“The Difference Between OSDP and the Traditional Wiegand Protocol”

In the previous chapter, we looked at the various factors affecting access control system security, one important aspect being the communication protocol. Among the many security solutions available, today we'll focus on introducing the communication protocol between controllers and card readers: the origin of the Open Supervised Device Protocol (OSDP) and how it differs from other communication protocols.

 

 

“The Technical Characteristics of Wiegand and the Origin of OSDP”

 

 

In the early 1980s, as more and more companies sought to move away from traditional lock-and-key entry methods toward more centralized, unified access control management, Chief Security Officers (CSOs) continually explored ways to keep their business premises protected from external threats. Because the Clock-and-Data and Wiegand protocols supported interoperability between card readers and controllers in access control systems, they were widely adopted as the standard at the time.
These de facto standards were later formally established as industry standards by the Security Industry Association in the 1990s. Today, more than 90% of installed access control systems use the Wiegand protocol, making it the most common communication method for sending information from card readers to controllers in access control systems.
The working principle of Wiegand protocol devices is as follows:

 

圖片

Figure 1: Working Principle Diagram of Wiegand Protocol Devices

 

 

The controller has two power wires to supply the card reader, and the reader sends the card number to the controller via two signal wires, D0 and D1. Since these two signals can only transmit the card number and serve no other function, any additional feature requires a dedicated wire. For example, when the controller needs to control the reader's red or green LED signal, a dedicated wire is required for that control, and the same goes for the buzzer, which also needs its own dedicated wire. If, due to on-site requirements, the reader needs to be disabled from reading cards (for example, at a parking lot exit, where the reader should only activate after an in-ground loop detects a vehicle), a dedicated Hold wire is also needed. And if the reader needs to send its own tamper signal to the controller, that too requires a dedicated wire.

 

 

『So, what are the shortcomings of Wiegand technology?”

The Wiegand standard was never designed to meet the security needs of today's enterprise users, and the constant emergence of increasingly sophisticated threats poses ever greater challenges for users trying to ensure secure data transmission. At its core, Wiegand lacks the security that today's access control systems require because it is unencrypted, has a limited transmission distance, and is operationally inefficient — it does not allow two-way data transmission between the controller and reader, making firmware upgrades, configuration changes, status changes, and other important updates impossible. Furthermore, anyone who learns the Wiegand protocol language, or who can obtain off-the-shelf hacking devices, can easily exploit its vulnerabilities, creating major security problems for users who rely on this protocol for security.


The Wiegand protocol is a one-way signal that can only send the card number from the reader to the controller. Because of this one-way operating principle, achieving various types of control from the controller to the reader requires separate dedicated connections, resulting in a system with a relatively large amount of wiring.
In addition, card readers use a single-node management model — one Wiegand port can only connect to one reader, which results in a certain degree of resource waste for the overall system. There's also the transmission distance: 120 meters is basically the theoretical limit, and the actual distance is even shorter under real installation conditions. Yet some real-world use cases require distances longer than 120 meters. To avoid Wiegand signal loss in such cases, a local controller must be redeployed nearby, requiring a larger equipment investment.

 

 

『To solve these various problems with Wiegand, OSDP was born”

The Open Supervised Device Protocol (OSDP), introduced ten years ago, has significantly enhanced the capabilities of access control systems, making the outdated and vulnerable Clock-and-Data and Wiegand protocols look obsolete by comparison. As more information about vulnerabilities in legacy access control systems comes to light, users urgently need to adopt protocols like OSDP to improve their overall security posture and support both current and future technology needs.
OSDP was originally initiated by companies including Mercury, HID, and Codebench. These companies later donated the OSDP protocol to the Security Industry Association (SIA) free of charge, so that it could be better promoted and adopted. In May 2020, the OSDP protocol was officially adopted by the International Electrotechnical Commission (IEC) as an international standard, registered as IEC 60839-11-5.

OSDP的由來

Figure 2: The Origin of OSDP

 

Since then, OSDP has gradually developed around the world, with major manufacturers beginning to develop their own OSDP controllers and card readers. Thanks to OSDP's openness, products from different manufacturers are able to interoperate with one another.

