13.56 MHz

The 13.56 MHz Smart-Card Family Explained: 1K, 4K, AES & NFC Tags

The 13.56 MHz contactless smart card is the modern high-frequency credential, built on the ISO/IEC 14443 Type A air interface. The family spans several tiers: legacy 1K and 4K smart cards, AES-upgradeable cards, simple memory and NFC tags, and high-security AES-secured smart cards. Each tier sits at a different security level, which determines whether we encode a ready-to-use compatible credential or supply a compatible blank that your own system enrols.

What is a 13.56 MHz contactless smart card, and why does it matter for access cards?

A 13.56 MHz contactless smart card is a high-frequency credential that operates under the ISO/IEC 14443 Type A air interface. It is one of the most widely deployed smart-card technologies in the world, used across office access control, hotel locks, public transit, cashless payment, and campus credentials. Every smart card we manufacture in this family is built on genuine, licensed silicon.

Because the 13.56 MHz family spans several distinct chip generations with very different cryptography, saying a card is "13.56 MHz" alone never fully identifies it. An access reader is provisioned for a specific card type and, often, a specific memory layout and key. Matching that card type on genuine, licensed silicon is the first requirement when you order compatible cards. The right approach for replacements depends entirely on which tier your system uses.

1K and 4K contactless smart cards: the legacy tier

The 1K and 4K contactless smart card is the original and most common member of the family, supplied as 1K (sixteen sectors) and 4K (forty sectors) variants on genuine, licensed silicon. It protects its sectors with an early proprietary 48-bit stream cipher. That cipher is an early-generation design the industry has long considered cryptographically weak, so these 1K and 4K cards are widely regarded as a legacy, open-tier credential. Many older office systems, building-entry panels, and budget hotel locks still rely on them.

Because this tier is an open legacy one, we can encode a genuine, licensed 1K or 4K credential that carries the exact data layout your reader already accepts. For these systems we supply ready-encoded compatible cards that present the same sector structure, facility data, and card number your installation expects. This makes the 1K and 4K card among the most straightforward 13.56 MHz formats for spare and replacement credentials.

  • 1K: 16 sectors, ~768 usable data bytes; 4K: 40 sectors, larger storage
  • Early proprietary 48-bit stream cipher — legacy, open-tier security
  • Common in older office access, building entry, and budget hotel locks
  • Broadly supported: we encode the matching layout onto a genuine, licensed 1K/4K credential

AES-upgradeable cards, memory tags and NFC tags: the in-between tiers

Between the legacy 1K/4K card and the top security tier sit a few in-between options. The AES-upgradeable smart card is the common drop-in upgrade path from the legacy 1K/4K card: it keeps a sector-style memory structure but can be operated in security levels that replace the old cipher with AES-128. When one of these cards is run in its higher AES security levels, it behaves like a modern secured credential rather than a legacy one, so the right replacement strategy depends on how your integrator configured it.

Alongside those are the simple memory and NFC tags. A low-cost 13.56 MHz ISO 14443-A memory card has little storage and, in its base form, no encryption — common in disposable transit tickets, event wristbands, and some hotel key cards; a hardened variant adds a Triple-DES (3DES) authentication step for a meaningful step up. NFC Forum Type 2 tags (also ISO 14443-A) are simple read/write memory tags used for marketing, product authentication, and basic fobs, while ISO/IEC 15693 vicinity smart cards cover longer-range library, laundry and some hotel tags. Plain memory and NFC tags are an open tier, so we encode a ready-to-use compatible credential on genuine, licensed silicon; the 3DES-authenticated and AES-mode cards are secured tiers, where we supply a compatible blank on the matching genuine, licensed chip and your own system enrols it with its keys.

  • AES-upgradeable card: sector-style layout, upgradeable to AES-128 in higher security levels
  • Base memory tag: no encryption — disposable transit, wristbands, some hotel cards
  • 3DES-authenticated memory tag: adds authentication — a real security step up
  • NFC Type 2 and ISO 15693 tags: simple read/write memory, not encrypted credentials
  • Approach varies: plain memory/NFC we encode ready-to-use; 3DES and AES cards ship as compatible blanks your system enrols

AES-secured smart cards: the high-security tier

The AES-secured 13.56 MHz smart card is the high-security member of the family, built around a flexible application file system and strong cryptography. Its first widely deployed generation introduced AES-128 (alongside legacy 3DES/DES modes); a later generation added features such as multiple isolated applications, transaction MAC, and proximity checking; the current generation adds further hardening and certifications. This is the card you find in modern transit networks, enterprise access control, and newer hotel and resort lock systems that want diversified keys per card.

Its AES encryption and diversified keys are designed so the credential data is written by your own system, never read out of an existing card. For these installations we supply compatible blank AES-secured credentials on genuine, licensed silicon, and your system administrator enrols them through your access-control or property-management software — exactly as you would enrol blanks ordered through the OEM channel. The keys, and your site security, stay in your hands; the blank simply matches the card family your readers expect.

