What is a Salto credential and how does SVN work?
A Salto credential is a 13.56 MHz contactless smart card that carries a user's access rights on the card itself, using SALTO's SVN (SALTO Virtual Network) data-on-card model. Salto describes SVN as a system where stand-alone smart locks "read, receive and write information via users' key cards," so battery-powered offline doors stay current without being wired to a network.
In practice this means a Salto card is not just an ID number the way a proximity card is. When a user presents a Salto card at an online wall reader, updated permissions and blacklist data are written back onto the card, then carried to every offline lock the user touches. That write-back audit-and-revoke mechanism is the defining feature of a SALTO Space deployment and the reason the card technology matters more than on a simple read-only system.
What frequency and card technology does Salto use?
Salto operates at 13.56 MHz over the ISO/IEC 14443-A air interface. The current secure credential is an AES-secured 13.56 MHz smart card carrying SVN data inside encrypted sectors, protected by AES-128 mutual authentication with per-card diversified keys. Older Salto sites may still run a non-secure 13.56 MHz smart card, which stores SVN data without strong per-sector cryptography and is the technology Salto now advises migrating away from.
The identifier of a modern Salto card is not broadcast in the clear. Because the card and reader each prove possession of a diversified key before any data moves, a Salto AES-secured smart card cannot be read or rewritten by an unauthorized encoder, which is what separates it from the legacy generation.
Can a Salto card be cloned or copied?
An AES-secured Salto smart card cannot be cloned by copying its serial number, because access data is protected by an AES-128 mutual-authentication exchange rather than exposed on the surface of the card. A cloned card would need a secret key it never has access to. A legacy, non-secure Salto smart card is a different story: the older 13.56 MHz smart card generation was comprehensively reverse-engineered and cloned by academic researchers in 2008, and inexpensive tools now exist to copy it.
This is exactly the gap SALTO addresses in its own security guidance. If a Salto system still issues legacy non-secure cards, the credential — not the lock — is the weak point, and moving to the AES-secured card closes it.
What does SALTO's 2024 security advisory recommend?
SALTO published an RFID Credentials Security Advisory (Document ID SAL_2024_001, dated 6 March 2024) that proactively encourages its clients and partners to transition from non-secure legacy 13.56 MHz credentials to a more secure, AES-secured smart card. The advisory notes that widely available cloning tools "significantly lower the barrier to cloning non-secure credentials," cites that researchers from Radboud University of Nijmegen and University College London "successfully compromised the security" of the legacy credential, and — "in alignment with the chip vendor's recommendations" — advises upgrading both the credential and the lock firmware.
The takeaway for an owner is direct: SALTO itself is telling operators to move off the old card. Reissuing users onto an AES-secured smart card, and applying the firmware update SALTO references, is the manufacturer's own recommended path.
SALTO Space vs SALTO KS — what's the difference?
SALTO Space and SALTO KS are two ways to run the same lock hardware. SALTO Space is the on-premise, data-on-card platform built around SVN, where permissions travel on the card and update at wall readers. SALTO KS (Keys as a Service) is SALTO's cloud platform — Access Control as a Service — where doors are managed online and mobile keys can be issued or revoked in real time from anywhere.
| Aspect | SALTO Space (SVN) | SALTO KS (cloud) |
|---|---|---|
| Management | On-premise software | Cloud / ACaaS |
| How rights update | Written to the card at wall readers | Over the network / mobile |
| Credential | AES-secured 13.56 MHz smart card | Card or mobile key (BLE) |
| Best fit | Large offline door counts | Distributed / remotely managed sites |
Can I buy a compatible Salto card, and which formats can I source?
A working Salto credential is encoded with your system's own SVN keys, so a genuinely "compatible" Salto AES-secured smart card is not something an independent supplier can produce — the keys are held by SALTO Space or SALTO KS and your integrator, and Security ID Systems does not offer one. Additional encoded Salto credentials should come from Salto or the integrator that manages your site's keys.
Where we can help is the surrounding hardware layer. Sites running Salto often keep blank or open-format cards on hand for enrollment stock, for legacy hotel doors, or for adjacent readers that use open serial-number formats. Those are credentials we supply and encode.
Open formats we do supply
We don't sell a keyed Salto SVN credential, but these are the open and hotel-card formats we stock and encode — useful for enrollment stock, legacy doors, and serial-number readers alongside a Salto deployment.
Sources & references
SALTO Systems and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.