What separates MIFARE Classic 1K, Ultralight, Plus and DESFire EV3, where the cheap chip is still adequate, and what to specify when it matters.

Ask a card manufacturer which chip you need and you will usually get one of two answers. Either a price list with part numbers and no explanation, or a paragraph about "advanced encryption" that names nothing at all. Neither helps you decide.
This guide names the chips, states what each one does, and is direct about where the cheap option is adequate and where it is not. We manufacture all of them, so we have no reason to push you toward one.
It is written for whoever has to put a part number on a specification: integrators, distributors, trade printers and programme owners.
Before any chip decision, one thing has to be settled: what frequency does the reader use. Everything else follows from that, and getting it wrong cannot be corrected later by encoding.
The older technology. Simple, cheap, tolerant of dirt and orientation, and essentially no security. Still enormously common in access control, time and attendance, and older hotel estates. Read range is typically two to ten centimetres depending on the reader.
The modern standard for anything where the credential represents value or access rights. Supports real cryptography, faster data rates, and more memory. Governed mainly by ISO/IEC 14443. Read range is usually two to five centimetres, which is a security feature rather than a limitation.
A dual frequency card carries two independent transponders, each with its own chip and antenna, embedded in the same body. The two do not talk to each other. A 125 kHz reader sees one and ignores the other; a 13.56 MHz reader does the reverse. This is the standard answer for an organisation that has upgraded part of its estate and needs staff to carry one credential instead of two.
Dual frequency is not a compromise
It is two complete systems in one piece of PVC. Each performs exactly as it would alone. The only cost is the price of the second inlay and slightly tighter manufacturing tolerances, because two antennas have to coexist without detuning each other.
The most widely deployed contactless chip in the world, and the one most often specified without anyone asking whether it should be.
13.56 MHz, ISO/IEC 14443 Type A. One kilobyte of EEPROM organised as 16 sectors, each with four blocks of 16 bytes. Each sector has its own pair of keys, which is what allows one card to serve several unrelated applications. Factory programmed UID, either four bytes or seven.
It is inexpensive, universally supported, and its sector model is genuinely useful when a single card has to carry a door credential, a canteen balance and a printer quota that belong to three different administrators.
Its CRYPTO1 cipher was broken publicly in 2008 and has been comprehensively broken since. With inexpensive equipment and physical access to a card, its keys can be recovered and the card cloned. This is not theoretical and it is not disputed by anyone, including NXP.
When the consequence of a cloned card is low and the cost of replacing the reader estate is high. A gym locker, a loyalty card, a car park barrier at a site with other controls, a hotel that accepts the risk and rotates cards frequently. What Classic should not be is the answer for a new deployment where the credential protects something that matters. If you are buying readers today, buy readers that do not need Classic.
13.56 MHz, ISO/IEC 14443 Type A, seven byte UID. Very small memory: 64 bytes on the original Ultralight, 48 or 128 bytes of user memory on EV1. No cryptography on the plain versions. Ultralight C adds Triple DES authentication.
Short life credentials where the cost per unit dominates. Event and transport tickets, disposable wristbands, short stay hotel cards, promotional tags. The one time programmable bits and the counter functions on EV1 make it genuinely useful for anything that should be usable a fixed number of times.
Anything reusable over years, anything holding a balance, anything where cloning matters. The memory is too small to carry much and the plain versions have no meaningful protection.
13.56 MHz, ISO/IEC 14443 Type A running the full ISO/IEC 14443-4 protocol layer. Available in 2, 4 and 8 kilobyte versions. AES-128 cryptography, alongside DES and 3K3DES for backwards compatibility. Instead of fixed sectors, memory is organised as applications containing files, which is much closer to how a filesystem works and much easier to administer across multiple stakeholders.
EV1 established the AES based platform. EV2 added transaction MAC, which lets a reader prove that a transaction genuinely happened, and virtual card architecture for handling multiple applications more cleanly. EV3 added Secure Dynamic Messaging, useful where a card also has to be read by a phone, and improved the transaction and proximity handling further.
The chip itself is more expensive and the encoding is more work. In exchange you get a credential whose security is not publicly broken, which matters over the seven to ten year life of a lock estate. For any new hotel, office or campus deployment, DESFire is the default recommendation and the burden of proof sits with anyone proposing something cheaper. In hotel access control this is the same shift that drives the AES migration on Visionline estates.
