TRANSIT Ultimate | installation guide
5/40
1.2
Ultimate features
Encrypted tag authentication
The TRANSIT Ultimate enables encrypted tag authentication for the Ultimate tags: Smartcard Booster Ultimate, LEGIC
Booster Ultimate and Window Tag Ultimate. The authentication uses encryption based upon AES 128-bit keys. Key
diversification is used to ensure that a unique encryption key is used for every tag.
Implementation
The Ultimate-mode features are implemented in the TAB board. The TAB-board performs the authentication or other
Ultimate function using the bi-directional tag communication channel at 433MHz.
Figure 1: TRANSIT Ultimate block diagram
Authentication procedure
The encrypted tag authentication is performed when both antennas (433MHz and 2.45GHz) receive the same id-
number. This ensures that the tag to be authenticated is located in the well-defined directional beam in front of the
reader.
1.
Receive Ultimate tag id-number.
2.
Send encrypted challenge to the tag.
The challenge is generated by the Security Key Pack based upon random numbers encrypted with a diversified
AES128 key.
3.
Receive, decrypt and verify the encrypted challenge response from the tag.
4.
When the authentication is successful, the id-number is transmitted on the communication output(s).
The TAB board may be bypassed to make the TRANSIT Ultimate backwards compatible with the TRANSIT Standard.
See chapter 6.1.
TRANSIT - PIC
2.45GHz
433MHz
Ultimate
mode
bypass
Serial com-select
USB-detect
USB
I/F-board
Wiegand
Relay output
Smiley RGB
TAB-board
Security Key Pack
TRANSIT Ultimate