{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,4]],"date-time":"2026-07-04T16:58:34Z","timestamp":1783184314976,"version":"3.54.6"},"reference-count":36,"publisher":"MDPI AG","issue":"12","license":[{"start":{"date-parts":[[2025,12,4]],"date-time":"2025-12-04T00:00:00Z","timestamp":1764806400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Information"],"abstract":"<jats:p>A secure and sustainable building access control system plays a vital role in protecting organisational assets worldwide. Physical access management at Auckland University of Technology (AUT) is still primarily done through traditional card-based authentication. The system is susceptible to replay and cloning attacks because the conventional Mifare Classic credentials employ outdated Crypto1 encryption. Such weaknesses provide significant threats in laboratories, engineering testing facilities, and research and technological areas that require strict security procedures. To overcome the above issues, we propose a secure and sustainable university building access control system using mobile app credentials. This research grounded a thorough risk analysis of the university\u2019s current infrastructure, mapping potential operational continuity threats. We analyse card issuance records by identifying high-risk areas such as restricted laboratories and evaluating the resilience of the current Gallagher\u2013Salto system against cloning and replay attacks. We quantify the distribution and usage of cards that are vulnerable. To evaluate the risks to operational continuity, the system architecture is examined. Additionally, a trial implementation of the Gallagher Mobile Connect platform was conducted, utilising cloud registration, multi-factor authentication (PIN or biometrics), and books. Pilot implementation shows that mobile-based credentials improve user experience, align with AUT\u2019s environmental sustainability roadmap, and increase resilience against known attacks. Results have shown that our proposed mobile credentials can improve the system performance up to 80%.<\/jats:p>","DOI":"10.3390\/info16121073","type":"journal-article","created":{"date-parts":[[2025,12,4]],"date-time":"2025-12-04T13:53:30Z","timestamp":1764856410000},"page":"1073","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["A Secure and Sustainable Transition from Legacy Smart Cards to Mobile Credentials in University Access Control Systems"],"prefix":"10.3390","volume":"16","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-2845-533X","authenticated-orcid":false,"given":"Rashid","family":"Mustafa","sequence":"first","affiliation":[{"name":"Computer and Information Sciences, Auckland University of Technology, Auckland 1010, New Zealand"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Toseef Ahmed","family":"Khan","sequence":"additional","affiliation":[{"name":"Computer and Information Sciences, Auckland University of Technology, Auckland 1010, New Zealand"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2770-8319","authenticated-orcid":false,"given":"Nurul I.","family":"Sarkar","sequence":"additional","affiliation":[{"name":"Computer and Information Sciences, Auckland University of Technology, Auckland 1010, New Zealand"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,12,4]]},"reference":[{"key":"ref_1","first-page":"267","article-title":"A Practical Attack on the MIFARE Classic","volume":"Volume 5189","author":"Hoepman","year":"2008","journal-title":"Lecture Notes in Computer Science, Proceedings of the Smart Card Research and Advanced Applications\u2014CARDIS 2008, London, UK, 8\u201311 September 2008"},{"key":"ref_2","first-page":"201","article-title":"Dismantling MIFARE Classic","volume":"Volume 5536","author":"Garcia","year":"2009","journal-title":"Lecture Notes in Computer Science, Proceedings of the Applied Cryptography and Network Security (ACNS 2009), Paris-Rocquencourt, France, 2\u20135 June 2009"},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Meijer, C., and Verdult, R. (2015, January 12\u201316). Ciphertext-Only Cryptanalysis on Hardened MIFARE Classic Cards. Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security (CCS 2015), Denver, CO, USA.","DOI":"10.1145\/2810103.2813641"},{"key":"ref_4","unstructured":"Gray, A.R. (2025). Managing Change in Higher Education: Implementing Mobile Credentials Across USNH. [Master\u2019s Thesis, University of New Hampshire]. Available online: https:\/\/scholars.unh.edu\/ms_leadership\/143."},{"key":"ref_5","doi-asserted-by":"crossref","unstructured":"Mustafa, R., Sarkar, N.I., Mohaghegh, M., and Pervez, S. (2024). A Cross-Layer Secure and Energy-Efficient Framework for the Internet of Things: A Comprehensive Survey. Sensors, 24.","DOI":"10.20944\/preprints202410.0518.v1"},{"key":"ref_6","doi-asserted-by":"crossref","unstructured":"Szymoniak, S., and Kesar, S. (2023). Key Agreement and Authentication Protocols in the Internet of Things: A Survey. Appl. Sci., 13.","DOI":"10.3390\/app13010404"},{"key":"ref_7","doi-asserted-by":"crossref","unstructured":"Namane, S., and Dhaou, I.B. (2022). Blockchain-Based Access Control Techniques for IoT Applications. Electronics, 11.","DOI":"10.3390\/electronics11142225"},{"key":"ref_8","first-page":"108712","article-title":"A survey on Bluetooth Low Energy security and privacy","volume":"203","author":"Pawelke","year":"2022","journal-title":"Comput. Netw."},{"key":"ref_9","doi-asserted-by":"crossref","unstructured":"Onumadu, P., and Abroshan, H. (2024). Near-Field Communication (NFC): Cyber Threats and Mitigation Solutions in Payment Transactions: A Review. Sensors, 24.","DOI":"10.3390\/s24237423"},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Ve\u013eas, A., Boro\u0161, M., Kuffa, R., and Lenko, F. (2024). Testing of Permeability of RFID Access Control System for the Needs of Security Management. Appl. Sci., 14.","DOI":"10.3390\/app14104227"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Vestenick\u00fd, P., Hrubo\u0161, M., and Kolla, E. (2023). Evaluation of Contactless Identification Card Immunity against a Current Pulse in an Adjacent Conductor. Electronics, 12.","DOI":"10.3390\/electronics12234875"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Gre\u00df, H., Kr\u00fcger, B., and Tischhauser, E. (2025). The Newer, the More Secure? Standards-Compliant Bluetooth Low Energy Man-in-the-Middle Attacks on Fitness Trackers. Sensors, 25.","DOI":"10.3390\/s25061815"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Peker, Y.K., Bello, G., and Perez, A.J. (2022). On the Security of Bluetooth Low Energy in Two Consumer Wearable Heart Rate Monitors\/Sensing Devices. Sensors, 22.","DOI":"10.3390\/s22030988"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Hasan, S.S.U., Ghani, A., Daud, A., Akbar, H., and Khan, M.F. (2025). A Review on Secure Authentication Mechanisms for Mobile Devices. Sensors, 25.","DOI":"10.3390\/s25030700"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Gong, Y., Li, K., Xiao, L., Cai, J., Xiao, J., Liang, W., Liang, W., and Khan, M.K. (2023). An Adaptive, Lightweight, Secure, and Efficient RFID Fast Authentication Protocol. Sensors, 23.","DOI":"10.3390\/s23115198"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Gong, Y., Li, K., Xiao, L., Cai, J., Xiao, J., Liang, W., Liang, W., and Khan, M.K. (2023). VASERP: An Adaptive, Lightweight, Secure, and Efficient RFID-Based Authentication Scheme for IoV. Sensors, 23, Available online: https:\/\/pubmed.ncbi.nlm.nih.gov\/37299924\/.","DOI":"10.3390\/s23115198"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Wang, S., Fan, Z., Su, Y., Zheng, B., Liu, Z., and Dai, Y. (2024). A Lightweight, Efficient, and Physically Secure Key Agreement Authentication Protocol for Vehicular Networks. Electronics, 13.","DOI":"10.3390\/electronics13081418"},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Mu\u00f1oz-Ausecha, C., Ruiz-Rosero, J., and Ram\u00edrez-Gonz\u00e1lez, G. (2021). RFID Applications and Security Review. Computation, 9.","DOI":"10.3390\/computation9060069"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Corches, C., Daraban, M., and Miclea, L. (2021). Availability of an RFID Object-Identification System in IoT Environments. Sensors, 21.","DOI":"10.3390\/s21186220"},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Natgunanathan, I., Fernando, N., Loke, S.W., and Weerasuriya, C. (2023). Bluetooth Low Energy Mesh: Applications, Considerations and Current State-of-the-Art. Sensors, 23.","DOI":"10.3390\/s23041826"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Sun, D., and Tian, Y. (2022). Study