What Is a Smart Card?

Related problems: Replacing badges that are easy to copy; Want one badge for doors, printers and other building systems; Need stronger badges for server rooms and other sensitive areas

A smart card is an access badge with an embedded chip that can store data and, in current formats, run cryptographic checks with the card reader to prove it is genuine. Access control smart cards are usually contactless and work at 13.56 MHz (high frequency). Common examples include iCLASS and Seos from HID Global and MIFARE DESFire from NXP Semiconductors. Smart cards are the usual upgrade from 125 kHz proximity cards, which typically send an unprotected number that is widely reported to be easy to copy.

At a glance

  • Smart cards for door access are typically contactless and work at 13.56 MHz.
  • Current formats support encryption and mutual authentication; when readers are configured to use them, copying is much harder than with prox cards.
  • Older smart card formats, such as MIFARE Classic and legacy iCLASS, have publicly documented weaknesses.
  • Security depends on the format, how keys are managed and how readers are configured, not on the word “smart”.
  • One card can often serve doors plus other uses such as secure printing, if the systems support it.

What problem it solves

Organizations replacing prox cards want a badge that can’t be copied by someone who stands near an employee for a moment. Smart cards address that by making the card prove itself: instead of simply broadcasting a number, the card and reader exchange challenges using secret keys, and the data the reader needs is stored in protected areas of the chip.

Smart cards also let one credential do more. Because the chip can hold separate protected applications, the same card can open doors and, with compatible systems, release print jobs or work with other building services. For sensitive areas, a smart card can be paired with a PIN or biometric at the reader to add a second factor, much as multi-factor authentication (MFA) does for logins.

How it works

The chip and the read. When the card is held near a reader, the reader’s field powers the chip. In current formats, when the reader is configured for secure reading, the card and reader run a cryptographic handshake: each proves it holds the right keys before the card releases the credential data, and the data can be encrypted in transit.

Keys. The keys that protect the card’s data are central to its security. Some programs use a manufacturer’s standard keys; others let an organization use site-specific or custom keys so that readers and tools set up with other keys are not able to authenticate to its cards. Custom keys usually raise protection and lock-in at the same time, so it matters who holds them and how replacement cards are ordered.

Formats and generations. Smart card families have changed over time. Earlier formats, such as MIFARE Classic and original iCLASS, were later shown to have weaknesses that let researchers recover keys or copy cards. Newer generations, such as iCLASS SE and Seos from HID Global and MIFARE DESFire EV2 and EV3 from NXP, are designed with stronger cryptography. A card that looks modern may still be read in a weaker mode if the reader is set to read only its unprotected serial number, so the configuration matters as much as the card.

In the system. The reader passes the credential to the door controller of the access control system, which checks permissions as it would for any badge. Migration from prox commonly uses multi-technology readers and, sometimes, dual-technology cards that carry both a prox and a smart card chip during the transition.

When it matters for buyers

  • When retiring prox cards. Smart cards and mobile credentials are the usual replacements.
  • When choosing a cloud platform. Access control as a service (ACaaS) providers support different card families; your choice can tie you to readers and suppliers.
  • When auditors ask about badge security. Being able to state the format, generation and key arrangement answers most questions.
  • When standardizing sites. One card format across locations lets staff use one badge everywhere.
  • When adding uses. Secure printing or other building services need cards and readers that support them.

Questions to ask vendors

  • Which smart card family and generation are you proposing, and what known weaknesses does it have?
  • Will our readers authenticate the card cryptographically, or read only its serial number?
  • Are the keys standard or unique to us, and who holds them?
  • Can we buy replacement cards from more than one source?
  • Will the readers read our current prox cards during migration, and can we disable prox afterward?
  • Does the card work with our cloud or on-premises platform, and with phones if we add mobile credentials later?

How it differs from a proximity card

A proximity card works at 125 kHz and typically sends a fixed, unencrypted number to the reader, which is why it is widely reported to be easy to copy. A smart card works at 13.56 MHz and has a chip that, in current formats, can use keys and encryption to authenticate with the reader, depending on how the reader is configured. The two can look identical, and some readers read both. Moving from prox to a current smart card format with well-managed keys is one of the most common access control security upgrades. See our door access controls overview for help planning one.

Frequently Asked Questions

Are smart cards impossible to clone?
No. A current smart card format with well-managed keys is much harder to copy than a 125 kHz proximity card, but older smart card formats have publicly documented weaknesses, and some readers or configurations only read an unprotected card number. Security depends on the format, the keys and how readers are set up.
What are iCLASS, Seos and MIFARE DESFire?
They are examples of 13.56 MHz smart card technologies used for access control. iCLASS and Seos are product families from HID Global; MIFARE DESFire is a family from NXP Semiconductors. Each has older and newer versions, and the newer versions are generally designed with stronger cryptography than the originals.
Can one smart card do more than open doors?
Often. Depending on the card and the systems involved, the same card may support secure printing, cashless vending, time and attendance or logging in to computers. Each application needs compatible readers and setup, so confirm support before you plan around it.
What are custom or site-specific keys?
Some smart card programs let an organization use keys unique to it instead of a manufacturer's default keys, so readers and tools set up with other customers' keys are not able to authenticate to its cards. It adds protection but also adds key management, so ask who holds the keys and how cards are reordered.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.