Secure Channel Mode
The OSM-2400 is in Secure Channel Mode when DIP Switch 6 is ON or when the Secure Channel
Base Key (SCBK) has been set by the user. While the OSM-2400 is in Secure Channel Mode, the
OSM-2400 will limit its functionality until a Secure Channel session is established. If the SCBK has
not been set by the user, the OSM-2400 uses the SCBK-D (default SCBK). !
ACU Mode - When Secure Chanel Mode is not active, the OSM-2400 will initiate an unencrypted
session with the OSDP reader or PD (Peripheral Device). When Secure Channel Mode is active, the
OSM-2400 will only attempt to establish a Secure Channel session with the PD. !
PD Mode -When Secure Channel Mode is not active, the ACU (Access Control Unit) can initiate an
unecrypted session or Secure Channel session with the OSM-2400. When Secure Channel Mode is
active, the OSM-2400 will only process a subset of commands (listed below), until the ACU
establishes a Secure Channel session with the OSM-2400.!
•osdp_ID!
•osdp_CAP!
•osdp_COMSET!
•osdp_CHLNG!
•osdp_MFG!
Setting the Secure Channel Base Key (SCBK)
From the factory, the OSM-2400 is loaded with the SCBK-D, as defined in the OSDP specification.
The SCBK-D / SCBK is used to encrypt the data payload of OSDP messages while in a Secure
Channel session. The OSM-2400 SCBK-D is 30 31 32 33 34 35 36 37 38 39 3A 3B 3C 3D 3E 3F
(16 bytes in HEX) and is public. !
IMPORTANT: It is strongly recommended that a new SCBK be set in the OSM-2400 when using
Secure Channel communication in ACU Mode or PD Mode. The SCBK is set in while the
OSM-2400 is in PD Mode. The OSM-2400 will only accept the osdp_KEYSET command while it is
in a Secure Channel communication session with an ACU. This means the current SCBK must be
known before a new SCBK can be set in the OSM-2400.!
The ACU sends the osdp_KEYSET command with the new SCBK to the OSM-2400 while in a
Secure Channel communication session. It is best practice for the SCBK to be sent to the
OSM-2400 out-of-band, meaning the OSM-2400 is directly connected to the ACU over a short run
of cable and not connected to the ACU over the OSDP network connection. If an attacker is able to
listen in on the OSDP communication while the osdp_KEYSET command is sent from the ACU to
the OSM-2400 in PD Mode, they will have the SCBK and be able to decrypt the OSDP messages. !
Section continued on next page.