 

 

『Wiegand vs. OSDP Comparison”

This diagram gives us a clear, intuitive comparison of the wiring required for Wiegand versus OSDP

 

韋根(wiegand)和OSDP接線差異

Figure 3: Wiring Differences Between Wiegand and OSDP

 

 

On the right is the Wiegand wiring method — aside from the power wires, it generally requires 5 or more additional signal control wires. OSDP, by comparison, is much simpler: a single pair of shielded twisted-pair cable is enough to complete this wiring.
Why twisted-pair cable? Because OSDP's underlying technology is based on the traditional, stable RS-485 multi-point bus standard, which requires shielded twisted-pair wiring to handle this data transmission. In comparison, using OSDP greatly reduces the amount of wiring needed. Also, because OSDP is based on RS-485, the transmission distance has also greatly improved — the theoretical communication distance has increased from Wiegand's original 120 meters to 1,200 meters, a substantial leap. Although in practice the distance between reader and controller rarely needs to be that long, once OSDP is used, wiring distance between reader and controller is no longer a limiting factor during installation. Let's compare using the table below:

 

韋根(wiegand)OSDP優缺點差異

Figure 4: Pros and Cons of Wiegand vs. OSDP

 

 

Wiegand is a technology that originated 40 years ago. It met the needs of its time and was secure back then, but it is increasingly falling behind the times. OSDP, on the other hand, was developed to solve the problems faced today and provides ample room for future expansion.
Compared to OSDP, Wiegand does not monitor the card reader, nor does it encrypt communication with it.


In terms of encryption and monitoring, OSDP comes in two versions, V1 and V2. In terms of security, while V1 is unencrypted, it does monitor the card reader — meaning signals such as whether the reader is offline, its usage status, or whether someone has removed it can all be monitored from the back end, because it uses two-way communication. The V2 version adds AES-128 encryption to the line. Wiegand transmits signals one-way, from the reader to the controller, while OSDP uses RS-485 to achieve two-way connectivity between controller and reader. Wiegand is a point-to-point connection — each port can only connect to one Wiegand reader — while OSDP is a bus-based, multi-point connection, where readers can be distinguished from one another by address. The transmission distance has also increased from the original 120 meters to 1,200 meters.


Wiegand has limited functionality — every feature requires its own dedicated wire, resulting in a large number of connections. With OSDP, on the other hand, two signal wires can handle everything — including LED color control, buzzer control, tamper signals, and more — all through just 2 wires.
Wiegand's one-way transmission means the controller cannot manage the front-end reader, so management must be done on-site at the reader itself. OSDP, being two-way, allows full management and configuration of the front-end reader from the back end — even firmware upgrades.

 

 

『Proprietary RS-485 vs. OSDP Comparison”

As we mentioned, OSDP is based on RS-485. Some of you might point out that many controller manufacturers introduced their own RS-485 protocols long ago — so how does that compare to OSDP today?

 

私有化RS485和OSDP對比

Figure 5: Proprietary RS-485 vs. OSDP Comparison

 

 

Each company's proprietary RS-485 protocol is closed and only works with that company's own controllers and readers. OSDP, on the other hand, is an open international standard with much better universality. Once a customer adopts OSDP devices, they gain a great deal of freedom in product selection, able to mix and match different models and brands into a complete system as project needs or security standards evolve. Also, because proprietary RS-485 protocols are each developed independently, their feature completeness varies. OSDP, supported by many manufacturers, draws on the strengths of each, resulting in more complete functionality.

 

For users, once they adopt a particular vendor's proprietary RS-485 protocol, readers from other vendors won't be supported going forward, resulting in poor replaceability. With OSDP, however, readers and controllers from different vendors are compatible with each other, without being limited to a single manufacturer. As for encryption, proprietary RS-485 implementations vary widely in their level of security. OSDP, by contrast, has a complete monitoring and encryption framework, offering better security. Most importantly, although proprietary RS-485 protocols have been around for a long time, relatively few projects in the market actually use them. OSDP, despite starting later, has had a positive, driving impact on the entire industry.

 

圖片

Figure 6: Excerpt from the OSDP Primer Whitepaper — Benefits for OSDP Users

 

Above, we've gone from the various inconveniences of traditional communication protocols to the origin and technical features of the Open Supervised Device Protocol (OSDP). In the next chapter, we'll look at how, given these technical capabilities, OSDP improves security and operational efficiency.


Coming Up Next: 《How Does OSDP Improve Security and Operational Efficiency?