Dismantling the SEOS Protocol

Black Hat Asia 2025 · Day 1 · Briefings

Overview

This talk, "Dismantling the SEOS Protocol," delves into the intricate security mechanisms of HID Global's SEOS protocol, a widely adopted RFID access control technology. Presented by Evil Damon, a senior penetration tester specializing in hardware and physical security, and Iceman, an RFID hacking veteran and open-source enthusiast, the session aims to demystify a system often touted as "future-proof" and highly secure. The speakers embarked on this research due to the scarcity of substantial public information beyond vendor whitepapers, driven by a fundamental desire to understand how critical security systems truly function.

Watch on YouTube

Visual summary for Dismantling the SEOS Protocol
Visual summary for Dismantling the SEOS Protocol

Key moments

  1. 0:00 Introduction to dismantling SEOS protocol
  2. 3:20 RFID 101: Moving to encrypted communication
  3. 4:00 What is SEOS? Claims and documentation gaps
  4. 4:50 SEOS tag internal structure: GDF, ADFs, keys
  5. 6:00 Reverse engineering methodology and tools used
  6. 6:50 Technical deep dive: APDU command structure
  7. 7:50 Discovery of custom Get ADF command

Dismantling the SEOS Protocol

Speakers: Evil Damon (Senior Penetration Tester, OneStep Group), Iceman (Co-founder, Aurora org)

Conference: Black Hat Asia

YouTube: https://www.youtube.com/watch?v=mnhGx1i6x08

Overview

This talk, "Dismantling the SEOS Protocol," delves into the intricate security mechanisms of HID Global's SEOS protocol, a widely adopted RFID access control technology. Presented by Evil Damon, a senior penetration tester specializing in hardware and physical security, and Iceman, an RFID hacking veteran and open-source enthusiast, the session aims to demystify a system often touted as "future-proof" and highly secure. The speakers embarked on this research due to the scarcity of substantial public information beyond vendor whitepapers, driven by a fundamental desire to understand how critical security systems truly function.

The core objective of their work was threefold: to gain a deep understanding of the SEOS protocol's operational mechanics, to meticulously review the specific technologies and cryptographic primitives it employs, and ultimately, to rigorously evaluate its security posture. This presentation is less about discovering vulnerabilities and more about transparently exposing the underlying complexity and robust design of SEOS. It serves as a comprehensive guide for security professionals, researchers, and system integrators seeking to move beyond marketing claims and grasp the practical realities of modern RFID security.

The significance of this research extends beyond mere academic curiosity. SEOS is deployed in a vast array of environments, from corporate offices and educational institutions to critical infrastructure. As such, an independent, detailed analysis of its security architecture is paramount. By openly dissecting the protocol's layers of protection, Evil Damon and Iceman provide invaluable insights into the state of the art in secure access control, advocating for greater transparency and independent scrutiny within the security industry.

Background

▶ Watch: Introduction to dismantling SEOS protocol (0:00)

RFID (Radio Frequency Identification) technology has become ubiquitous, enabling seamless interactions in various domains, from asset tracking to access control. At its most basic, an RFID system comprises a tag (or card) and a reader. The reader generates an RF field that powers the tag's internal IC, allowing it to communicate. Early RFID systems were notoriously simple, transmitting data like a facility code and card number in plaintext. This made them highly susceptible to replay attacks, where an attacker could easily sniff and retransmit the unencrypted data to gain unauthorized access.

To address these fundamental vulnerabilities, the industry evolved. The first layer of defense introduced was password protection, where the reader would challenge the tag for a specific password before allowing data transmission. While an improvement, this still left systems vulnerable to brute-force attacks or compromise if the password was weak or leaked. The next significant leap, and the foundation of modern secure RFID, was the integration of encryption. This transformed the communication into "gobbledygook," making it unintelligible to eavesdroppers without the correct cryptographic keys.

HID Global, a dominant player in the access control market, has a history marked by both innovation and security challenges. Their earlier iClass generation, while initially perceived as secure, eventually faced public scrutiny and demonstrated vulnerabilities. In response, HID Global developed iClass SEOS, commonly referred to simply as SEOS, as its successor. It was marketed with strong buzzwords like "strong authentication," "heightened privacy," and "AES encryption," promising a "future-proof" and significantly more secure solution. Despite these claims and the widespread adoption of SEOS, comprehensive public documentation detailing its internal workings remained scarce, largely confined to high-level whitepapers. This lack of transparency created a knowledge gap that Evil Damon and Iceman sought to fill, providing a much-needed independent technical review of the protocol's intricate design.

