Skip to content

Future-proofing your site security with mobile credentials

Mobile credentials are increasing in demand as more businesses think about how they can future-proof their security investment. As smartphones reach mass adoption and technologies such as Bluetooth® and NFC (near field communication) improve, this trend will only continue.

The basics of mobile credentials

Mobile credentials live on your smartphone but work in the same way as the card or fob you’d use to gain entry into a building. They use NFC or Bluetooth technology.

Mobile credentials work with all TSL readers, all Protege wireless locks and tSec readers with -BT in the product code. They can’t be used with third-party readers.

NFC vs Bluetooth®

For ICT’s mobile credentials, NFC is available for Android phones and Bluetooth is available with Android and iOS devices.

Both NFC and Bluetooth use radio frequency technology to communicate between the credential and the reader. The main difference is that NFC has a much shorter read range than Bluetooth. NFC has a range of a few centimetres, while Bluetooth’s range is longer and can be adjusted in the app’s settings.

Two phone screens showing the ICT mobile credential app, with proximity unlock, shake-to-unlock, NFC unlock and Bluetooth proximity settings

Issuing, managing and revoking credentials: How does it work?

Credentials are issued through the Mobile Credential Portal. When you assign a mobile credential to a user, the credential will be sent to the user’s email address.

Once the user accepts (or “consumes”) the credential, they will be sent to Protege Access+, which is where they access the credential from then on. Once a credential has been consumed, it can’t be issued to a new person or reused.

Revoking mobile credentials is easily managed through Protege WX or GX. All user credentials are stored in the user profile alongside other ICT credentials. Simply click revoke and the credential will no longer be valid. Revoking a credential is like cutting up an access card: it can no longer be used. However, they can be temporarily disabled if required. So, if someone loses their phone or gets a new one, you can temporarily disable the mobile credential, remove the old device from their profile and add the new one.

Cards vs mobile credentials

A hand tapping a physical ICT access card against a wall-mounted reader
A person tapping a smartphone against an ICT reader to unlock a glass door

Mobile credentials have several advantages over physical access cards. Let’s explore the differences now:

Cost

According to a 2021 report by IPVM, the recurring cost of mobile credentials is cited as one of the biggest barriers for access control installers and integrators getting people on board. Ongoing fees can ultimately end up costing far more than just using standard cards and fobs.

There’s no subscription fee. A mobile credential is a one-time purchase that often costs less than other high-frequency credential options.

Security

Security is the first question most organisations ask about mobile credentials. Here’s how mobile credentials answer it:

Bluetooth® and NFC security

The short read range of NFC makes it quite secure. To establish a connection, the smartphone must be within a few centimetres of the reader. With Bluetooth, the unlock distance is adjustable in the app’s settings, so you can tune how close you need to be. The workable range varies with reader configuration, location and other factors.

Access to the credential is authenticated using a secure cloud-based server and one of the most secure encryption methods available: AES-256.

AES-256 (Advanced Encryption Standard) is the same encryption standard used by governments and financial institutions worldwide. A 256-bit key has approximately 1.1 × 10⁷⁷ possible combinations, and brute-forcing it is considered computationally infeasible with any current or foreseeable technology. This protects mobile credentials against the cloning and interception risks that affect many legacy card technologies.

Risk of loss

One of the greatest security risks with access cards is that they’re easily lost.

Lost cards are so common that people routinely post about them on social media, a small reminder of how easily a physical credential can end up in the wrong hands.

If these losses go unnoticed or unreported, it doesn’t matter how smart the card is, it can still be used to gain access if it were to fall into the wrong hands. If you have a company logo on the card/lanyard, whoever finds it knows exactly where to go.

However, a lost phone is easily noticeable and will be reported right away. You can then immediately disable the credential through Protege WX or GX.

You’re also able to store multiple mobile credentials in the app, enabling you to select what credential you need for the site you’re visiting. No need to print and track multiple cards, meaning less stress in your day-to-day.

Layered authentication

If a phone is lost or stolen and someone fails to report it, your site still has many layers of authentication protecting it.

