits a static number in the clear. There is no encryption, no authentication, and no challenge between the card and the reader. The reader checks the number and opens the door, and it has no method for telling an original from a copy.

The next tier up, MIFARE Classic at 13.56 megahertz, added a proprietary cipher with 48-bit keys. That cipher has been publicly broken for years, and key recovery attacks are documented in the security research community. Buildings running either format have a credential layer that is decorative.

The formats that hold up are DESFire EV2 and EV3 and equivalent high-security families, which use AES encryption with mutual authentication and diversified keys. Mobile credentials sit alongside them, carried on a phone that is already protected by the resident's own biometric lock. The practical advantage of the phone is not convenience. It is that a mobile credential can be revoked centrally in seconds, from anywhere, without asking anyone to hand anything back.

The wire behind the reader

Wiegand, the wiring standard that connects most readers to most controllers in this market, dates to the 1980s. It sends credential data in one direction, in plain text, with no supervision of the reader itself. A tap installed inside a reader housing harvests every credential presented to that door, and the controller has no way to report that the reader was ever opened.

The replacement standard, OSDP, was adopted by the Security Industry Association in 2012 and approved as an international standard in May 2020. Its Secure Channel mode encrypts reader-to-controller traffic with AES-128 and continuously supervises the reader for tamper and disconnection. It also runs over RS-485, which allows multi-drop wiring and reaches roughly 4,000 feet against Wiegand's practical limit of about 500.

This is where access control stops being a security topic and becomes an architecture topic. A reader can be swapped in an afternoon. Cabling topology, conduit routing, and controller placement cannot. A building wired home-run for Wiegand carries that decision for its entire operating life, and the decision was made by whoever drew the electrical layout, usually without being discussed.

The number nobody tracks

Here is the metric worth carrying out of this article. Revocation latency is the elapsed time between the moment a credential should stop working and the moment it actually does.

Consider a 200-unit building. At handover it issues roughly two and a half credentials per unit, which is 500 cards in circulation on day one. Then the building starts operating. Housekeepers, drivers, leasing agents, fit-out contractors, and long-staying guests all receive credentials, because the building has no other mechanism for letting them in.

Now add occupant turnover. In a mid-rise with a meaningful rental component, thirty percent of units changing occupants in a year is unremarkable. If each turnover issues fresh credentials and nobody revokes the old ones, the building adds roughly 150 active credentials annually. By year five it holds something near 1,250 live credentials against perhaps 500 people entitled to be inside.

Orphaned credentials are the most common finding in access control audits, and the pattern is consistent across building types: cards are issued reliably and revoked casually. The building's security is then set by the largest number in the database, not the smallest.

Expiry dates instead of intentions

The fix is structural and it is unglamorous. Temporary credentials should carry hard expiry dates written at the moment of issue, so that revocation happens by default rather than by memory.

A delivery credential valid for ninety minutes. A contractor credential valid for the duration of the scope of works and no longer. A domestic staff credential tied to a specific unit, visible to the resident in an app, and revocable by that resident without calling management. None of this is advanced technology. It is a policy written into the specification before the system is procured.

Access tiers deserve the same discipline. A perimeter gate, a lobby turnstile, an elevator floor call, a unit door, an amenity deck, and a back-of-house corridor are not equivalent risks and do not require equivalent credential strength. Encrypted formats belong at the perimeter and the unit door. A bicycle store can carry something lighter.

What this looks like at brief stage

Multi-technology readers read legacy and encrypted formats simultaneously, which means a building can migrate in phases rather than all at once. That flexibility is worth specifying even when the initial rollout is modest.

The arithmetic favors deciding early. In mature markets a single-door upgrade from unencrypted proximity to an encrypted format runs several hundred dollars installed, so a 200-unit building with 40 controlled doors is a five-figure exercise before anyone touches the software. Specifying OSDP-capable readers, RS-485 topology, and an encrypted credential family at the brief adds a small increment to a system that was going into the building anyway.

The retrofit version of the same decision arrives after handover, lands in the maintenance reserve, and competes with every other line item the building did not plan for.

Access control is one of the few building systems where the resident experiences the failure personally. A card that still works for someone who moved out two years ago is not an abstraction. It is a person in the corridor at eleven at night who has no reason to be there.

The security of a building is not decided at the door. It is decided in the database that tells the door what to do, and in how quickly anyone can change what that database says.

Owners who ask a single question, how fast can one credential be revoked and who has to be called to do it, learn more about a building than any specification sheet will tell them. That answer is written at brief stage and almost never revisited.

At Imajineer, credential architecture is drawn alongside the electrical layout, before anyone selects a reader. The conversation is available when it is useful.

footer class="PhCafd B6ltWa"