Key Findings

▶ Watch: What is SEOS? Claims and documentation gaps (4:00)

The primary discovery of this research is the highly layered and robust security architecture of the SEOS protocol, which the speakers aptly compare to an "onion" or an "ogre" due to its multiple, nested protection mechanisms. Far from being easily broken, SEOS implements a sophisticated combination of open standards and custom cryptographic constructs, designed to withstand replay, sniffing, and unauthorized access attempts.

A significant contribution of their work is the detailed mapping and explanation of the SEOS communication flow, which was previously obscure. They identified and documented key commands, including standardized ISO 7816 APDU commands for application selection, and custom commands like the get ADF command, which is crucial for retrieving application-specific data. This command, they noted, utilizes ASN.1 (Abstract Syntax Notation One) encoding for its parameters, specifically to request an object ID. The response from this command is particularly vital as it contains a cryptogram and a MAC, which, when decrypted, reveal the object ID and, critically, the diversifier. The diversifier is a pivotal element, as it's later used by the reader to properly encrypt the keys, forming a core part of the system's key diversification function.

Further findings include the detailed breakdown of the ISO 7816 general authentication process. This involves the exchange of challenges and responses, incorporating a value referred to as R&D ICC (Random ICC), which, while potentially static across some cards, plays a role in generating session keys. The authentication sequence also involves combining the R&D ICC with a random IFD value and a key IFD value, all processed through a diversified encryption key to produce cryptograms and MACs. This intricate handshake establishes secure messaging for subsequent data exchanges. The speakers highlighted the use of MAC chaining, where each sequential command's MAC is incremented, ensuring the integrity and correct sequence of data transmission, an advanced feature for preventing message reordering or tampering. This multi-layered approach to key management and message integrity underscores the thoughtful design behind the SEOS protocol.

Technical Deep Dive

▶ Watch: SEOS tag internal structure: GDF, ADFs, keys (4:50)

The technical dissection of the SEOS protocol reveals a meticulously engineered system, integrating multiple cryptographic layers and data formats. The communication process begins with standard ISO 7816 APDU (Application Protocol Data Unit) commands. An APDU command is encapsulated with a 0B0A header and concludes with a CRC (Cyclic Redundancy Check) for data integrity. The initial command is typically an ISO 7816 select file command, which selects a specific application on the card using an application ID, a combination of a Registered ID (RID) and a manufacturer-specific identifier. A successful response is indicated by 9000.

Following application selection, the custom get ADF command comes into play. This command, identified by an A5 instruction header, is used to retrieve information about an Application Data File (ADF) or even the overarching Global Data File (GDF). The command's payload is encoded using ASN.1, which the speakers simplified as Tag Length Value (TLV). It specifies the object ID for which information is requested. The response contains a cryptogram encrypted with a privacy key and a MAC key for integrity. Decrypting this reveals the object ID and, crucially, the diversifier. The diversifier is a unique value used by the reader to generate the correct diversified encryption key for subsequent secure communication. The ADF itself is a flexible store for data objects, each potentially secured with different privacy, MAC, and authentication keys, allowing granular access control.

The next critical phase is ISO 7816 general authentication, also known as secure messaging. This process establishes a secure channel. The reader sends a general authentication command, specifying a key slot (e.g., 01) and requesting the R&D ICC (Random ICC). The card responds with the R&D ICC value. The reader then generates a random IFD value and a key IFD value, combines these with the R&D ICC and the diversified encryption key, and encrypts the result into a cryptogram with an accompanying MAC. This is sent back to the card. The card performs the reverse operation, decrypting and verifying the values. This challenge-response mechanism is then repeated in reverse, with the card generating new values and sending them to the reader, ensuring mutual authentication and the establishment of session keys for secure messaging.

For actual data retrieval, the ISO 7816 get data command is used, always within the established secure messaging context. The session keys for encryption and MAC are generated from the previously exchanged values and the diversified encryption key. A key feature here is MAC chaining, where the MAC of each command is incremented sequentially. This ensures that the order of commands is preserved and prevents replay or reordering attacks. The command itself, such as 5C D0 to get object ID D0, is encrypted using the session encryption key and padded to the correct block size. The card's response, also encrypted and MAC-chained, is then decrypted by the reader, revealing the requested object data. This intricate dance of encryption, MACs, and chaining forms the "layers" of security.

