AES-secured 13.56 MHz hotel credential

Dormakaba Confidant Cards Explained: AES Security & Options

A Dormakaba Confidant credential is a 13.56 MHz contactless smart card used on Saflok and dormakaba electronic locks. On dormakaba's Enhanced Security tier it is an AES-secured smart card protected by an added AES-128 encryption layer, which dormakaba introduced specifically to move hotels off older, weaker credential encryption.

Last updated 2026-07-29

What is a Dormakaba Confidant credential?

A Dormakaba Confidant credential is a 13.56 MHz contactless smart card issued for Saflok and dormakaba electronic locks, most often in hospitality. Confidant RFID is one of dormakaba's lock lines, and the card carries a guest or staff key that the lock validates locally. On dormakaba's highest tier, that card is an AES-secured smart card protected by an additional AES-128 encryption layer that dormakaba calls Enhanced Security.

Dormakaba layers its credentials into tiers rather than a single card type. A Confidant deployment can run legacy cards, a 3DES-secured memory card as the default minimum, or the AES-128 Enhanced Security credential — and which tier a property is on determines how resistant its keys are to copying.

What is dormakaba Enhanced Security (AES-128)?

Enhanced Security is dormakaba's added AES-128 encryption layer for hotel key credentials, described in its Enhanced Credential Encryption security advisory dated 6 September 2023. The advisory sets out a credential pyramid: legacy security (which dormakaba flags to upgrade), standard security (a 3DES-secured memory card, dormakaba's stated default minimum), enhanced security ("an additional encrypted layer using AES-128"), and mobile credentials.

Enabling Enhanced Security is not just a new card. Per dormakaba's own guidance it requires updated RFID encoders, a supported Ambiance software version, reissued guest and staff cards, and lock firmware updates so that "locks are programmed to accept only high-security keys." It is a coordinated upgrade of card, encoder, software, and lock — which is why it is planned as a project, not a card swap.

Is my Saflok / Confidant lock affected by the Saflok vulnerability?

The Saflok vulnerability, tracked as CVE-2024-29916 and published 21 March 2024, describes weak key derivation that relied on the card's serial number, affecting pre-fix firmware on Saflok MT, RT, Confidant, Quantum and Saffire locks. It was assigned a CVSS score of 5.6 (medium) by CISA-ADP. Independent researchers who disclosed it ("Unsaflok") estimated a very large installed base was affected and that remediation transitions properties to a stronger credential.

Two honesty notes matter here. The headline scale figures — millions of doors across tens of thousands of properties — are the researchers' estimates, not numbers dormakaba has confirmed. And dormakaba has stated publicly that it is "unaware of any reported instances of this issue being exploited." The correct response is not alarm but the upgrade dormakaba already recommends: move the property onto Enhanced Security AES-128 keys and apply the firmware updates.

How do I upgrade a Confidant system to Enhanced Security?

Upgrading a Confidant or Saflok system to Enhanced Security follows the path dormakaba lays out across its security-support advisories. In short: move from legacy cards to at least the 3DES-secured default minimum, then enable Enhanced Security (AES-128) on a supported Ambiance version, install the required RFID encoders, reissue all guest and staff cards, and apply lock firmware updates so locks accept only high-security keys.

Because dormakaba's own advisory filenames and CDN dates do not always match each document's printed date, confirm the current steps through dormakaba's security-support hub rather than a stray PDF link. Dormakaba also publishes a hospitality self-assessment tool and a support line for operators working through the upgrade.

Dormakaba credential tiers at a glance

The table maps dormakaba's credential pyramid so an operator can locate their property's current tier.

Dormakaba hotel credential tiers
TierCredentialEncryptionDormakaba guidance
LegacyNon-secure 13.56 MHz smart cardWeak / brokenRecommend upgrade
Standard (default minimum)3DES-secured memory card3DESBaseline, capabilities declining
Enhanced SecurityAES-secured smart cardAES-128 layerRecommended for hotels
MobilePhone / digital wallet keyEncrypted BLE / walletOptional add-on

Can I source a compatible Confidant card?

An Enhanced Security Confidant card is encoded with your property's AES-128 keys through dormakaba's Ambiance software and Gen II encoders, so a genuinely compatible high-security Confidant card is not something an independent supplier can produce. Security ID Systems does not offer a keyed Enhanced Security credential; additional high-security cards come from dormakaba or your integrator, who hold the keys.

What we do supply are the open hotel-card formats around a dormakaba estate — blank hotel key cards, Saflok and Quantum card stock, and legacy magstripe cards for older front-desk units. Those are the formats below.

Hotel-card formats we supply

We don't sell a keyed Enhanced Security Confidant credential, but these open hotel-card formats are ones we stock and encode for dormakaba, Saflok and adjacent front-desk systems.

Sources & references

Dormakaba and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

Dormakaba Confidant / Saflok (Enhanced Security) — common questions

Is my Saflok or Confidant lock affected by the Saflok vulnerability?

CVE-2024-29916 (published March 2024) affected pre-fix firmware on Saflok MT, RT, Confidant, Quantum and Saffire locks through weak key derivation tied to the card serial number. It scored 5.6 (medium). Dormakaba's fix is to move properties onto Enhanced Security AES-128 keys and apply firmware updates.

What is dormakaba Enhanced Security?

Enhanced Security is dormakaba's added AES-128 encryption layer for hotel key cards, introduced in its 6 September 2023 Enhanced Credential Encryption advisory. It sits above the 3DES-secured default minimum and requires updated encoders, a supported Ambiance version, reissued cards, and lock firmware updates.

How many hotels were affected by the Saflok issue?

Independent researchers estimated millions of doors across tens of thousands of properties, but those figures are the researchers' own estimates, not numbers confirmed by dormakaba. Dormakaba has stated it is unaware of any reported instances of the issue being exploited.

Do I have to reissue all guest and staff cards to upgrade?

Yes. Enabling Enhanced Security is a coordinated upgrade: reissue all guest and staff cards onto AES-128 keys, install the required RFID encoders, run a supported Ambiance version, and apply lock firmware updates so locks accept only high-security keys.

Where do I get more Confidant cards?

High-security Confidant cards are encoded with your property's keys through dormakaba's software, so additional working cards come from dormakaba or your integrator. Open hotel-card stock and legacy magstripe cards for older front-desk units can be sourced separately.