What is an STid Architect EV3 credential?
An STid Architect EV3 credential is the current generation of AES-secured 13.56 MHz smart card, read by an STid Architect reader and encoded through the STid SECard kit. STid supports the EV1, EV2, and EV3 generations of this smart-card family; EV3 is the newest, carrying Common Criteria EAL5+ certification on its secure processor.
The important distinction is that STid Architect EV3 is not a Genetec-style or HID-style closed product — the plastic is a standards-based AES smart card, and what makes your specific card yours is the private key set you write to it. STid describes the model as using "public algorithms and an EAL5+ certified crypto processor," a deliberate choice of open, peer-reviewed cryptography over secret in-house ciphers. That is why an STid EV3 badge is only as strong as the key policy the site actually enabled.
Can an STid Architect EV3 badge be cloned or copied?
No — an STid Architect EV3 badge encoded with your own keys cannot be cloned by reading and copying it. The credential authenticates with AES and per-card diversified keys, so the secret never crosses the air gap, and STid layers additional named defences on top. The table below maps each common attack against an access badge to the specific STid Architect protection that blocks it.
| Attack on a badge | How it works | STid Architect EV3 defence |
|---|---|---|
| Cloning / copying | Read a card and write its data to a blank | AES mutual authentication with per-card diversified keys — the secret key is never transmitted |
| Replay / interleaving | Capture a valid exchange and replay it | Secure Messaging (EV2 generation) rejects replayed or interleaved messages |
| Relay attack | Extend the radio link so a distant badge seems present | Proximity Check measures response timing to defeat relay |
| Reader tampering | Pull a reader off the wall to reach its keys | Patented motion sensor wipes the authentication keys from the reader |
| Line tapping | Splice reader-to-controller wiring to inject IDs | SSCP® or OSDP Secure Channel encrypts and authenticates the link |
Why does STid let you own your encryption keys?
STid lets the customer own the encryption keys because in a keyed AES system, key custody is the real security boundary — not the chip. STid states the goal plainly: "create your own security keys — full independence over encryption." With the SECard kit, a site generates its own AES keys and writes them into both its Architect readers and its EV3 credentials, so the working secret exists only inside that organisation.
This is a meaningful contrast with older shared-key systems, where a single master key held by the manufacturer or embedded in every reader meant that compromising one device could threaten a whole population of cards. Because an STid Architect EV3 deployment can run fully site-specific keys, there is no shared secret for an attacker to recover once, and no way for STid or a reseller to mint a working duplicate of your badge.
STid Architect EV1 vs EV2 vs EV3 — what changed?
STid Architect can read three generations of the AES-secured 13.56 MHz smart card, and each generation added security rather than replacing the last. All three use AES-128 mutual authentication with per-card diversified keys; the later generations hardened the card against relay and man-in-the-middle attacks and raised the certification level.
| Smart-card generation | Key security addition | Certification |
|---|---|---|
| EV1 | AES-128 mutual authentication, per-card diversified keys | Common Criteria EAL4+ |
| EV2 | Adds Secure Messaging and Proximity Check (anti-relay) | — |
| EV3 | Adds transaction-timer / message-authentication hardening | Common Criteria EAL5+ |
Where do STid Architect EV3 credentials come from?
STid Architect EV3 credentials come from STid or the integrator that holds your keys — never from a generic "compatible card" supplier, because a duplicate would need the private AES keys stored in your SECard kit. Security ID Systems does not offer a drop-in STid EV3 card. For the wider view of the reader platform and the SECard workflow, see the canonical guide, STid Architect & SECard explained.
What we can supply is the migration and fallback layer. STid Architect readers frequently still read 125 kHz proximity on legacy doors, or are set to read a card serial number (CSN) as a plain identifier. Those open and UID-based formats we encode as fully compatible credentials, so a site can standardise its older readers while the EV3 credentials stay under its own key control.
Compatible formats we do supply
The keyed EV3 credential itself must come from STid or your integrator. Where an STid Architect reader still reads legacy proximity or a card serial number, these open formats are ones we encode as fully compatible credentials.
Sources & references
STid Electronics and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.