Beyond the core protocol, the talk delved into the Secure Identity Object (SIO), a key concept in HID Global's ecosystem. The SIO is described as a "carrier-independent" container for encrypted and signed payloads, capable of being stored on RFID cards, mobile phone secure elements, or transmitted over various carriers. Its structure, also presented in ASN.1, includes a relative OID, a key reference ID (indicating the key set used, e.g., 01 for standard keys or 00 for "elite keys"), a crypto identifier (e.g., 0300 08 or 09 for EIX or EIX prime), and the encrypted PAX payload. The PAX payload itself is divided into a variable-sized encrypted portion and a fixed 16-byte signature.

To decrypt the SIO payload, a diversified key is essential, generated by a Key Diversification Function (KDF). This KDF utilizes AAC (Advanced Audio Coding) with SHA-1, taking a specially crafted 48-byte input and producing a 16-byte output. The speakers cautioned about potential buffer overflows, noting that AAC can produce a 20-byte hash. The cryptographic algorithms used for SIO are Authenticated Encryption with Associated Data (AEAD) schemes, specifically EIX and EIX prime. EIX uses AES in OMAX mode, providing variable-size encryption and a 16-byte signature. EIX prime, used in GSM traffic, employs AES in CBC (Cipher Block Chaining) mode with CMAC, also allowing variable encryption size but with a variable signature size (standard defines 4 bytes, but SEOS uses 16 bytes). The speakers noted that HID Global uses the bouncy castle implementation for these cryptos, which is open source, but implementing them in C presented challenges, particularly with endianness, requiring two weeks of painstaking effort to get correct test vectors.

Finally, the decrypted SIO payload contains data in a padded PEX Wiegand format. This format is not raw Wiegand but includes a leading byte indicating the number of zero bits to shift. For example, 06 1B7D 040 signifies a 26-bit Wiegand payload where the 06 means shifting the subsequent bytes by six bits. Once shifted and converted to binary, this string can be fed into a Wiegand decoder (like the one in Proxmark client) to extract the familiar facility code and card number. This intricate process of unpacking, decrypting, and decoding highlights the depth of the SEOS security design.

Demo / Proof of Concept

▶ Watch: Technical deep dive: APDU command structure (6:50)

While the talk did not feature a live, real-time demonstration of exploiting or breaking the SEOS protocol, the entire presentation was a detailed exposition of the speakers' proof-of-concept understanding and reverse engineering efforts. Their methodology involved extensive sniffing of HF14 communication using a Proxmark device, which provided raw, "gobbledygook" trace files. The core of their work was the painstaking analysis and decoding of these raw bytes.

The speakers demonstrated their understanding by presenting simplified ASN.1 representations of complex byte blobs, breaking down each field, its purpose, and its interaction with other protocol elements. This included showing how they identified the custom get ADF command, parsed the ASN.1 structures, and located the diversifier. Furthermore, their ability to describe the intricate ISO 7816 general authentication and secure messaging sequences, including the roles of R&D ICC, diversified encryption keys, and MAC chaining, serves as a testament to their successful protocol reconstruction.

A significant part of their proof of concept involved implementing the identified cryptographic algorithms. Iceman specifically mentioned the two weeks spent porting the EIX and EIX prime algorithms from academic papers and the bouncy castle open-source implementation into a C environment, overcoming challenges like endianness mismatches to achieve working test vectors. This practical implementation allowed them to correctly decrypt the SIO payloads and subsequently decode the padded PEX Wiegand format into recognizable facility codes and card numbers. Though not a live hack, the rigorous process of reverse engineering, cryptographic implementation, and data decoding presented throughout the talk is the proof of concept that they have comprehensively "dismantled" and understood the SEOS protocol down to its fundamental operations.

Defensive Implications

▶ Watch: Discovery of custom Get ADF command (7:50)

The most striking defensive implication derived from this talk is the speakers' unequivocal conclusion: SEOS is a "pretty damn secure system." This is a critical takeaway, especially given the history of vulnerabilities in previous RFID systems. HID Global has clearly learned from past issues, adopting a design philosophy that integrates well-established open standards (like ISO 7816, AES, SHA-1) with thoughtfully constructed custom elements and robust cryptographic practices such as key diversification, secure messaging, and MAC chaining.

