High-security 13.56 MHz credential

ICT Protege Credentials Explained: tSec, OSDP & Smart Cards

ICT Protege is an access-control platform (Protege GX and WX) read by ICT's tSec multi-technology readers, which support an AES-secured 13.56 MHz smart card alongside legacy 125 kHz proximity. ICT secures the reader-to-controller link with OSDP Secure Channel using AES-128, and its mobile credentials use AES-128 (Bluetooth) and AES-256 (NFC). Coded smart cards use your own keys, so they are sourced through ICT or your integrator.

Last updated 2026-07-29

What is ICT Protege and the tSec reader?

ICT Protege is the access-control and intrusion platform from Integrated Control Technology, sold as Protege GX (enterprise) and Protege WX (web-based, smaller sites). The credentials are read by ICT's tSec reader range, which the datasheet calls "a complete multi-technology smart card RFID solution" — meaning one reader can handle several card technologies at once.

The significance of tSec is that it lets an ICT Protege site run modern and legacy credentials side by side. ICT's own material describes support for an AES-secured 13.56 MHz smart card and 125 kHz cards "from a single reader," plus optional Bluetooth and NFC mobile credentials. That multi-technology design is what makes a phased upgrade off insecure prox possible without swapping every reader on day one.

What card technology does ICT Protege use?

ICT Protege uses an AES-secured 13.56 MHz smart card (ISO/IEC 14443 Type A) as its secure credential, while the tSec readers also read legacy 125 kHz proximity for migration. ICT's tSec datasheet names the smart-card credential explicitly and lists 13.56 MHz operation; the verified datasheet references the EV1 generation of the AES-secured smart card, so this guide does not assert newer generations that ICT's public datasheet does not confirm.

The security comes from the AES layer: the credential is bound with diversified keys and mutual authentication rather than broadcasting a fixed number, and ICT supports customer-owned key management. That is the difference between a tSec smart card and the 125 kHz cards it replaces, whose fixed numbers can be copied with an inexpensive cloner — the risk ICT itself highlights in its "125 kHz proximity card dilemma" guidance.

How does ICT secure the reader-to-controller link?

ICT secures the reader-to-controller link with OSDP Secure Channel using AES-128, or with encrypted RS-485. ICT's tSec datasheet states that "OSDP with secure channel offers additional security with AES-128 encryption and predefined key management and authentication," and the readers carry the OSDP Verified logo for the OSDP 2.2 secure profile.

This closes the classic weakness of legacy Wiegand wiring, which is unencrypted and can be tapped to inject card numbers behind the reader. On an ICT Protege system, running tSec readers to the controller over OSDP Secure Channel means the AES protection that starts at the card continues across the cable, so an attacker cannot simply splice the line to defeat a strong credential.

How secure are ICT Protege mobile credentials?

ICT Protege mobile credentials use strong encryption on both radios: ICT's datasheet lists the NFC mobile credential as "AES-256 (NIST certified)" and the Bluetooth mobile credential as "AES128 Encrypted." A phone enrolled into Protege can therefore serve as a credential with cryptography comparable to, or stronger than, a physical smart card.

For a buyer, the value is choice and lifecycle control: mobile credentials can be issued and revoked remotely, and they ride the same tSec readers as cards during a transition. The table below summarises what a tSec reader accepts and the encryption on each path.

Credential / linkTechnologyEncryption
Legacy card125 kHz proximityNone
Smart card13.56 MHz AES-secured (EV1-class)AES-128, diversified keys
Reader → controllerOSDP v2 Secure ChannelAES-128
Mobile (NFC)Smartphone tapAES-256
Mobile (Bluetooth)Smartphone BLEAES-128

Can I get a compatible ICT Protege card?

A coded ICT Protege smart card is written with your site's AES keys, so a working credential is sourced through ICT or your integrator — Security ID Systems does not sell a drop-in coded ICT card. As with other keyed AES systems, the encryption keys, not the plastic, are what make a card yours, so there is no legitimate off-the-shelf "compatible" ICT smart card for a properly keyed site.

What we do supply is the migration layer that tSec's multi-technology readers are built for. The 125 kHz proximity cards you are moving away from — and generic Wiegand or card-serial-number credentials where a reader is set to read a plain identifier — we encode as fully compatible credentials that read identically on your existing readers.

Compatible formats we do supply

Coded ICT Protege smart cards carry your own keys and come through ICT or your integrator. The 125 kHz proximity and generic Wiegand formats a tSec multi-technology reader still accepts during migration are ones we supply as fully compatible credentials.

Sources & references

Integrated Control Technology and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

ICT Protege — common questions

What card does ICT Protege use?

ICT Protege uses an AES-secured 13.56 MHz smart card (ISO/IEC 14443 Type A) as its secure credential, read by tSec multi-technology readers that also read legacy 125 kHz proximity. ICT's public datasheet references the EV1 generation of the smart card, so newer generations are not asserted here.

Does ICT Protege support OSDP Secure Channel?

Yes. ICT's tSec datasheet states that OSDP with Secure Channel adds AES-128 encryption with predefined key management and authentication, and the readers are OSDP Verified. Running tSec readers over OSDP Secure Channel replaces tappable Wiegand wiring with an encrypted, authenticated link.

How secure are ICT Protege mobile credentials?

ICT lists its NFC mobile credential as AES-256 (NIST certified) and its Bluetooth mobile credential as AES-128 encrypted. Both ride the same tSec readers as cards, so a site can add phone-based credentials during or after a card migration and revoke them remotely.

Can ICT Protege readers read my old 125 kHz cards?

Yes. ICT's tSec readers are multi-technology, reading 125 kHz proximity and 13.56 MHz smart cards from a single unit. That lets an ICT Protege site transition off insecure prox at its own pace rather than replacing every reader and card at once.

Can I buy a compatible ICT Protege smart card?

A coded ICT smart card is written with your site's AES keys, so a working card comes through ICT or your integrator, not a third party. Security ID Systems supplies the 125 kHz proximity and generic Wiegand formats a tSec reader accepts during migration.