High-security 13.56 MHz credential

STid Architect EV3 Cards: Key Ownership & Clone Resistance

An STid Architect EV3 credential is an AES-secured 13.56 MHz smart card, in its most current generation, that the site owner encodes with their own keys. Its clone-resistance comes from three things working together: per-card AES mutual authentication, the EV2/EV3 defences against replay and relay attacks, and the fact that the encryption keys live in your SECard kit — not with STid and not with any card reseller.

Last updated 2026-07-29

What is an STid Architect EV3 credential?

An STid Architect EV3 credential is the current generation of AES-secured 13.56 MHz smart card, read by an STid Architect reader and encoded through the STid SECard kit. STid supports the EV1, EV2, and EV3 generations of this smart-card family; EV3 is the newest, carrying Common Criteria EAL5+ certification on its secure processor.

The important distinction is that STid Architect EV3 is not a Genetec-style or HID-style closed product — the plastic is a standards-based AES smart card, and what makes your specific card yours is the private key set you write to it. STid describes the model as using "public algorithms and an EAL5+ certified crypto processor," a deliberate choice of open, peer-reviewed cryptography over secret in-house ciphers. That is why an STid EV3 badge is only as strong as the key policy the site actually enabled.

Can an STid Architect EV3 badge be cloned or copied?

No — an STid Architect EV3 badge encoded with your own keys cannot be cloned by reading and copying it. The credential authenticates with AES and per-card diversified keys, so the secret never crosses the air gap, and STid layers additional named defences on top. The table below maps each common attack against an access badge to the specific STid Architect protection that blocks it.

Attack on a badgeHow it worksSTid Architect EV3 defence
Cloning / copyingRead a card and write its data to a blankAES mutual authentication with per-card diversified keys — the secret key is never transmitted
Replay / interleavingCapture a valid exchange and replay itSecure Messaging (EV2 generation) rejects replayed or interleaved messages
Relay attackExtend the radio link so a distant badge seems presentProximity Check measures response timing to defeat relay
Reader tamperingPull a reader off the wall to reach its keysPatented motion sensor wipes the authentication keys from the reader
Line tappingSplice reader-to-controller wiring to inject IDsSSCP® or OSDP Secure Channel encrypts and authenticates the link

Why does STid let you own your encryption keys?

STid lets the customer own the encryption keys because in a keyed AES system, key custody is the real security boundary — not the chip. STid states the goal plainly: "create your own security keys — full independence over encryption." With the SECard kit, a site generates its own AES keys and writes them into both its Architect readers and its EV3 credentials, so the working secret exists only inside that organisation.

This is a meaningful contrast with older shared-key systems, where a single master key held by the manufacturer or embedded in every reader meant that compromising one device could threaten a whole population of cards. Because an STid Architect EV3 deployment can run fully site-specific keys, there is no shared secret for an attacker to recover once, and no way for STid or a reseller to mint a working duplicate of your badge.

STid Architect EV1 vs EV2 vs EV3 — what changed?

STid Architect can read three generations of the AES-secured 13.56 MHz smart card, and each generation added security rather than replacing the last. All three use AES-128 mutual authentication with per-card diversified keys; the later generations hardened the card against relay and man-in-the-middle attacks and raised the certification level.

Smart-card generationKey security additionCertification
EV1AES-128 mutual authentication, per-card diversified keysCommon Criteria EAL4+
EV2Adds Secure Messaging and Proximity Check (anti-relay)
EV3Adds transaction-timer / message-authentication hardeningCommon Criteria EAL5+

Where do STid Architect EV3 credentials come from?

STid Architect EV3 credentials come from STid or the integrator that holds your keys — never from a generic "compatible card" supplier, because a duplicate would need the private AES keys stored in your SECard kit. Security ID Systems does not offer a drop-in STid EV3 card. For the wider view of the reader platform and the SECard workflow, see the canonical guide, STid Architect & SECard explained.

What we can supply is the migration and fallback layer. STid Architect readers frequently still read 125 kHz proximity on legacy doors, or are set to read a card serial number (CSN) as a plain identifier. Those open and UID-based formats we encode as fully compatible credentials, so a site can standardise its older readers while the EV3 credentials stay under its own key control.

Compatible formats we do supply

The keyed EV3 credential itself must come from STid or your integrator. Where an STid Architect reader still reads legacy proximity or a card serial number, these open formats are ones we encode as fully compatible credentials.

Sources & references

STid Electronics and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

STid Architect EV3 — common questions

Can an STid Architect EV3 card be cloned?

No, when it is encoded with your own keys. The EV3 credential uses AES mutual authentication with per-card diversified keys, adds Secure Messaging against replay and a Proximity Check against relay attacks, and the reader wipes its keys if it is tampered with. A copy would need a secret key it can never read.

What is the difference between STid EV1, EV2 and EV3 cards?

All three are AES-secured 13.56 MHz smart cards with per-card diversified keys. EV2 added Secure Messaging and a Proximity Check to defeat replay and relay attacks; EV3 added further man-in-the-middle hardening and carries Common Criteria EAL5+ certification, versus EAL4+ for EV1.

Who controls the keys on an STid Architect EV3 system?

The customer does. Using the STid SECard kit, the site generates its own AES keys and writes them to its readers and cards. The working secret never leaves the organisation, so STid and card resellers cannot reproduce a valid credential.

Is an STid Architect EV3 card the same as an iCLASS or Seos card?

No. STid Architect EV3 is a standards-based AES-secured 13.56 MHz smart card that you key yourself through SECard, whereas HID iCLASS and Seos are HID's own credential platforms keyed through HID. Architect readers can read iCLASS by serial number during a migration, but the credentials are distinct.

Can I get a compatible STid Architect EV3 card from a third party?

No. A working EV3 credential must carry your site's private AES keys, which exist only in your SECard kit, so no third party can supply a drop-in card. Additional EV3 credentials should come from STid or your integrator.