Episode 28 ~1:50 Low Current & ELV EN · العربية

Access Control, why OSDP is killing Wiegand

Wiegand was open, unencrypted, one-way, point-to-point, and limited to a 26-bit string. It was also good enough, until cloning, sniffing, and integration with badging databases became routine. OSDP fixes the security and the topology in one move.

Animated explainer, press play to watch the concepts now; the filmed cut publishes once production wraps.

What you'll walk away with

Four ideas to carry into the next specification conversation you have.

01

Wiegand is plaintext, one-way, ~150 m.

26 bits over two data wires (D0/D1), no encryption, no acknowledge. Easily cloned and replayed.

02

OSDP is encrypted, bidirectional, multi-drop.

RS-485, up to 1.2 km, AES-128 secure channel (OSDP-SC), up to 8 readers per loop, full feedback to controller.

03

OSDP supports biometric and mobile credentials.

Variable payload size, handles fingerprint templates, facial vectors, mobile NFC/BLE IDs natively.

04

Spec OSDP v2.2 with Secure Channel.

Older OSDP (v1.x, v2.0 without SC) is downgrade-attackable. New installs must spec v2.2 with SC mandatory.

Wiegand vs OSDP × where each fails or wins

SIA AC-01 (Wiegand) vs SIA OSDP v2.2 (Open Supervised Device Protocol).

Attribute Wiegand · OSDP Notes
Cable distance150 m · 1,200 mOSDP uses RS-485
Wires required5 (V, GND, D0, D1, LED)OSDP: 4 (V, GND, +A, -B)
DirectionOne-way · BidirectionalOSDP confirms reader state
EncryptionNone · AES-128 (SC)OSDP-SC mandatory in v2.2
Multi-drop1 reader per port · 8 readers per portOSDP saves controller ports
Card data size26 bits typical · variableOSDP supports 200-bit credentials
Biometric supportNo · Yes (native)Critical for KSA government / banking
Mobile credentialHack-via-emulation · Native NFC/BLEOSDP-2.2 packets

What OSDP changes operationally

Five reasons new builds in Saudi increasingly mandate OSDP.

Wiegand cloning is a real attack, not theoretical.

Tools like the Proxmark3 clone 125 kHz HID Prox cards in seconds. ESPKey and similar devices sit in the cable between reader and controller, recording card data in real-time and replaying it to unlock the door. OSDP-SC's AES-128 makes both attacks impractical.

Audit trail granularity improves.

Wiegand's one-way wire means the controller never knows if the reader heard a request, lost power, was tampered, or was even there. OSDP polls each reader continuously, door alarms, tamper alerts, and offline events all log to the access management system.

Fewer cable runs per controller.

A 100-door office in Wiegand needs 100 home-runs to the access controller. The same office in OSDP can use multi-drop loops of 8 readers, 13 cable runs cover 100 doors. Saves conduit, panel space, and termination labour.

Saudi government tenders now spec OSDP.

MOH, MOE, MOI, NEOM, Aramco all spec OSDP v2.2 with Secure Channel on new builds. The trigger was a regional banking incident in 2022 where Wiegand sniffing exposed 12,000 employee badges. Migration projects are in flight across major sectors.

Bluetooth and mobile credentials need OSDP.

HID Mobile Access, Stid, Smart-i, modern mobile credentials use NFC or BLE to transmit larger, encrypted credential payloads. Wiegand's 26-bit limit cannot carry them. The move to phone-based access is the practical forcing function for OSDP migration.

Next Episode

Public Address & STI / STIPA

Watch next

Get the next episode by email

Practical lighting know-how from NLC Academy. No spam, unsubscribe anytime.

By subscribing you agree to receive NLC emails.