Often forgotten and frequently the right answer. MIFARE Plus keeps the Classic memory map, so a reader estate configured for Classic can read it, but it supports AES and can be switched to a secure mode later.
That makes it the tool for a specific and very common situation: an estate that cannot replace all its readers at once but wants to stop buying broken credentials. You issue Plus cards now, they work with the existing Classic infrastructure, and when the readers are upgraded you move the cards to AES without reissuing them.
Read only. The chip holds a 64 bit identifier fixed at manufacture and transmits it continuously in the reader's field. No memory to write to, no security whatsoever. Cloning one requires a writable card and about ten seconds. Perfectly adequate for a barrier where the real control is a camera and a human.
Functionally equivalent to EM4100, from a different manufacturer. Cheaper, extremely common, specified interchangeably.
Read and write at 125 kHz, with modest memory and, on HITAG 2, a proprietary cipher. HITAG 1 carries 2048 bits of EEPROM and a factory programmed serial number. Common in access control and in vehicle applications, and the usual low frequency half of a dual frequency card. It is also the chip most often specified in moulded ABS key fobs.
A writable chip that can emulate several low frequency formats, which is why it turns up both in legitimate multi format deployments and in the cloning devices sold online. Its existence is a good reason not to rely on 125 kHz for anything that matters.
You do not have a choice to make. The system decides, and your task is to identify what it uses. Send us a working card or the reader model and we will match it, and the compatibility guide sets out exactly what to look for.
Ask what the consequence of a cloned credential is. If the answer is "someone gets a free coffee", Classic or even 125 kHz is proportionate. If the answer involves a guest room, a stock room, a server room or a payment, specify DESFire EV3 and budget for it once rather than reissuing in three years.
MIFARE Plus if the readers are Classic configured and will be upgraded. Dual frequency if the split is between 125 kHz and 13.56 MHz estates.
DESFire, because its application and file model lets facilities, IT and catering each hold their own keys without being able to read each other's data. Trying to do this with Classic sectors works, but it is administratively fragile.
One question settles most of these conversations
What happens if somebody copies this card? If nobody can answer that, the specification is not finished, and no chip recommendation made before it is answered is worth much.
Four things, and none of them require the specification to be finished: the reader or lock model the credential has to work with, the quantity, the material and finish, and the artwork or a rough of it. Everything else can be settled afterwards, and the guide to specifying a card order covers the rest.
We manufacture for the trade and do not sell to your customers. Chips we work with routinely include MIFARE Ultralight C, Classic 1K, Plus 4K, DESFire EV1 and EV3, HITAG 1, EM4200 and dual frequency combinations of the two bands, and encoding and personalisation happen on the same floor as the printing.
Card bodies can be PVC or recycled PVC with an eighty per cent recycled core, PET, or wood in basswood, cherry, black walnut and bamboo, the wood and bamboo options under FSC licence FSC-C195226. Minimum order is 500 units, standard production thirteen calendar days from artwork approval to dispatch, eight express, twelve on wooden cards. Everything ships under your brand, from one floor in Dongguan.
It is accurate. CRYPTO1 has been broken since 2008 and practical attacks are widely documented. Whether that matters depends entirely on what the card protects. Overstating it would be claiming every Classic deployment must be replaced tomorrow; understating it would be selling Classic for a new hotel without saying anything.
Yes. Chip and body are independent choices. An eight kilobyte DESFire fits the same ISO 7810 ID-1 card as a 64 byte Ultralight, in PVC or in wood. What each body does and does not change is set out in the materials guide.
For 13.56 MHz, typically two to five centimetres with a standard reader, and it depends more on the reader's antenna and power than on the card. For 125 kHz, typically two to ten centimetres. Anyone quoting much more than that is describing UHF, which is a different technology for a different job.
The factory programmed UID is unique, yes. But UID based access control is weak, because UIDs are readable by anyone and writable UID cards exist. A UID is an identifier, not an authenticator. Systems that grant access on UID alone are effectively unencrypted regardless of which chip they use.
Yes, and that is exactly what a dual frequency card is. Two passive transponders, each with its own chip and antenna, independent of each other, in one laminated body.
Send the reader or lock model, the quantity and the date you need them. That is enough for us to answer.
Talk to us