Vehicle Access: Keys, Fobs and Passive Entry

Last modified: Jul 30, 2026

Vehicle access is a sequence, not a single lock: the car must recognize a credential, authorize a requested action and still provide a safe fallback when electronics or batteries fail. Unlocking a door and authorizing propulsion are separate decisions.

Mechanical access and emergency entry

A metal key operates a physical lock directly. On many modern cars it survives mainly as an emergency blade hidden inside a fob, with the door cylinder concealed behind a trim cap. It can provide entry when the fob, phone, vehicle radio or low-voltage system is unavailable.

Mechanical entry does not necessarily authorize driving. An electronic immobilizer may still require a valid transponder, fob, card, phone or service procedure before the vehicle can select a drive mode.

Physical locks have familiar limits: keys can be copied or stolen, cylinders can be forced, and a lock provides no remote revocation or event log. Their enduring value is independence from a wireless service and a predictable emergency path.

Button-operated remote entry

Remote keyless entry uses a fob button to request locking, unlocking or opening a cargo area. The fob sends a radio message containing an identifier and changing authentication data. Well-designed systems reject previously used messages and do not treat a recorded unlock transmission as permanently valid.

This is different from passive keyless entry. A button-operated fob normally transmits because the user pressed it; a passive fob can respond automatically when the vehicle searches for a nearby key.

Age and implementation matter more than the label. Older or weak systems may use inadequate authentication, poor resynchronization rules or vulnerable key enrollment. A replacement key should be enrolled through an authorized procedure, and credentials that are lost or no longer owned should be removed from the car.

Passive keyless entry and start

A passive system allows the credential to remain in a pocket or bag. The vehicle and key perform a challenge-and-response exchange, then the vehicle decides whether the credential is close enough and in the right place for the requested action.

The location decision matters. A key outside the driver's door may authorize that door but should not be treated as being inside the cabin for propulsion. Antenna layout, radio ranging and software logic all influence this distinction.

Conventional passive systems can be vulnerable to relay theft. Two devices extend communication between the vehicle and a genuine key that is actually farther away, so the system mistakes relayed communication for proximity. This attack does not need to decrypt a correctly authenticated message; it exploits weak distance verification. Official police guidance distinguishes relay-vulnerable passive entry from fobs that require a button press. Warwickshire Police guidance on keyless vehicle theft

Some fobs enter a sleep state after remaining motionless. Some vehicles let the owner disable passive entry. Signal-blocking pouches can help, but only if both the primary and spare keys are protected and the pouch is tested regularly by attempting to unlock the car with the enclosed key nearby.

Unlocking is not drive authorization

An immobilizer checks an authorized credential before allowing normal propulsion. UN Regulation No. 162 provides technical approval requirements for immobilizers in participating markets. The protected function in an EV is not an ignition spark or fuel circuit; it is the electronic authorization needed for the propulsion system to operate normally. UNECE: UN Regulation No. 162 on immobilizers

Separating entry from driving limits the consequence of a forced door or broken window. A secondary drive PIN can add another layer after a key is accepted, but it must have a secure recovery path and does not stop towing or theft from the cabin.

Access also includes charge-port, front-cargo, rear-cargo and glovebox controls. Their permissions may differ from the passenger doors. A shared driver or delivery credential should receive only the access needed.

Digital keys extend the credential lifecycle

Phone and smartwatch keys add provisioning, sharing, expiry and remote revocation to vehicle access. NFC can support a deliberate tap, Bluetooth Low Energy can establish communication, and ultra-wideband can provide secure distance measurement for passive entry.

The Car Connectivity Consortium Digital Key specification combines those technologies and defines cross-device credential handling. A phone key is covered in detail in Digital key technology. Car Connectivity Consortium Digital Key

A digital credential still depends on correct enrollment and account security. An attacker who takes over the owner account or abuses a weak key-provisioning process may not need to attack the radio link at all.

Failure and recovery

Owners should know four separate procedures:

  • how to enter when the fob or phone battery is depleted;
  • where to present a key card, NFC device or fob for backup authorization;
  • how to replace the vehicle's low-voltage power safely; and
  • how to revoke a lost credential without deleting the only working key.

Do not discover the emergency blade or backup reader during a roadside incident. Procedures vary by model, and unsupported attempts to energize, open or modify an EV can create damage or high-voltage risk.

What buyers should test

During handover, count every physical key, card and phone credential. Confirm that unknown keys can be removed and ask whether the vehicle displays the complete credential list.

Test each door and cargo opening, walk-away locking, the interior-versus-exterior key decision and the emergency entry method. Check whether passive entry can be disabled, whether a motion-sleep fob or secure ranging is used, and what notification appears when a new driver or key is added.

For layered theft controls beyond access, see Theft prevention and recovery.

Sources

More information