SIFER cards, fobs and the IR56 format

Inner Range SIFER Cards & Fobs: The IR56 Format Explained

Inner Range SIFER cards and fobs are AES-secured 13.56 MHz credentials carrying a 56-bit Inner Range identity (IR56) made of a 24-bit site code and a 32-bit card number. Whether a SIFER credential can be reproduced depends on its key tier: shared-key SIFER-P is a fixed format, while custom-key SIFER-U and SIFER-C credentials cannot be sourced from a third party.

Last updated 2026-07-29

What is an Inner Range SIFER card or fob?

An Inner Range SIFER card or fob is the credential half of the SIFER system, an AES-secured 13.56 MHz smart credential that Inner Range's SIFER readers authenticate with 128-bit AES. The same credential is issued as a plastic card or a key fob, and both carry the same 56-bit Inner Range identity, known as the IR56 format.

Because a SIFER credential is an encrypted smart card rather than a readable proximity token, its identity is released only after an AES exchange. That is what separates a SIFER card or fob from a 125 kHz proximity credential, whose number can be read and copied. The security level a given SIFER card actually provides, though, depends on its key tier.

What is the IR56 / 56-bit SIFER format?

IR56 is the 56-bit Inner Range credential identity used by SIFER. It is composed of a 24-bit site code, which identifies the installation, and a 32-bit card number, which identifies the individual holder. The breakdown below shows how the identity is structured.

FieldWidthPurpose
Site code24 bitsIdentifies the installation / site
Card number32 bitsIdentifies the individual holder
Total identity (IR56)56 bitsThe full Inner Range credential ID
Protection128-bit AESEncrypts the credential card-to-door

Why does the key tier matter for SIFER cards and fobs?

Two SIFER cards can share the identical IR56 format and still differ completely in security, because the security lives in the key. A SIFER-P card is factory pre-programmed with a shared Inner Range global key and a default site code, so every SIFER-P card in the world uses the same key. A SIFER-U or SIFER-C card is bound to a custom site-specific 128-bit AES key that belongs only to one installation.

This is why a site that has hardened its SIFER system to a custom key will find that its readers "will not be able to read SIFER-P pre-programmed cards, only secured cards using the same custom encryption key." For cards and fobs, the practical lesson is that the tier — not the plastic — determines whether a credential is site-unique and clone-resistant.

Can a SIFER card or fob be cloned?

A custom-key SIFER card or fob (SIFER-U or SIFER-C) cannot be cloned by a third party, because reproducing it would require a site-specific 128-bit AES key that is never exposed. A shared-key SIFER-P credential uses the common Inner Range global key, so while it is still an encrypted smart card, it does not provide the site-unique protection that a custom key does.

For the highest assurance, SIFER offers a "Gold Card" option that generates a guaranteed-unique key that nobody — including Inner Range — can view. A site that combines custom-key credentials with the Gold Card approach reaches the strongest SIFER configuration, where no external party holds the key needed to reproduce a working card or fob.

How do SIFER cards fit a migration from prox?

Sites usually reach SIFER cards and fobs by migrating from 125 kHz proximity or Wiegand credentials. Because SIFER uses its own encrypted credential and key model, new SIFER cards and fobs must be issued to all users, and the Inner Range Integriti controller must meet the firmware and software minimums for SIFER support.

During the transition, a site commonly keeps its legacy 125 kHz proximity credentials working in parallel until every holder has a SIFER credential. Those legacy proximity formats — Inner Range's own low-frequency prox and the general prox a mixed site carries — are the layer a third party can supply while the SIFER rollout completes.

Can I buy compatible SIFER cards and fobs?

For the shared-key SIFER-P profile, yes — the IR56 56-bit format is fixed and a compatible SIFER-P card can be supplied for a site still running the factory global key. For custom-key SIFER-U and SIFER-C credentials, no third party can produce a working card or fob, because each is bound to a site-specific key held only by the installation; those come from Inner Range or your integrator.

The always-available option is the legacy 125 kHz proximity layer a site migrates away from, including Inner Range's own low-frequency prox formats. Those open low-frequency formats we encode as fully compatible credentials for use during the SIFER rollout.

Compatible SIFER-P and prox formats we supply

For sites on the shared-key SIFER-P profile, or still running 125 kHz proximity during a SIFER migration, these are formats we encode as fully compatible credentials.

Sources & references

Inner Range and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

Inner Range SIFER (IR56 credentials) — common questions

What is the IR56 format on a SIFER card?

IR56 is the 56-bit Inner Range credential identity used by SIFER, made of a 24-bit site code and a 32-bit card number. It identifies the installation and the individual holder, and the credential is protected with 128-bit AES from the card to the door module.

Are SIFER cards and fobs the same credential?

Yes. Inner Range issues SIFER as both plastic cards and key fobs, and both carry the same 56-bit IR56 identity and the same 128-bit AES protection. The form factor does not change the security; the key tier does.

Can a SIFER card or fob be cloned?

A custom-key SIFER-U or SIFER-C card or fob cannot be cloned, because reproducing it requires a site-specific 128-bit AES key that is never exposed. A shared-key SIFER-P credential uses the common Inner Range global key, so it lacks site-unique protection even though it is still encrypted.

What is a SIFER Gold Card?

The Gold Card option generates a guaranteed-unique encryption key that nobody, including Inner Range, can view. Combined with custom-key credentials, it produces the strongest SIFER configuration, where no external party holds the key needed to reproduce a working card or fob.

Can I buy compatible SIFER cards and fobs?

For the shared-key SIFER-P profile, yes, because the IR56 format is fixed. For custom-key SIFER-U and SIFER-C credentials, no third party can supply them, since each is bound to a site-specific key held only by the installation. The legacy 125 kHz prox layer can always be supplied during migration.