What is a Dormakaba Confidant credential?
A Dormakaba Confidant credential is a 13.56 MHz contactless smart card issued for Saflok and dormakaba electronic locks, most often in hospitality. Confidant RFID is one of dormakaba's lock lines, and the card carries a guest or staff key that the lock validates locally. On dormakaba's highest tier, that card is an AES-secured smart card protected by an additional AES-128 encryption layer that dormakaba calls Enhanced Security.
Dormakaba layers its credentials into tiers rather than a single card type. A Confidant deployment can run legacy cards, a 3DES-secured memory card as the default minimum, or the AES-128 Enhanced Security credential — and which tier a property is on determines how resistant its keys are to copying.
What is dormakaba Enhanced Security (AES-128)?
Enhanced Security is dormakaba's added AES-128 encryption layer for hotel key credentials, described in its Enhanced Credential Encryption security advisory dated 6 September 2023. The advisory sets out a credential pyramid: legacy security (which dormakaba flags to upgrade), standard security (a 3DES-secured memory card, dormakaba's stated default minimum), enhanced security ("an additional encrypted layer using AES-128"), and mobile credentials.
Enabling Enhanced Security is not just a new card. Per dormakaba's own guidance it requires updated RFID encoders, a supported Ambiance software version, reissued guest and staff cards, and lock firmware updates so that "locks are programmed to accept only high-security keys." It is a coordinated upgrade of card, encoder, software, and lock — which is why it is planned as a project, not a card swap.
Is my Saflok / Confidant lock affected by the Saflok vulnerability?
The Saflok vulnerability, tracked as CVE-2024-29916 and published 21 March 2024, describes weak key derivation that relied on the card's serial number, affecting pre-fix firmware on Saflok MT, RT, Confidant, Quantum and Saffire locks. It was assigned a CVSS score of 5.6 (medium) by CISA-ADP. Independent researchers who disclosed it ("Unsaflok") estimated a very large installed base was affected and that remediation transitions properties to a stronger credential.
Two honesty notes matter here. The headline scale figures — millions of doors across tens of thousands of properties — are the researchers' estimates, not numbers dormakaba has confirmed. And dormakaba has stated publicly that it is "unaware of any reported instances of this issue being exploited." The correct response is not alarm but the upgrade dormakaba already recommends: move the property onto Enhanced Security AES-128 keys and apply the firmware updates.
How do I upgrade a Confidant system to Enhanced Security?
Upgrading a Confidant or Saflok system to Enhanced Security follows the path dormakaba lays out across its security-support advisories. In short: move from legacy cards to at least the 3DES-secured default minimum, then enable Enhanced Security (AES-128) on a supported Ambiance version, install the required RFID encoders, reissue all guest and staff cards, and apply lock firmware updates so locks accept only high-security keys.
Because dormakaba's own advisory filenames and CDN dates do not always match each document's printed date, confirm the current steps through dormakaba's security-support hub rather than a stray PDF link. Dormakaba also publishes a hospitality self-assessment tool and a support line for operators working through the upgrade.
Dormakaba credential tiers at a glance
The table maps dormakaba's credential pyramid so an operator can locate their property's current tier.
| Tier | Credential | Encryption | Dormakaba guidance |
|---|---|---|---|
| Legacy | Non-secure 13.56 MHz smart card | Weak / broken | Recommend upgrade |
| Standard (default minimum) | 3DES-secured memory card | 3DES | Baseline, capabilities declining |
| Enhanced Security | AES-secured smart card | AES-128 layer | Recommended for hotels |
| Mobile | Phone / digital wallet key | Encrypted BLE / wallet | Optional add-on |
Can I source a compatible Confidant card?
An Enhanced Security Confidant card is encoded with your property's AES-128 keys through dormakaba's Ambiance software and Gen II encoders, so a genuinely compatible high-security Confidant card is not something an independent supplier can produce. Security ID Systems does not offer a keyed Enhanced Security credential; additional high-security cards come from dormakaba or your integrator, who hold the keys.
What we do supply are the open hotel-card formats around a dormakaba estate — blank hotel key cards, Saflok and Quantum card stock, and legacy magstripe cards for older front-desk units. Those are the formats below.
Hotel-card formats we supply
We don't sell a keyed Enhanced Security Confidant credential, but these open hotel-card formats are ones we stock and encode for dormakaba, Saflok and adjacent front-desk systems.
Sources & references
Dormakaba and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.