What credential does a Yale nexTouch commercial lock use?
Yale nexTouch is a commercial keypad and credential lock whose line has been rebranded ASSA ABLOY Accentra (formerly Yale Commercial). On the high-security credential side, Accentra uses HID Seos — a 13.56 MHz credential that stores identity data inside a Secure Identity Object (SIO), an encrypted, digitally signed data container, protected by AES-128. HID is an ASSA ABLOY company, so Seos is the natural high-assurance credential across the Accentra platform.
Yale nexTouch also integrates with third-party access-control panels, in which case the reader format follows the host system — often 125 kHz proximity or another 13.56 MHz smart card. For a nexTouch running on the Accentra platform with HID readers, however, HID Seos is the credential that matters, and it is a fundamentally different security model from a legacy prox card.
How secure is HID Seos on a Yale / Accentra lock?
HID Seos is a high-security credential, and it is what gives a Yale/Accentra commercial lock its clone resistance. The HID Seos datasheet states that data within the SIO is secured with "key diversification, authentication signatures, and AES-128 based encryption," using a "mutual authentication protocol with generation of diversified session key" and "secure messaging," and that the card "always defaults to using a random contactless unique identifier."
In plain terms: the card and reader each prove their identity before any data moves, every card has its own diversified key, and the serial number is randomised so the card cannot be tracked or copied by its number. That is why a Seos-based Accentra credential belongs in a different class from the 125 kHz proximity cards it is meant to replace.
Can a Yale / Seos commercial card be cloned?
No. A HID Seos credential on a Yale/Accentra lock cannot be cloned by copying its serial number the way a 125 kHz proximity card can, and there is no publicly documented cryptographic break of Seos. The AES-128 mutual authentication means a cloned card would have to reproduce a secret key it never has access to.
This is a deliberate contrast with HID's own earlier 13.56 MHz technology. The proprietary cipher used by legacy iCLASS was reverse-engineered and published by academic researchers in 2012, who reported recovering the iCLASS Elite master key in roughly fifteen authentication attempts. Seos was designed as the standards-based AES replacement for that generation, and no equivalent break has been published against it — which is why it anchors the high-security tier on Accentra.
How do I migrate a Yale / commercial site from prox to Seos?
Migrating a Yale/Accentra commercial site from 125 kHz proximity to Seos is a gradual process, using multi-technology readers and combo cards. HID's Signo and iCLASS SE readers can read both legacy 125 kHz prox and 13.56 MHz Seos, and HID offers a "Seos Essential + Prox" card that carries a Seos credential and a 125 kHz prox number on one card. That lets a site issue one credential that works on both old and new readers during the cutover.
The typical path runs: legacy 125 kHz prox → install HID Signo / iCLASS SE readers → issue Seos Essential + Prox combo cards → retire the prox side once all doors read Seos. Because the readers accept both technologies, no one is locked out mid-transition, and the site ends on an AES-128 Seos credential that also works as a phone-based mobile credential.
Yale / Accentra credential options compared
The table compares the credential tiers a Yale/Accentra commercial lock can run, from legacy prox to Seos.
| Credential | Band | Security | Third-party card? |
|---|---|---|---|
| 125 kHz proximity | 125 kHz LF | Fixed number, no encryption | Yes — openly supplied |
| Seos Essential + Prox | Dual (125 kHz + 13.56 MHz) | Prox side open, Seos side AES-128 | Prox side only |
| HID Seos | 13.56 MHz HF | AES-128 mutual auth, diversified keys | No — HID channel only |
Can I buy a compatible Yale / Seos card?
No — and that is by design. A HID Seos credential is cryptographically bound with keys held by HID and your credential-management system, so there is no legitimate way for an independent manufacturer to produce a "compatible" Seos card, and Security ID Systems does not offer one. If your Yale/Accentra doors run Seos, additional credentials should be sourced through HID or the integrator that manages your site's keys.
Where we can help is the migration layer. Many commercial sites running Seos still have doors, gates, or legacy readers on 125 kHz proximity during the transition — and those open prox formats we supply as fully compatible, encoded credentials, including the prox side of a dual-technology deployment.
Open formats we do supply
We can't supply a keyed HID Seos card, but if your Yale/Accentra site still runs 125 kHz proximity anywhere during a Seos migration, these open formats are ones we encode as fully compatible credentials.
Sources & references
Yale and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.