End-to-end AES access credential

Inner Range SIFER Cards Explained: End-to-End AES & Site Keys

Inner Range SIFER is a high-security 13.56 MHz access credential and reader system that applies 128-bit AES encryption from the card all the way to the door module over a secure RS-485 link. A SIFER deployment is clone-resistant only once it moves off the shared factory key (SIFER-P) to a site-specific key (SIFER-U or SIFER-C).

Last updated 2026-07-29

What is Inner Range SIFER?

SIFER is Inner Range's high-security smart-card reader and credential system, used with its Integriti access-control platform. Inner Range describes the SIFER reader as "a multi-drop RS-485 based reader that employs 128 bit AES encryption from the card right through to the door module," using an AES-secured 13.56 MHz smart card as the credential.

What sets SIFER apart from a typical reader is where the encryption reaches. Many systems encrypt only between the card and the reader; SIFER extends the 128-bit AES protection along the reader-to-controller link as well, so the credential data stays encrypted from the card to the door module rather than being exposed on the wiring.

What frequency and encryption does SIFER use?

Inner Range SIFER operates at 13.56 MHz on an AES-secured smart card and protects the credential with 128-bit AES. The SIFER credential carries a 56-bit identifier composed of a 24-bit site code and a 32-bit card number, and the reader talks to the controller over a multi-drop RS-485 connection that Inner Range describes as a superset of OSDP — "more secure than Wiegand."

The AES-secured smart card generation SIFER uses is independently Common Criteria certified. Combined with the encrypted RS-485 link, this closes two gaps at once: the credential cannot be skimmed as a clear number, and the reader-to-controller wiring cannot be tapped or replayed the way unencrypted Wiegand can.

What are the SIFER-P, SIFER-U and SIFER-C tiers?

SIFER credentials come in tiers that differ by which encryption key they use, and the tier decides whether a card is clone-resistant. The critical distinction is between the shared factory key and a site-specific key.

TierKey usedWho sets itClone-resistant?
SIFER-PShared Inner Range global key (default site code 1001)Factory pre-programmedNo — the key is common to all SIFER-P
SIFER-UCustom site-specific 128-bit AES keyInstaller programs on siteYes — site key not shared
SIFER-CCustom site-specific key, factory-locked batchFactory to a site's custom keyYes — site key not shared

How secure is a SIFER card, and can it be cloned?

A SIFER card's clone-resistance depends entirely on whether the site uses a custom key. On the factory SIFER-P profile, cards are pre-programmed with a shared Inner Range global key and a default site code, so they authenticate but do not provide site-unique protection. Once an installer loads a site-specific 128-bit AES key (SIFER-U) or orders factory custom cards (SIFER-C), the credential is bound to a key that is not shared with any other site.

Inner Range's documentation makes the effect concrete: once a reader is secured with a site's custom key, it "will not be able to read SIFER-P pre-programmed cards, only secured cards using the same custom encryption key." For the highest assurance, SIFER offers a "Gold Card" option that generates a guaranteed-unique key that nobody — including Inner Range — can view.

How does a site migrate to SIFER?

A SIFER migration typically starts from 125 kHz proximity or Wiegand readers and moves to SIFER's encrypted 13.56 MHz smart card over secure RS-485. Because SIFER uses its own credential and key model, new SIFER cards must be issued to all users, and the Integriti controller must meet Inner Range's firmware and software minimums for SIFER support.

The security-critical step is not merely adopting SIFER but moving off the shared SIFER-P global key to a site-specific SIFER-U or SIFER-C key. A deployment left on the shared global key has the encryption plumbing in place but not the site-unique protection, so the migration is only complete once a custom key is loaded and cards are re-issued against it.

Can I buy a compatible Inner Range SIFER card?

It depends on the tier. For a site running the factory SIFER-P profile — the shared Inner Range global key with the default site code — the 56-bit format is fixed and a compatible SIFER-P card can be supplied. For a site that has moved to a site-specific SIFER-U or SIFER-C key, no third party can produce a working credential, because the card is bound to a key held only by the site; those come from Inner Range or your integrator.

The other formats we can supply are the legacy 125 kHz proximity layers a site migrates away from — Inner Range's own low-frequency prox formats and the general prox formats a mixed site carries. Those open low-frequency formats we encode as fully compatible credentials.

Compatible formats we can supply

For sites still on the shared-key SIFER-P profile, or running 125 kHz proximity during a SIFER migration, these are formats we encode as fully compatible credentials.

Sources & references

Inner Range and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

Inner Range SIFER — common questions

What makes SIFER more secure than a Wiegand prox reader?

Inner Range SIFER applies 128-bit AES encryption from the card right through to the door module over a secure multi-drop RS-485 link that is a superset of OSDP. This protects both the credential and the reader-to-controller wiring, unlike a 125 kHz prox card read into unencrypted Wiegand, which can be skimmed and tapped.

What is the difference between SIFER-P, SIFER-U and SIFER-C?

SIFER-P cards are factory pre-programmed with a shared Inner Range global key, so they are not site-unique. SIFER-U cards are programmed by the installer with a custom site-specific 128-bit AES key, and SIFER-C cards are factory-programmed to a site's custom key. Clone-resistance requires a custom key (SIFER-U or SIFER-C).

Do I need a custom SIFER site key, or is the default fine?

The shared SIFER-P global key provides encryption but not site-unique protection, because the same key is common to all SIFER-P cards. A secure deployment loads a custom site-specific key (SIFER-U or SIFER-C). Once a reader holds a custom key, it stops reading shared-key SIFER-P cards.

Can I keep my existing cards when moving to SIFER?

No. SIFER uses its own encrypted credential and key model, so new SIFER cards must be issued to all users, and the Integriti controller must meet Inner Range's firmware and software minimums. Legacy 125 kHz proximity cards can run in parallel only during the migration.

Can I buy a compatible SIFER card?

Only for the shared-key SIFER-P profile, where the 56-bit format is fixed and a compatible card can be supplied. A site using a custom site-specific key (SIFER-U or SIFER-C) cannot get a third-party card, because the credential is bound to a key held only by the site; those come from Inner Range or your integrator.