What is ICT Protege and the tSec reader?
ICT Protege is the access-control and intrusion platform from Integrated Control Technology, sold as Protege GX (enterprise) and Protege WX (web-based, smaller sites). The credentials are read by ICT's tSec reader range, which the datasheet calls "a complete multi-technology smart card RFID solution" — meaning one reader can handle several card technologies at once.
The significance of tSec is that it lets an ICT Protege site run modern and legacy credentials side by side. ICT's own material describes support for an AES-secured 13.56 MHz smart card and 125 kHz cards "from a single reader," plus optional Bluetooth and NFC mobile credentials. That multi-technology design is what makes a phased upgrade off insecure prox possible without swapping every reader on day one.
What card technology does ICT Protege use?
ICT Protege uses an AES-secured 13.56 MHz smart card (ISO/IEC 14443 Type A) as its secure credential, while the tSec readers also read legacy 125 kHz proximity for migration. ICT's tSec datasheet names the smart-card credential explicitly and lists 13.56 MHz operation; the verified datasheet references the EV1 generation of the AES-secured smart card, so this guide does not assert newer generations that ICT's public datasheet does not confirm.
The security comes from the AES layer: the credential is bound with diversified keys and mutual authentication rather than broadcasting a fixed number, and ICT supports customer-owned key management. That is the difference between a tSec smart card and the 125 kHz cards it replaces, whose fixed numbers can be copied with an inexpensive cloner — the risk ICT itself highlights in its "125 kHz proximity card dilemma" guidance.
How does ICT secure the reader-to-controller link?
ICT secures the reader-to-controller link with OSDP Secure Channel using AES-128, or with encrypted RS-485. ICT's tSec datasheet states that "OSDP with secure channel offers additional security with AES-128 encryption and predefined key management and authentication," and the readers carry the OSDP Verified logo for the OSDP 2.2 secure profile.
This closes the classic weakness of legacy Wiegand wiring, which is unencrypted and can be tapped to inject card numbers behind the reader. On an ICT Protege system, running tSec readers to the controller over OSDP Secure Channel means the AES protection that starts at the card continues across the cable, so an attacker cannot simply splice the line to defeat a strong credential.
How secure are ICT Protege mobile credentials?
ICT Protege mobile credentials use strong encryption on both radios: ICT's datasheet lists the NFC mobile credential as "AES-256 (NIST certified)" and the Bluetooth mobile credential as "AES128 Encrypted." A phone enrolled into Protege can therefore serve as a credential with cryptography comparable to, or stronger than, a physical smart card.
For a buyer, the value is choice and lifecycle control: mobile credentials can be issued and revoked remotely, and they ride the same tSec readers as cards during a transition. The table below summarises what a tSec reader accepts and the encryption on each path.
| Credential / link | Technology | Encryption |
|---|---|---|
| Legacy card | 125 kHz proximity | None |
| Smart card | 13.56 MHz AES-secured (EV1-class) | AES-128, diversified keys |
| Reader → controller | OSDP v2 Secure Channel | AES-128 |
| Mobile (NFC) | Smartphone tap | AES-256 |
| Mobile (Bluetooth) | Smartphone BLE | AES-128 |
Can I get a compatible ICT Protege card?
A coded ICT Protege smart card is written with your site's AES keys, so a working credential is sourced through ICT or your integrator — Security ID Systems does not sell a drop-in coded ICT card. As with other keyed AES systems, the encryption keys, not the plastic, are what make a card yours, so there is no legitimate off-the-shelf "compatible" ICT smart card for a properly keyed site.
What we do supply is the migration layer that tSec's multi-technology readers are built for. The 125 kHz proximity cards you are moving away from — and generic Wiegand or card-serial-number credentials where a reader is set to read a plain identifier — we encode as fully compatible credentials that read identically on your existing readers.
Compatible formats we do supply
Coded ICT Protege smart cards carry your own keys and come through ICT or your integrator. The 125 kHz proximity and generic Wiegand formats a tSec multi-technology reader still accepts during migration are ones we supply as fully compatible credentials.
Sources & references
Integrated Control Technology and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.