What is Inner Range SIFER?
SIFER is Inner Range's high-security smart-card reader and credential system, used with its Integriti access-control platform. Inner Range describes the SIFER reader as "a multi-drop RS-485 based reader that employs 128 bit AES encryption from the card right through to the door module," using an AES-secured 13.56 MHz smart card as the credential.
What sets SIFER apart from a typical reader is where the encryption reaches. Many systems encrypt only between the card and the reader; SIFER extends the 128-bit AES protection along the reader-to-controller link as well, so the credential data stays encrypted from the card to the door module rather than being exposed on the wiring.
What frequency and encryption does SIFER use?
Inner Range SIFER operates at 13.56 MHz on an AES-secured smart card and protects the credential with 128-bit AES. The SIFER credential carries a 56-bit identifier composed of a 24-bit site code and a 32-bit card number, and the reader talks to the controller over a multi-drop RS-485 connection that Inner Range describes as a superset of OSDP — "more secure than Wiegand."
The AES-secured smart card generation SIFER uses is independently Common Criteria certified. Combined with the encrypted RS-485 link, this closes two gaps at once: the credential cannot be skimmed as a clear number, and the reader-to-controller wiring cannot be tapped or replayed the way unencrypted Wiegand can.
What are the SIFER-P, SIFER-U and SIFER-C tiers?
SIFER credentials come in tiers that differ by which encryption key they use, and the tier decides whether a card is clone-resistant. The critical distinction is between the shared factory key and a site-specific key.
| Tier | Key used | Who sets it | Clone-resistant? |
|---|---|---|---|
| SIFER-P | Shared Inner Range global key (default site code 1001) | Factory pre-programmed | No — the key is common to all SIFER-P |
| SIFER-U | Custom site-specific 128-bit AES key | Installer programs on site | Yes — site key not shared |
| SIFER-C | Custom site-specific key, factory-locked batch | Factory to a site's custom key | Yes — site key not shared |
How secure is a SIFER card, and can it be cloned?
A SIFER card's clone-resistance depends entirely on whether the site uses a custom key. On the factory SIFER-P profile, cards are pre-programmed with a shared Inner Range global key and a default site code, so they authenticate but do not provide site-unique protection. Once an installer loads a site-specific 128-bit AES key (SIFER-U) or orders factory custom cards (SIFER-C), the credential is bound to a key that is not shared with any other site.
Inner Range's documentation makes the effect concrete: once a reader is secured with a site's custom key, it "will not be able to read SIFER-P pre-programmed cards, only secured cards using the same custom encryption key." For the highest assurance, SIFER offers a "Gold Card" option that generates a guaranteed-unique key that nobody — including Inner Range — can view.
How does a site migrate to SIFER?
A SIFER migration typically starts from 125 kHz proximity or Wiegand readers and moves to SIFER's encrypted 13.56 MHz smart card over secure RS-485. Because SIFER uses its own credential and key model, new SIFER cards must be issued to all users, and the Integriti controller must meet Inner Range's firmware and software minimums for SIFER support.
The security-critical step is not merely adopting SIFER but moving off the shared SIFER-P global key to a site-specific SIFER-U or SIFER-C key. A deployment left on the shared global key has the encryption plumbing in place but not the site-unique protection, so the migration is only complete once a custom key is loaded and cards are re-issued against it.
Can I buy a compatible Inner Range SIFER card?
It depends on the tier. For a site running the factory SIFER-P profile — the shared Inner Range global key with the default site code — the 56-bit format is fixed and a compatible SIFER-P card can be supplied. For a site that has moved to a site-specific SIFER-U or SIFER-C key, no third party can produce a working credential, because the card is bound to a key held only by the site; those come from Inner Range or your integrator.
The other formats we can supply are the legacy 125 kHz proximity layers a site migrates away from — Inner Range's own low-frequency prox formats and the general prox formats a mixed site carries. Those open low-frequency formats we encode as fully compatible credentials.
Compatible formats we can supply
For sites still on the shared-key SIFER-P profile, or running 125 kHz proximity during a SIFER migration, these are formats we encode as fully compatible credentials.
Sources & references
Inner Range and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.