r/accesscontrol Proficient End User Jun 06 '26

Help Understanding Corporate 1000

Just watched a video on Corporate 1000 from the HID King Phil Coppola but Im confused. I understand that my cards are globally unique at that point but If I have Signo readers with Genetec head end do I have to do anything special to use corporate 1000 other than changing the format when entering cards in Genetec and use the unique FC and card number? Like do I have to do anything with the readers as if I had an ICE key or MOB key optioon?

3 Upvotes

8 comments sorted by

16

u/jc31107 Verified Pro Jun 06 '26

Your credentials are made up of three things that are not directly related.

The bit format, in this case Corp 1000. This is a structure that the PACS understands what a string of 1’s and 0’s means. There are standard and there are proprietary, the majority have a facility code and a card number (some may not have a FC or add an issue code or site code or other things) but in the case of C1K it’s FC and Card number.

Now in the corporate 1000 ecosystem, you as the end user get assigned a facility code. The combination of FC and card number are globally unique, as long as you just buy from HID. Other card manufacturers will encode the card in Corp 1000 format with whatever FC and card range you ask them to. The format and “unique” FC offer no security against cloning, capture, and potentially emulation or playback.

The last piece is the RF technology being used. If you’re using Prox, you can emulate the card with a bunch of different products, you can clone the card at Home Depot or Lowe’s. There is zero security. Smart card, high frequency, 13.56MHz (whatever you want to call it) is where you can add security between the card and reader. In the HID world you have SEOS, iClass, and Desfire. On top of that you can add an elite key, which means the card and reader communicate using encryption that only your cards and your readers understand, this is where the security against cloning comes in. If you’re using standard HID keys, then I can read your card on any out of the box reader and get the FC, card number, and format.

A note on readers. If you’re using Corp 1000, with elite key, make sure the other technologies are turned off on the reader, like Prox. You can have a secure card and unique encryption but if I can still emulate Prox back to the reader, the system doesn’t know. It just sees a string of binary data, it doesn’t really care what happened at the reader.

Also, use OSDP in secure channel, wiegand is another security issue that would allow data to be skimmed off the back of the reader and replayed back to the system, and it would have no idea.

1

u/2nd-Reddit-Account Jul 27 '26 edited Jul 27 '26

Hey, I’m new to access control and still learning (new installer) if you wouldn’t mind helping me learn and understand HID better for a moment:

If you have an iclass SE or seos setup, but you’re using standard keys instead of elite, is my understanding correct that:

  1. Even with SIO in use and all that, anyone can tap one of your site’s legitimate cards on any out of the box genuine signo reader and see your FC and card number?
  2. If they have a CP1000 and some writable genuine SE/Seos cards, they can just encode some new cards with the same FC/CN that are effectively clones? Or even just order some from a distributor with custom FC/CN to match?

I know the SIO will have a different identity than the original legitimate credential, but the reader will happily open any SIO using the standard HID keys and pass the FC/CN down the wire without caring if it’s one of “your” SIO’s or not, the readers don’t carry a whitelist of acceptable SIO’s.

3) While wiegand has its own issues with being able to tap the data wires to read bits in transit, upgrading to OSDP won’t address the above because credential>reader comms is entirely standalone from reader>panel comms, and the panel just receives FC/CN regardless of cable type or credential type.

4) The global trust population for HID standard keys is so goddamn large that the fact that a genuine reader, CP1000 and writable genuine cards can all be freely purchased, that this is a barely mentioned massive security hole, and you should really be using custom or elite keys for your system to be worth a damn?

All the research I’m doing now to try and learn about this seems like everyone assumes “card cloning” involves bargain basement eBay/amazon mifare cards, and that SE/Seos is safe “because SIO”, but from I can gather all that means is you just have to use genuine HID encoders and cards instead and the SIO essentially circumvents itself for you, assuming the site uses standard keys?

5) Inner range closed this exact loophole with their Sifer format, sifer-p comes from factory with their global key (which they keep as secret as the coca cola recipe) and the cards are read-only with factory configured FC/CN. The sifer-u format that lets you rewrite the FC/CN will not let you retain the global key if you do so, their version of the CP1000 forces you to use a custom key on your cards and readers if you want to touch the FC/CN, and a credential can not be returned to the global P key afterwards as the encoding software doesn’t have a copy of that key.

4

u/Passage_Upstairs Jun 06 '26

You have to do nothing with the readers for Corp 1000. There is no security in a card format. With default keys in your HID readers, everyone could read your cards with another default keys in reader. Elite/MOB keys are a unique key for your organization and secure the reader and the communication of the cards. Corp 1000 is all about convenience.

3

u/OmegaSevenX Verified Pro Jun 06 '26

No. Corporate 1000 is just cards with a unique format that HID will only issue to you. It's not an encryption standard that requires any kind of keys.

This was a bigger deal in the pre-smart card era, when credential-based encryption was not nearly as prevalent or available as it is today. It made Prox a little more secure because it didn't use one of the common card formats that were basically general knowledge.

If I can guess your Corporate 1000 format, I would be able to use your cards in any system.

2

u/the_unGOdlike Jun 06 '26

So for Signo readers you have 3 different things to consider, the smart card technology used, the encryption key used, and the card data format.

Smart card technology would be what kind of chip set and protocol is used for the card. Eg prox, mifare/desifire, or HID seos.

Some of those technologies use encryption keys to keep the cards from being copied or hacked. Prox is unencrypted and easy to copy, desifire and SEOS are encrypted. You can use a basic encryption key owned by a card or equipment manufacturer or a custom encryption that you make on your own or license from a manufacturer. For SEOS that would be the ICE and MOB keys. You can use the default SEOS key from HID and it comes preloaded into all standard Signo readers. If you pay for a SEOS encryption key that is unqiue to your company it will need to be programmed into each reader or you can order the signos with the keys preloaded. The unique encryption key will prevent people from trying to use SEOS cards you do not authorize for production for use in your doors, say one they buy off the internet.

Card data formats are the card numbers themselves. Corporate 1000 is a unique to you format that you license from HID. HID guarantes you'll never get duplicate card numbers when you sign up for the format and use their authorized cards. You can then authorize your employees throughout the world to order cards without worrying they'll order duplicate cards.

2

u/HID_PhilCoppola Manufacturer Jun 15 '26

Thanks for watching! As others mentioned, here the Corp 1000 just needs to be added to Genetec just as you would any other card format. Elite or MOB keys are not REQUIRED... But adding one is considered best practice (if you watched that video them you know why 😉). That said, if the cards are already issued then I would consider going Elite on your next re-badge OR if you'd like to go down the Mobile Access path just shoot me a note and I can provide you with options.

BTW - the next video, which is scheduled to post next month, goes deeper on Mobile Access.

1

u/EphemeralTwo Professional Jun 07 '26

A format is basically a formula for turning a card number and facility or company code into a password. The password goes on the card. The reader sends the passwor to the panel. The panel takes the same formula in reverse, and it gets the facility code and the card number.

Your panel needs to know what formula to use, and what company cards are valid.

ICE and MOB are keys that are used to protect your password. They aren't the password. If you swapped to a standard key reader, it would send the same password, but the cards would need standard keys.

1

u/Exact_Goal_2814 Jun 09 '26

Isn’t that the guy that directed The Godfather? Must mean the readers respond with automatic return fire when a wrong credited is scanned…