Guide

Contactless smart card families explained

6 min read·
Contactless smart card families explained

In short

Most contactless access, transit and payment cards are 13.56 MHz devices built on the ISO/IEC 14443 standard. Within that world, the widely deployed MIFARE-class families range from the older, cryptographically broken Classic products to modern AES-based DESFire-class cards. For any new secure deployment, DESFire-class credentials are strongly preferred because their open, standards-based cryptography has held up where the legacy proprietary ciphers have not.

What standard do contactless smart cards use?

The dominant contactless smart-card standard is ISO/IEC 14443, a 13.56 MHz 'proximity' specification with a working range of about 10 centimeters. It defines two signaling variants, Type A and Type B, that differ in how the card and reader modulate the field and handle anti-collision when several cards are present. Contactless bank cards, transit fare media and most modern access badges are ISO/IEC 14443 devices.

Related 13.56 MHz standards fill adjacent roles: ISO/IEC 15693 covers longer-range 'vicinity' cards, and the NFC Forum layers interoperable tag types and phone interaction (ISO/IEC 18092) on top of the same frequency, which is how a smartphone can read or emulate these cards.

What are the main MIFARE-class card families?

MIFARE is a long-running family of 13.56 MHz ISO/IEC 14443 Type A chips, and the individual products within it are worth distinguishing because they are not equally secure. Classic is the original, low-cost, memory-based card built around a proprietary stream cipher; it is enormously widespread but cryptographically dated. Ultralight is a stripped-down, inexpensive chip aimed at disposable tickets and single-use tokens.

The DESFire family (successive EV1, EV2 and EV3 generations) is the secure, microprocessor-based tier: it uses standardized cryptography, supports multiple isolated applications on one card, follows the ISO/IEC 14443-4 transmission protocol and adds secure messaging. A Plus tier bridges the two, offering a Classic-compatible footprint with an upgrade path to AES-based security.

Why is card security a real concern?

The proprietary CRYPTO1 cipher used by the original Classic cards was reverse-engineered and publicly broken by security researchers years ago, and practical attacks that recover keys and clone those cards are well documented. A credential technology whose cryptography has been broken cannot be treated as a trustworthy secret, no matter how common it is.

This matters because the card is only one half of the system — the reader and back end enforce policy, but if an attacker can trivially copy a card, the door does not know the difference. Diversified per-card keys, mutual authentication and modern ciphers are what keep a cloned or captured card from unlocking the estate.

Why are DESFire-class cards preferred for new deployments?

DESFire-class cards use open, well-analyzed cryptography — AES and, in older configurations, 3DES — rather than a secret proprietary algorithm, and they authenticate mutually with the reader before exchanging data. Their application-based file structure lets one card securely host several independent uses (say, building access and cafeteria payment) with separate keys, and secure messaging protects data in transit between card and reader.

For any new secure access, transit or closed-loop payment project, this combination of standards-based cryptography, key diversification and multi-application support is why integrators default to DESFire-class credentials over legacy Classic-based cards. The goal is not brand loyalty; it is choosing a card whose security assumptions still hold.

Where are these cards used?

Contactless smart cards run three big categories: physical access control (employee and resident badges), public-transit ticketing and fare collection, and payment or closed-loop stored value (campus, transit and event cards). Many large transit networks historically deployed MIFARE-class media at scale, which is part of why the family is so pervasive.

When specifying a card, the practical questions are the security tier the application demands, compatibility with the installed readers and lock or gate hardware, and whether a single credential needs to serve multiple systems. Matching those requirements to the right family — rather than defaulting to the cheapest compatible card — is what separates a durable deployment from one that has to be re-issued after a breach.

Need this specified and supplied?

Tell us your system and volume — we'll confirm the right technology and quote.

Request a Quote