13.56 MHz access credential

Bosch (Keenfinity) Access Cards Explained: Coding, Security & Upgrade

Bosch's access-control business now trades as the Keenfinity Group, and its recommended credential is an AES-secured 13.56 MHz smart card carrying a "Bosch Code" written into the card's secure sector. Bosch's own whitepaper states that three functions — key diversification, encryption, and mutual authentication — make such a card secure, and that 125 kHz proximity "has been compromised." Bosch-coded cards use your site's keys, so they are sourced through Bosch, not a third party.

Last updated 2026-07-29

Is Bosch access control now "Keenfinity"?

Yes — as of 2025, Bosch's building-technologies access and intrusion business trades as the Keenfinity Group, and boschsecurity.com now redirects to keenfinity-group.com. The products themselves remain Bosch-branded: the AMS management software, the AMC2 access modular controllers, and the LECTUS reader family are all still current under the Keenfinity name.

For anyone maintaining a Bosch access system, the practical takeaway is that support, documentation, and product security advisories now live on the Keenfinity site, but the hardware and card technology are unchanged. This guide uses "Bosch" for the products and "Keenfinity" for the company that now stands behind them.

What card does Bosch recommend to replace 125 kHz proximity?

Bosch recommends replacing 125 kHz proximity with an AES-secured 13.56 MHz smart card. Bosch's data-security whitepaper is blunt that legacy prox "has been compromised," noting that "card-copying devices … make copies" and "gain illicit access," and it states that "upgrading the frequency from 125 kHz to 13.56 MHz allows you to take advantage of the security functions on 13.56 MHz processor cards."

Bosch adds that among modern cards, only a very few credential types remain uncompromised — it names AES-secured 13.56 MHz smart cards and LEGIC Advant among them. In other words, moving to 13.56 MHz is necessary but not sufficient; the card also has to use its cryptographic functions properly, which is where the Bosch Code and key diversification come in.

What makes a Bosch smart card secure?

Bosch's whitepaper attributes a secure smart card to three functions working together, and it is a useful, vendor-neutral way to judge any access credential. The table below lists them and shows how they contrast with a legacy proximity card.

Credential on a Bosch readerSecurityBosch guidance
125 kHz proximityFixed number, no encryptionCompromised — upgrade away
13.56 MHz card, serial number onlySerial read from a public sectorNot sufficient on its own
13.56 MHz AES card + Bosch CodeKey diversification, encryption, mutual authenticationRecommended
Reader → controller (OSDP v2 SC)AES-encrypted, authenticated linkReplaces Wiegand

Why isn't reading the card serial number (CSN) enough?

Reading only the card serial number (CSN) is not enough because, as Bosch notes, the CSN "is always stored in a public (unencrypted) card sector" — anyone with a reader can retrieve it, and it can be copied. A system that authenticates on the CSN alone is little better than a proximity card with a longer number.

Bosch's answer is the "Bosch Code": rather than trusting the public serial, a Bosch-coded card stores its credential data in the card's secure, encrypted sector, protected by key diversification (a unique key derived per card), encryption of the reader-to-card conversation, and mutual authentication so the card and reader each prove themselves. Because that secure sector is written with your site's keys, a Bosch-coded card cannot be reproduced by simply copying its serial number.

Does Bosch support OSDP Secure Channel instead of Wiegand?

Yes — Bosch recommends OSDP v2 Secure Channel for the reader-to-controller link in place of legacy Wiegand. Bosch's whitepaper explains that Wiegand wiring is unencrypted and can be tapped, whereas OSDP v2 Secure Channel provides an AES-encrypted, authenticated connection; Bosch also cites AES-256 encryption on the controller-to-server link.

This matters because the strongest card in the world is undermined if the wire behind the reader broadcasts card numbers in the clear. Running Bosch LECTUS readers to an AMC2 controller over OSDP v2 Secure Channel carries the protection that starts on the card all the way into the AMS software, closing the tap-and-replay gap that legacy Wiegand leaves open.

Where to get Bosch-compatible credentials

A Bosch-coded AES smart card is written with your site's keys, so additional coded credentials are sourced through Bosch/Keenfinity or your integrator — Security ID Systems does not sell a drop-in Bosch-coded card. If your system is an older Bosch Access Professional or AMC deployment reading legacy formats, the companion guide, Bosch Access Professional & AMC: cards, readers & prox migration, covers the migration path in detail.

What we supply is the legacy and UID layer: the 125 kHz proximity cards and card-serial-number credentials that Bosch multi-technology readers still accept during a migration. Those open formats we encode as fully compatible credentials that read identically on your existing readers.

Compatible formats we do supply

Bosch-coded AES smart cards carry your site's keys and come through Bosch/Keenfinity. Where a Bosch reader still accepts 125 kHz proximity or a plain card serial number during a migration, these open formats are ones we supply as fully compatible credentials.

Sources & references

Bosch and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

Bosch access control — common questions

Is Bosch security the same as Keenfinity now?

Yes. As of 2025, Bosch's building-technologies access and intrusion business trades as the Keenfinity Group, and boschsecurity.com redirects to keenfinity-group.com. The products — AMS software, AMC2 controllers, LECTUS readers — remain Bosch-branded and are still supported under Keenfinity.

What card does Bosch recommend to replace 125 kHz prox?

Bosch recommends an AES-secured 13.56 MHz smart card carrying a Bosch Code. Its whitepaper states 125 kHz proximity "has been compromised" and that upgrading to 13.56 MHz lets a site use the card's security functions — key diversification, encryption, and mutual authentication.

What is the "Bosch Code" on an access card?

The Bosch Code is credential data Bosch writes into a card's secure, encrypted sector, keyed to your site. Bosch uses it because the card serial number sits in a public sector that anyone can read and copy, so authenticating on the encrypted Bosch Code instead makes the card far harder to clone.

Does Bosch support OSDP Secure Channel?

Yes. Bosch recommends OSDP v2 Secure Channel to replace legacy Wiegand for the reader-to-controller link, providing an AES-encrypted, authenticated connection, with AES-256 cited on the controller-to-server link. LECTUS readers to an AMC2 controller can run this end to end.

Can I buy a compatible Bosch access card?

A Bosch-coded AES card is written with your site's keys, so a working coded card comes through Bosch/Keenfinity or your integrator, not a third party. Security ID Systems supplies the 125 kHz proximity and card-serial-number credentials a Bosch reader may still accept during migration.