High-security 13.56 MHz credential

STid Architect & SECard Explained: Security, Keys & Credential Options

STid Architect is a modular 13.56 MHz and Bluetooth reader platform that reads an AES-secured contactless smart card over the SSCP® or OSDP secure protocol, with cryptography running on an EAL5+ certified secure processor. Its defining trait is key ownership: with the STid SECard kit the customer creates and holds their own encryption keys, so no third party can produce a working "compatible" Architect credential.

Last updated 2026-07-29

What are STid Architect and SECard?

STid Architect is STid Electronics' modular access-control reader line, and SECard is the desktop kit used to configure it and encode its credentials. An Architect reader operates at 13.56 MHz (ISO/IEC 14443 A and B, plus ISO/IEC 18092) and adds a Bluetooth channel for smartphone credentials, so one reader can serve cards, fobs, and phones.

The key idea that separates STid Architect from a plain proximity reader is that the credential is not a number broadcast in the clear. Architect reads an AES-secured contactless smart card whose identity is protected by mutual authentication and per-card diversified keys, and those keys are generated by the site owner using the STid SECard kit. That makes SECard the heart of the system: it is where a customer defines their private key architecture and writes it to both the readers and the cards.

What frequency and card technology does STid Architect use?

STid Architect uses the 13.56 MHz high-frequency band and reads an AES-secured contactless smart card across the EV1, EV2, and EV3 credential generations, alongside a Bluetooth channel for STid Mobile ID. STid's Architect Blue (ARCS) flyer lists support for ISO/IEC 14443 types A and B and ISO/IEC 18092, and the wider Architect range can also read legacy 125 kHz proximity, LEGIC, and iCLASS or similar cards by their card serial number (CSN) during a migration.

The security comes from the newer generations. STid describes the current AES-secured smart card as using "public algorithms and an EAL5+ certified crypto processor," with Secure Messaging that "protects against interleaving and replay attacks" and a Proximity Check that gives "protection against relay attacks." That is a fundamentally different model from a 125 kHz card, whose fixed number can be copied with a cheap cloner.

What is the SSCP protocol, and is it the same as OSDP?

SSCP® (Secure & Smart Communication Protocol) is STid's own encrypted, bidirectional reader-to-controller protocol, and it sits alongside — not instead of — the open OSDP standard. An Architect reader can be configured for Wiegand, Clock & Data, SSCP® v1/v2, or OSDP v1/v2 with Secure Channel, letting an installer keep legacy wiring or move to a fully encrypted link.

The reason this layer matters is that legacy Wiegand wiring is unencrypted and can be tapped to inject card numbers. Both SSCP® and OSDP Secure Channel replace that with an authenticated, AES-encrypted conversation between the reader and the door controller, so the protection that starts at the card is carried all the way back into the building. STid supports both so a site is never locked into a single controller vendor.

Who holds the encryption keys — STid or you?

With STid Architect, the customer holds the keys. STid markets this as "Create your own security keys — full independence over encryption," and it is the single most important fact about ordering STid credentials. Because the AES keys that bind a card to your readers are generated and stored by you in the SECard kit, STid itself cannot reproduce a working credential for your site, and neither can any card reseller.

STid packages this in tiers. The table below shows how key ownership changes across the Easyline, Expert, and Individual configurations — the move from STid's default keys to your own site-specific keys is what turns an Architect deployment from convenient into genuinely clone-resistant.

Configuration tierEncryption keysTool neededBest suited to
EasylineSTid default keysPre-configured, no kitFast rollout, lower-risk doors
ExpertYour own site-specific keysSTid SECard kitMost organisations wanting real security
IndividualFully bespoke key architectureSECard + STid engineeringGovernment / high-assurance sites

Can an STid Architect badge be cloned?

An STid Architect badge configured with your own keys cannot be cloned by copying a number the way a 125 kHz proximity card can. The credential is an AES-secured smart card, so its identity is protected by mutual authentication with per-card diversified keys; a copy would also have to reproduce a secret key it never has access to. STid adds Secure Messaging against replay and interleaving, a Proximity Check against relay attacks, and a patented motion sensor that erases the authentication keys from a reader if it is pulled off the wall.

For a mechanism-by-mechanism breakdown of how each of these defences maps to a specific attack, see the companion guide, STid Architect EV3 cards: key ownership and clone resistance. The short version: on STid Architect, clone-resistance depends far more on whether the site enabled its own keys than on the plastic itself.

Can I buy a compatible STid Architect card, and where do credentials come from?

No genuine "compatible" STid Architect card exists, because a working credential must carry your site's private AES keys, and those are held only in your SECard kit. Security ID Systems does not sell a drop-in STid card; the correct source for more encoded credentials is STid or the integrator that manages your keys. Blank STid stock — such as the STid 8870 2K smart card — can be ordered, but it still has to be encoded with your keys before it will open a door.

Where we can help is the other end of the same system. Many sites running STid Architect still have 125 kHz proximity readers on parking, lifts, or older doors, and some Architect readers are configured to read a card serial number (CSN) as a plain identifier. Those open and UID-based formats we do supply as fully compatible, encoded credentials.

Compatible formats we do supply

STid Architect credentials are keyed to your site and can only come from STid or your integrator. But where an Architect deployment still reads 125 kHz proximity or a plain card serial number on some doors, these open formats are ones we encode as fully compatible credentials.

Sources & references

STid Electronics and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

STid Architect — common questions

What card does STid Architect use?

STid Architect reads an AES-secured 13.56 MHz contactless smart card (EV1/EV2/EV3 generations) over ISO/IEC 14443, plus Bluetooth for STid Mobile ID. It can also read legacy 125 kHz, LEGIC, and iCLASS cards by their serial number during a migration.

What is the STid SECard kit for?

SECard is STid's desktop encoder and key-management kit. It is where a site creates its own AES encryption keys and writes them to both the Architect readers and the credentials. Without the matching keys in SECard, a card will not authenticate, which is why STid credentials cannot be sourced generically.

Is SSCP the same as OSDP?

No. SSCP® is STid's own encrypted reader-to-controller protocol, while OSDP is the open industry standard. STid Architect readers support both, plus legacy Wiegand and Clock & Data, so a site can move to an AES-encrypted, authenticated reader link without changing controller vendor.

Can an STid Architect card be cloned?

Not when it is configured with your own keys. The credential is an AES-secured smart card protected by mutual authentication and per-card diversified keys, with Secure Messaging against replay, a Proximity Check against relay attacks, and a reader motion sensor that wipes keys if a reader is removed.

Who owns the encryption keys on an STid system?

You do. STid describes this as "create your own security keys — full independence over encryption." The keys are generated and stored in your SECard kit, so neither STid nor any reseller can reproduce a working credential for your site.