For defenders, this means that the immediate threat landscape for SEOS is not one of easy, broad-stroke exploitation. Instead, the focus shifts to proper implementation, configuration, and key management. The system's security relies heavily on the strength of its diversified keys and the integrity of its cryptographic operations. Therefore, organizations deploying SEOS must ensure:

  1. Strict Key Management: All keys, especially master keys used for diversification, must be securely generated, stored, and managed, adhering to best practices for cryptographic key lifecycle management. Any compromise of these foundational keys would undermine the entire system.
  2. Independent Verification: While the protocol itself is strong, the speakers emphasized the need for independent testing of such critical systems. Organizations should not solely rely on vendor claims but seek out security assessments to validate their specific SEOS deployments.
  3. Beyond the Datasheet: Defenders are urged to "review how systems work" and "evaluate it beyond just a data sheet." Understanding the underlying protocol, as demonstrated by this talk, enables more informed risk assessments and better decision-making regarding system architecture and configuration.
  4. Vendor Collaboration: The speakers explicitly called for vendors to embrace independent research and publicly share information to facilitate security evaluations. Defenders should encourage this transparency from their suppliers, as it fosters a more secure ecosystem.
  5. Vulnerability Reporting: Should any vulnerabilities be discovered in specific SEOS implementations or configurations, the responsible disclosure to vendors is paramount to ensure timely fixes and maintain the overall security posture of the technology.

In essence, SEOS represents a significant step forward in RFID security. Its strength lies in its layered approach and adherence to cryptographic best practices. Defenders should leverage this understanding to ensure their deployments fully capitalize on these inherent security features, focusing on secure configuration and ongoing monitoring rather than anticipating easy protocol-level breaks.

Key Takeaways

  • SEOS is a Robust, Layered Security Protocol: The protocol employs multiple layers of encryption, authentication, and integrity checks, likened to an "onion" or "ogre," making it significantly more secure than previous RFID systems.
  • Combination of Standards and Custom Elements: SEOS integrates well-known ISO 7816 APDU commands and cryptographic primitives (like AES, SHA-1, AEAD) with custom commands (e.g., get ADF) and data structures (ASN.1, SIO).
  • Key Diversification is Central: The system heavily relies on diversified encryption keys, generated via a KDF using values like the diversifier and R&D ICC, which enhances security by making each card's keys unique.
  • Secure Messaging and MAC Chaining Ensure Integrity: ISO 7816 general authentication establishes secure messaging, and MAC chaining guarantees both the integrity and correct sequential order of commands and responses, preventing replay and reordering attacks.
  • SIO Provides Carrier-Independent Secure Data: The Secure Identity Object (SIO) acts as a flexible, encrypted, and signed container for identity data, allowing it to be stored and transmitted across various mediums.
  • SEOS is "Pretty Damn Secure": The speakers concluded that SEOS is a well-designed and secure system, emphasizing that their research was about understanding its complexity, not finding immediate breaks. This highlights the importance of independent research for validating vendor claims and fostering transparency.

About the Speaker(s)

Evil Damon is a Senior Penetration Tester at OneStep Group, with over a decade of experience in information security. He is particularly known for his expertise in electronics and hardware security, and he also teaches physical security. His work often involves deep dives into the mechanics of security systems.

Iceman is the co-founder of Aurora org and has been actively hacking RFID systems for over ten years. He is a strong advocate for open-source technologies and played a crucial role in the cryptographic implementation and detailed protocol analysis presented in this talk. His work has contributed significantly to the understanding of RFID security within the research community, including contributions to the Proxmark forum.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This is a masterclass in reverse engineering a critical access control protocol that was deliberately opaque. Evil Damon and Iceman have done the community a tremendous service by painstakingly dissecting HID Global's SEOS, moving beyond marketing fluff to expose its true, layered security architecture. Their work, involving deep protocol analysis, cryptographic implementation, and meticulous documentation, provides an unprecedented, independent technical understanding of a system deployed globally. This is exactly the kind of transparent, foundational research that informs and empowers defenders.

Heather Calloway (CISO) — STRONG ACCEPT

This session provides a rigorous and unsentimental assessment of HID Global's SEOS protocol, moving beyond vendor marketing to offer a transparent, independent technical review. The speakers methodically dismantle the protocol's complex, layered security architecture, concluding that it is a "pretty damn secure system." This deep dive into its cryptographic primitives, key diversification, and secure messaging mechanisms offers critical insights for CISOs and security leaders, shifting the focus from protocol-level vulnerabilities to the paramount importance of robust key management and diligent implementation in real-world deployments.

→ Top-rated talks at Black Hat Asia 2025

All talks from Black Hat Asia 2025