Unlocking SAM cards - Synergis Cloud Link 2.1.1

Synergis™ Cloud Link Administrator Guide 2.1.1

Applies to
Synergis Cloud Link 2.1.1
Last updated
2023-04-12
Content type
Guides > Administrator guides
Language
English
Product
Synergis Cloud Link
Version
2.1

Storing cryptographic keys on MIFARE Secure Access Module (SAM) AV2 cards instead of the Synergis™ key store increases security because the keys cannot be retrieved. The SAM cards must be unlocked to interact with Synergis™ Cloud Link for cryptographic operations.

Before you begin

  • Configure a Synergis Cloud Link 312 unit.
    NOTE: You need a Synergis Cloud Link 312 units to store the SAM card keys. For more information on Synergis Cloud Link 312 preparation, see Installing SAM cards on a Synergis Cloud Link 312.
  • Configure SAM cards using a SAM production tool like ISLOG SAM Manager, and install up to three cards. For more information on SAM Manager, see Configuring MIFARE SAM AV2 cards.
    NOTE: If you install more than one SAM card, the cards must have the same keys. Having multiple SAM cards installed will allow for faster card reads and access decisions on units with heavy access control activity.

Procedure

  1. Log on to the Synergis Cloud Link 312 unit.
  2. Click Configuration > Synergis™ key store.
  3. At the top of the key list, click .
  4. In the Create new version dialog box, do the following:
    Create new version dialog box on the Synergis key store page of the Synergis™ Appliance Portal.
    1. Select SAM LockUnlock.
    2. In the Components field, enter the LockUnlock keys that you configured in the SAM production tool, and click Add.
    3. Click OK.
  5. Click Configuration > SAM card.
    SAM card page in the Synergis™ Appliance Portal.
  6. In the SAM card unlock configuration section, enter the key number and key version of the LockUnlock key stored on the SAM card.
  7. In the SAM card status section, verify that the SAM cards were inserted and configured correctly.
    You can have up to three SAM cards installed. Each expansion slot can have one of the following statuses:
    OK
    A SAM card is inserted and the LockUnlock key, key number, and version number are valid.
    SAM card unlock failed
    A SAM card is inserted, but the LockUnlock key, key number, or version number do not match those on the card.
    No SAM card inserted
    There is no SAM card in the expansion slot.

After you finish

Enroll STid or OSDP readers, or configure enrolled readers.