Most smartphones are protected by a lock screen, whether that’s a PIN, a pattern or a biometric scan, before anyone can reach the app at all. If the malicious actor were to get past this, to access Protege Access+ they still need to enter another PIN. You can set how frequently you want to enter a PIN to enter the mobile app, from every time, to once a day, to every few weeks. For robust security, we recommend setting the frequency to every time or once a day.

Once you’re in the app, there is another layer of authentication: to actually send the credential you need to draw a pattern with Android or shake to unlock with iOS. Enabling these options mitigates the risk of relay attacks.

Diagram of a relay attack: a card reader communicates through two intermediary attacker devices to reach an RFID card

Sharing credentials

Sharing access cards is such a prevalent problem that companies spend hundreds of thousands a year to try and control this behavior. While it doesn’t seem like a big deal, it can result in people accessing areas they shouldn’t be in and lead to inaccurate reporting which could be critical in an emergency.

Additionally, low security cards pose a risk for shared facilities such as gyms, where a member could make copies for their friends, resulting in inaccurate reports and lost income.

However, people are unlikely to share their phones. Sharing credentials through email or text is also mitigated because you can limit the maximum number of devices that a credential can be installed on.

Plastic waste

The environmental impact of our decisions is something that we all must consider and try to reduce. Printing access cards only for them to be lost and printed again isn’t cost-effective or good for the Earth.

By switching from plastic access cards to mobile credentials, you can take effective steps to reduce the amount of waste going into landfills and to make your business more sustainable. It’s a more sustainable choice, and it lowers your ongoing credential costs.

Connecting to the internet and employee privacy

Privacy is something we all worry about, and installing a company’s app on your phone can bring up notions of ‘big brother is always watching’. You’ll need an internet connection the first time you log in, so the app can download your credential. After that, your credential stays valid on your device for up to a month without an internet connection, so a dropped signal at the door won’t lock you out. Monitoring and controlling your system from the app and receiving intercom calls do need a connection.

The credential is not actually stored on the phone and doesn’t use any location or tracking software. The credential is simply used to identify the user, which then communicates with the reader to check whether that user ID has access rights to that area. Everyone’s privacy is secure and protected.

If the reliance on the internet is a concern, we have mitigation plans in place. The readers are still able to be used with physical access cards or fobs. A user can hold more than one credential in the app and switch between them, and only one device can be logged in to an account at a time.

Mobile SDK

If your business already has an app of its own, you can add ICT mobile credentials to it using our Mobile SDK (software development kit), which puts credentials inside your own app for your customers or tenants.

Learn more in our article ICT’s Mobile SDK Takes Mobile Access Control Mainstream.

Use cases

Co-working spaces

No need to be there every time someone books a desk. Just send them an email with the credential and they can access the building in less than a minute.

School Campuses

Take advantage of modern technology and cut the plastic waste. Create an environmentally friendly solution for your staff and students with mobile credentials.

Commercial Offices

Create an easy onboarding process for new employees and HR with mobile credentials sent right to the user’s email. Lost keys and access cards are a thing of the past with mobile credentials.

Residential and Mixed-Use Facilities

Never again worry about a tenant not bringing back their access card or key. Simply revoke the mobile credential. Property managers and landlords don’t need multiple keys or cards, just the phone already in their pocket.

Parking Lots

Use the Mobile SDK to integrate the credential into your parking app, giving users access to any of your parking facilities.

Gyms and Fitness Facilities

Reduce credential sharing and keep accurate records. Integrate your access control with the same app that your customers book classes with, with ICT’s Mobile SDK.

Conclusion

ICT has spent 20+ years in access control, and has seen firsthand how mobile credentials change the way people get through the door. Mobile credentials cut the risk of lost and shared cards, lower your ongoing credential costs and fit the way people already use their phones. If you’re planning an access control upgrade, the ICT team can talk you through what mobile credentials would look like on your site.

Posted on

Updated on July 29, 2026

Product News

Discover how an ICT solution can benefit your organization

Talk to an expert today