The spread of DESFire technology: hype or inevitability? by Jari Valtonen, CEO, Idesco Oy, based in Oulu, Finland.
Over the past 18 months there has been a quiet shift by numerous large and medium-sized European access control providers (and consumers) toward integrating Mifareโs robust technology, DESFire, into their wireless offerings (or systems). Inasmuch this trend is likely due to a number of factors, itโs also prudent to consider which attributes of DESFire might be driving it. More important, though (if this is indeed a trend) is understanding what its implications could be for the evolution of access control as a whole. A riveting example of this has been an increase in interest in encrypting data transmitted across reader-controller networks โ not merely reader transactions with cards or fobs. With the appearance of this new feature in access control technology an important question invites consideration: are proprietary or โclosedโ technologies as well-positioned to adapt to this โdual-encryptionโ evolution as open technologies like Mifareโs DESFire?
In all fairness, answering this question without some speculation is nigh impossible. Simultaneously, however, there exists an analogy close enough to wireless access control to give us pause in our speculation: the steady global migration, across a variety of business sectors, away from PC/Server deployments of proprietary software (eg Microsoft, Sun) toward open source ones, using Linux and Unix. Initially, this appears like a false analogy. The security challenges Microsoft, for example, consistently struggles with should never be taken to represent comparable โvulnerabilitiesโ per se in closed solution access control manufacturers. However, in considerations of configurability and capacity for adapting to the full spectrum of aggregated user demands, this analogy becomes relevant. This is partly due to the significant resources closed solution manufacturers are forced to devote to ensuring their technology remains โclosedโ, inviolate to other product manufacturers. It is also partly a factor of complexity: what percentage of a manufacturerโs closed technology is devoted to walling off their customers from competitors versus the percentage devoted to serving them. After all, when any technology becomes too complex it grows unwieldy and less unattractive to potential new customers.
Will proprietary or closed solution access control manufacturers be able to adapt their technology in the future to the novel rigours of dually-encrypted access control systems at the same pace, efficacy, configurability – as well as security – as open technology manufacturers? Time will tell. In the meantime, a brief review of the current features of Mifareโs DESFire in an access control setting provides more than just food for thought. For, in addition to supporting the pinnacle in reader-card encryption, 128 bit AES (as well as 3DES) and an unmatched plethora of configurability options for enhancing security, both user and administrative convenience, DESFire, a 13,56 MHz technology, possesses the capacity to store (and encrypt) biometric data on a card, thereby protecting and satisfying usersโ privacy and confidentiality concerns while simultaneously meeting the security demands of even the most sensitive sites. The latter is achieved in no small part due to its remarkably high data transfer rate. Even in environments requiring much less robust security protocols, DESFire continues outperforming proprietary technologies solely on its capability for reliably hosting multi-applications. A userโs card might function not merely as an โelectronic keyโ but also store privileges for the company cafeteria, rider privileges for a metropolitan transit system or trigger discounts at a chain of car washes.
That same card might also encode both standard access to the employeeโs work site as well as special, limited (timeframe, date-duration or maximum visits) access privileges to other, higher security sites across a companyโs entire domain โ all readily tracked, monitored or administered from a single central location. Keys for accessing particularly sensitive sites might even be generated by a customerโs own application installed in the card. In short, the options in Mifareโs DESFire for customised configurations are, to put it mildly, expansive; whether for purposes of security or user and administrative convenience.
Almost certainly, DESFire will continue growing in prevalence as a global standard in access control but now itโs also crucial to understand the reasons are almost certainly multifaceted. This growth is not merely a function of the emergence of multi-application cards, nor of continued interest in at least ensuring if not indeed enhancing (or even replacing) the security of existing protocols. Nor is it even the consequence of an abiding interest in enhancing the efficiency and effectiveness of oneโs deployed security resources. Finally, it is almost certainly not solely a diffuse reaction by customers out of increased ambivalence toward closed or proprietary solutions per se.
Rather, it seems more likely that this growth in the prevalence of offered DESFire solutions is a reaction to these factors in aggregate. Some customers or companies will invariably find some factors – or combinations of factors – more compelling than others. Recalling our earlier analogy, even today there remain Sun and Microsoft customers aplenty, sufficient to tempt some to scoff at any notion of a โtrend away from proprietary technologiesโ. However, technology business as an ecosystem has already shown its high tolerance for long-established niches, as proprietary technology should be categorised. Open-source and open solutions constitute a new paradigm, not merely a new niche. Most notably, access control has not even begun wrestling with the efficacy of IP-networking of wireless access control, replete with the controversy and misperception such an evolution may well yet engender. In short, technology not only responds to the demands of consumers, mediated by the competition of manufacturers. It is also responsive to itself, shaping its landscape, similar to the way a river re-cuts its course during a flood. There is yet much more change on the horizon for all entities in the wireless access control industry-as-ecosystem to survive, evolve against and perhaps thrive amidst. Time will tell. Time will certainly tell.