  • First AES-128 generation; a later one added multiple apps, transaction MAC, proximity check; the current one is hardened and certified
  • Used in modern transit, enterprise access, and newer hotel/resort locks
  • AES + diversified keys = secured by design; your system holds the keys
  • Compatible approach: supply a compatible blank built on genuine, licensed silicon, then enrol it in your own system

How do I get replacements for my 13.56 MHz smart-card system?

Start by identifying which tier of the family your readers use — a legacy 1K/4K card, an AES-upgradeable card, a memory or NFC tag, or a high-security AES-secured card. The chip marking on existing cards, the lock or panel model, or your integrator's documentation will tell you. If you can send a sample card, that confirms the card type and, for the 1K/4K tier, the memory layout.

From there the path is straightforward. For open legacy tiers (1K/4K, plain memory and NFC tags) we encode compatible cards on genuine, licensed silicon that present the exact layout your reader already recognizes. For AES-secured tiers (the high-security card, and AES-upgradeable cards running in AES mode) we supply compatible blanks of the correct genuine, licensed card family, and your own system enrols them with its keys. Either way, these are independently manufactured compatible credentials built on genuine, licensed silicon — we are an independent manufacturer and supplier, not affiliated with, authorized by, or endorsed by any chip maker or any lock or access-control manufacturer. When in doubt, send the card type and a sample and request a quote.

The 13.56 MHz smart-card family at a glance — card type, security tier, where it's used, and the compatible approach

Card typeSecurityTypical systemsCompatible approach
1K / 4K contactless smart cardEarly 48-bit proprietary cipher (legacy, open tier)Older office access, building entry, budget hotel locksWe encode the matching layout onto a genuine, licensed 1K/4K credential
AES-upgradeable smart cardUpgradeable to AES-128 (security levels)Legacy-card upgrades, mixed-fleet access controlDepends on level: ready-encoded in legacy mode, compatible blank your system enrols in AES mode
Base memory tag (ISO 14443-A)None (base chip)Disposable transit tickets, event wristbands, some hotel cardsWe encode a ready-to-use credential on a genuine, licensed memory tag
3DES-authenticated memory tag3DES authenticationHotel key cards, ticketing needing a step upMatch the genuine, licensed chip + config; secured tier your system enrols
AES-secured smart card (first AES generation)AES-128 (also legacy 3DES/DES)Transit, enterprise access, secure facilitiesCompatible blank on genuine, licensed silicon, enrolled by your system
AES-secured smart card (multi-application generation)AES-128 + multi-app, transaction MAC, proximity checkModern access control, multi-application credentialsCompatible blank on genuine, licensed silicon, enrolled by your system
AES-secured smart card (current generation)AES-128, hardened + certified (latest)Current enterprise access, newer hotel/resort locksCompatible blank on genuine, licensed silicon, enrolled by your system

Frequently asked questions

Can you supply a replacement or spare for my 13.56 MHz smart card?

Yes, and the approach depends on the card type. Legacy 1K/4K cards and plain memory tags are open legacy tiers, so we encode a ready-to-use compatible credential on genuine, licensed silicon that presents the exact data your readers already accept. AES-secured smart cards (and AES-upgradeable cards running in AES mode) are secured tiers with AES and diversified keys — for those we supply a compatible blank on genuine, licensed silicon that your own system enrols with its keys.

Is a legacy 1K/4K contactless card secure?

No. The legacy 1K/4K card relies on an early proprietary 48-bit stream cipher the industry has long considered weak. It is regarded as a legacy, open-tier credential and is one of the reasons many sites have migrated to AES-secured cards. Because it is an open tier, these cards are broadly supported and quick for us to encode as spares and replacements.

What is the difference between a legacy 1K/4K card and an AES-secured card?

The legacy 1K/4K card uses an early proprietary cipher and a fixed sector memory layout. The AES-secured card is the high-security generation using AES-128 with a flexible application file system and diversified keys. For the legacy card we encode a ready-to-use compatible credential; for the AES-secured card we supply a compatible blank on genuine, licensed silicon that your own system enrols with its keys.

What is a 3DES-authenticated memory tag used for?

It is a low-cost 13.56 MHz memory tag that adds Triple-DES (3DES) authentication on top of a base memory chip, giving a meaningful security step up. It is common in hotel key cards and ticketing applications that want more than a plain memory tag. As a secured tier, replacements need the genuine, licensed chip and configuration matched, and your system enrols them with its keys.

How do I know which 13.56 MHz card my system uses?

Check the chip marking on existing cards, your lock or access-panel model, or your integrator's documentation. Sending a sample card confirms the card type and, for the 1K/4K tier, the memory layout. Once you know whether it is a legacy 1K/4K card, an AES-upgradeable card, a memory or NFC tag, or an AES-secured card, send us the details and request a quote.

Are your 13.56 MHz cards genuine, licensed products?

Our cards are independently manufactured compatible credentials built on genuine, licensed silicon and designed to work with the readers and locks that use this card family. We are an independent manufacturer and supplier, not affiliated with, authorized by, or endorsed by any chip maker or any lock or access-control manufacturer, and brand and format names are used only to identify the systems our products are compatible with.

Request a quote

Can't find your format? Email the specialists.

Send the part number printed on your card or a photo of the reader. We confirm compatibility before you order — and we cover the specialist formats nobody else lists.