on Address Privacy for Bluetooth Low Energy. Mathematics, 10.","DOI":"10.3390\/math10224346"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Chen, W., Wei, Z., and Yang, Z. (2025). Robust Beamfocusing for Secure NFC with Imperfect CSI. Sensors, 25.","DOI":"10.3390\/s25041240"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Rehman, A., Alharbi, O., Qasaymeh, Y., and Aljaedi, A. (2025). DC-NFC: A Custom Deep Learning Framework for Security and Privacy in NFC-Enabled IoT. Sensors, 25.","DOI":"10.3390\/s25051381"},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Firlej, A., Musial, S., and Kubiak, I. (2024). Data Immunity in Near Field Radio Frequency Communication Systems\u2014NFC as an Aspect of Electromagnetic Information Security. Appl. Sci., 14.","DOI":"10.3390\/app14135854"},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Ragothaman, K., Wang, Y., Rimal, B., and Lawrence, M. (2023). Access Control for IoT: A Survey of Existing Research, Dynamic Policies and Future Directions. Sensors, 23.","DOI":"10.3390\/s23041805"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Bukova, B., Tengler, J., Brumercikova, E., Brumercik, F., and Kissova, O. (2023). Environmental Burden Case Study of RFID Technology in Logistics Centre. Sensors, 23.","DOI":"10.3390\/s23031268"},{"key":"ref_27","doi-asserted-by":"crossref","first-page":"107829","DOI":"10.1016\/j.resconrec.2024.107829","article-title":"The Environmental Benefits and Burdens of RFID Systems in Li-Ion Battery Supply Chains\u2014An Ex-Ante LCA Approach","volume":"209","author":"Ding","year":"2024","journal-title":"Resour. Conserv. Recycl."},{"key":"ref_28","first-page":"17","article-title":"Life Cycle Assessment of Plastic and Paper-Based Ultra High Frequency RFID Tags","volume":"14","author":"Aliakbarian","year":"2024","journal-title":"Radio Freq. Technol."},{"key":"ref_29","doi-asserted-by":"crossref","unstructured":"Segkoulis, T., and Limniotis, K. (2025). Enhancing Multi-Factor Authentication for Mobile Devices Through Cryptographic Zero-Knowledge Protocols. Electronics, 14.","DOI":"10.3390\/electronics14091846"},{"key":"ref_30","doi-asserted-by":"crossref","first-page":"189","DOI":"10.1007\/s40171-016-0136-2","article-title":"A Review of RFID in Supply Chain Management: 2000\u20132015","volume":"17","author":"Musa","year":"2016","journal-title":"Glob. J. Flex. Syst. Manag."},{"key":"ref_31","unstructured":"(2022). Information Security, Cybersecurity and Privacy Protection\u2014Guidance on Managing Information Security Risks (Standard No. ISO\/IEC 27005:2022). Available online: https:\/\/www.iso.org\/standard\/80585.html."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Aven, T. (2015). Risk Analysis, John Wiley & Sons. [2nd ed.].","DOI":"10.1002\/9781119057819"},{"key":"ref_33","unstructured":"Khan, T.A. (2024). Secure and Sustainable Transition from Legacy RFID Cards to Mobile Credentials at AUT. [Master\u2019s Thesis, Auckland University of Technology]."},{"key":"ref_34","unstructured":"(2018). Cards and Security Devices for Personal Identification\u2014Contactless Proximity Object\u2014Part 1: Physical Characteristics (Standard No. ISO\/IEC 14443-1:2018). Available online: https:\/\/www.iso.org\/standard\/73597.html."},{"key":"ref_35","unstructured":"(2018). Risk Management\u2014Guidelines (Standard No. ISO 31000:2018). Available online: https:\/\/www.iso.org\/standard\/65694.html."},{"key":"ref_36","unstructured":"NIST Special Publication 800-30 Revision 1 (2025, November 27). Guide for Conducting Risk Assessments, Available online: https:\/\/csrc.nist.gov\/pubs\/sp\/800\/30\/r1\/final."}],"container-title":["Information"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2078-2489\/16\/12\/1073\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,4]],"date-time":"2025-12-04T14:14:33Z","timestamp":1764857673000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2078-2489\/16\/12\/1073"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12,4]]},"references-count":36,"journal-issue":{"issue":"12","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["info16121073"],"URL":"https:\/\/doi.org\/10.3390\/info16121073","relation":{},"ISSN":["2078-2489"],"issn-type":[{"value":"2078-2489","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,12,4]]}}}