HomeLearnGM PassKey, PassLock, and SecureID Security Systems
Knowledge Base
Manufacturer Systems 9 min read

GM PassKey, PassLock, and SecureID Security Systems

The complete guide to General Motors' immobilizer evolution -- from VATS resistor pellets through PassKey and PassLock to modern SecureID -- with programming procedures and failure diagnosis.

General Motors has deployed more different generations of vehicle security systems than perhaps any other single manufacturer, and understanding the differences between them is essential for anyone attempting to diagnose or service a GM vehicle's starting system. From the 1986 VATS (Vehicle Anti-Theft System) through PassKey I, PassKey II, PassKey III, PassLock I, PassLock II, and the current SecureID (Theft Deterrent) system, GM's security architecture has evolved from purely mechanical resistor measurement to full AES-encrypted transponder authentication.

Confusingly, these systems often coexisted within the same model years -- a 2003 Chevrolet Silverado might have PassKey III while a 2003 Chevrolet Cavalier has PassLock II, depending on the platform and trim level. The correct identification of which system is installed is the essential first step in any GM key or immobilizer service.

VATS / Pass-Key I (1986-2001)

VATS (Vehicle Anti-Theft System), marketed under the PASS-Key name on consumer vehicles, used an analog resistance measurement: a resistor pellet embedded in the key blade contacts two spring-loaded probes in the ignition cylinder when the key is inserted. The BCM measures the resistance across these probes. There are 15 possible resistance values (ranging from approximately 392 ohms to 11,800 ohms), and the BCM is programmed with one specific value for that vehicle. If the measured resistance matches, the BCM enables the starter relay and fuel pump. If it does not match, the BCM prevents starting for approximately 4 minutes. The elegance of VATS was its simplicity: no transponder chip, no radio frequency hardware, no complex electronics. The security came from the fact that a hot-wired ignition bypass required the thief to also include the correctly-valued resistor in the bypass circuit -- which required knowing which of the 15 values was correct. A determined thief with time and 15 resistors could try each value, but the 4-minute lockout penalty made this take up to an hour. A critical failure mode of VATS: the resistor pellet corrodes or the key wears such that the contact is intermittent, causing legitimate no-starts. These are diagnosable with a multimeter across the key pellet probes.

PassKey II and PassKey III (1992-2003)

PassKey II extended VATS with additional security: if the incorrect resistance was measured, not only did the BCM disable starting, but it also set a fault code and extended the lockout period on repeated failures. PassKey III added transponder chip capability alongside the resistor measurement for higher-security applications, requiring both the correct resistance AND a valid transponder chip response for engine start authorization. PassKey III with transponder was a transitional technology that combined the analog resistance method (retained for backward compatibility with key infrastructure) with the newer transponder approach. It was used on some 1990s Cadillac and Buick models. Programming PassKey III vehicles requires both cutting the blade to the correct pattern AND programming the transponder chip -- handled as a combined operation by our tools.

PassLock I and PassLock II (1995-2006)

PassLock represented GM's shift away from the key-mounted resistor to an entirely cylinder-mounted system. PassLock moved the authentication sensor INTO the ignition cylinder housing, removing any special requirement from the key blade itself. The ignition cylinder contains a magnet and Hall Effect sensor; when the correct key is inserted and the cylinder rotates, the Hall sensor detects a specific magnetic field pattern unique to that cylinder. The BCM compares this pattern to its stored value. This meant that any physically correct key (or even a filed-down blank that could turn the cylinder) would allow the correct signal to be generated -- security came from the system, not the key. The practical implication: if a thief broke a PassLock cylinder and could manually rotate the cylinder shaft (bypassing the mechanical lock), the Hall sensor would still generate the correct pattern and the BCM would allow start. PassLock's security was primarily its deterrence value and resistance to key copying, not resistance to cylinder destruction. PassLock failures are notoriously common on 1996-2006 GM vehicles. The Hall Effect sensor in the cylinder develops an intermittent connection, causing the BCM to receive an incorrect authentication signal. Symptom: car starts, runs for 10 minutes (the BCM's relearn cycle), then dies and will not restart for 10 minutes (BCM lockout). This specific 10-minute lockout cycle is almost always PassLock sensor failure. The repair options are cylinder replacement, sensor replacement, or the 'PassLock bypass' using a resistor wired to simulate the sensor -- which is a legitimate repair on vehicles outside their warranty period.

SecureID / Current GM Transponder System (2007-Present)

GM's current theft deterrent system uses a NXP Philips 46 or newer transponder chip in the ignition key, with the authentication handled by the BCM. The BCM is programmed with the VIN and a unique security PIN at the factory, and key enrollment requires this PIN. Unlike earlier systems, SecureID key programming cannot be performed with a simple self-programming sequence -- it requires the BCM's security PIN, which is either extracted via OBD-II (on compatible programmers) or obtained through a PIN calculation using the VIN and BCM security seed from GM's database. For all-keys-lost on SecureID vehicles, the procedure is: connect to OBD-II, command the BCM to output its security PIN (or calculate it from the BCM's response to a seed request), enter the PIN into the programming tool, and perform a key enrollment session. The BCM then accepts the new transponder chip's ID as an authorized key. The entire procedure is performed with the vehicle OBD-II port accessible and without needing any working key.
  • 2007+ GM vehicles: NXP 46 transponder chip, BCM-based authentication
  • BCM security PIN required for all programming -- not available without professional tool
  • All-keys-lost: PIN extraction via OBD or calculation from BCM seed
  • Key count: BCM tracks how many keys are enrolled (typically up to 8)
  • SecureID does NOT support self-programming sequences (unlike VATS/PassKey/PassLock)

Key Takeaways

VATS used resistor pellets in the key blade -- 15 possible resistance values
PassLock moved the authentication to the cylinder Hall sensor -- no special key required
PassLock failures cause a characteristic 10-minute lockout cycle (10-minute relearn symptom)
SecureID requires professional OBD-II programming with BCM PIN -- no self-programming
Identifying which system is installed is essential before any repair or programming attempt

Need Expert Help?

Knowledge is step one. If you need this service performed on your vehicle, we come to you 24/7 anywhere in South Georgia.

(912) 348-4006
CALL NOW: (912) 348-4006

Available 24/7 - Mobile Service