# Electromechanical Door Locks

Hi,

I'm wondering what the point of electromechanical door locks is. But first, the disclaimer:

Don't get me wrong. I'm a big fan of electronics. In fact, it's one of the few areas of engineering that excites me. I'm not that crazy about mechanics or mechanical systems. That's my personal bias, because my background is in electrical engineering (and physics), and I tend to gravitate towards high tech stuff and am interested in emerging technologies and the closing gap between fundamental science and the applications that stem from it.

That having been said, really, what is the point of elaborate powered door locking mechanisms (aside from in vehicles where they're quite handy)? Some of the newer "FOB" type systems seem pretty reliable. But magnetic stripe card reader door locks? Please. Give me a break. I'm living in a building with these hotel style locks on the doors right now. They're SO flaky! It seems like unless you stick the card in the reader in exactly the right way, at exactly the right speed, you get an error. What advantage does this offer? Is it JUST better security? Because it seems to me that, by comparison, a simple mechanical locking system can't fail nearly as often.

For hotels it allows you to change the locks after each guest, so a lost or copied key has no value.
For an apartment block frontdoor it has an advantage that you can restrict access to current tenants instead of all previous tenants - their ex-boyfriends, their mothers, babysitters and every ex-cleaner or janitor.

We has a similair problem, our labs were protected by high security mechanical locks cost something like $500 each and had to be replaced every year in case an ex-student had a copy of a key. My suggestion was to just put all the old lock barrels with their known keys attached in a bucket - shake them up and reinstall them at random. Since nobody would know which new lock their old key fitted it would be secure.

Magnetic swipe systems are pretty reliable. The problem with the hotel doors is because the cards are reused over and over again and the systems themselves are cheap. In comparison, how long does it take your ATM card to stop reading correctly? The best part about swipe systems is that you can lock out any one person's card without changing everyone's cards. The bad part is that just like metal keys they can be easily coppied with the right equipment.

No lock will ever be 100% reliable. If it can be opened with a key it can also be opened without the key.

not sure which i'd rather have, magnetic strip or RFID. the problem with RFID is that it broadcasts, so you could observe it from a distance. but the tech is not ubiquitous yet, so it'd take sophisticated criminals to break it. unless there's something i'm missing about how RFID works, i don't think moving to a more obscure technology makes me any more secure.

magnetic strips are ubiquitous and cheap to duplicate, but you need physical access to the card. maybe difficult with normal hotel door locks, but in general, trojan swipe readers are pretty common.

Depends on how secure the lock is !
Some RFID just send an ID number, most of them are very short range - ironically the cheaper/smaller they are the less sensitive the antennae and the shorter the range = more secure!
Key fobs for expensive cars and high security login keys for computers have a challenge-response system. The lock sends an encrypted message, the key manipulates that mathemetically and sends back a response, if that matches the same manipulation process in the lock it opens - a new message is generated each time and each response is different so recording them off the air isn't enough.

RFID with a smart chip or a card with a smart chip are both great options because of the challenge/response involved, but they are expensive. I read a story, although it may just be an urban legend, about a guy that drove his new BMW to starbucks and sat reading the paper next to a kid with a laptop. After about 30 minutes the kid with the laptop got up and drove the BMW away. With any challenge/response system this is possible although the complexity of the system dictates the amount of time required to get a large enough pool of responses to trick it. Still better than a single code on a card or RFID.

In the end it's like the joke about the two guys being chased by the bear. You may not be able to create a perfectly secure system, but you can make the criminals go down the street to the system that is easer to crack.

Interesting info on lock bumping. I hadn't seen that before. I think stock in the MEDECO company just went up!

