Access Control Credential Security: 26-Bit, Corporate 1000, Seos, MIFARE & More

Access control credential security is often misunderstood because several different concepts are commonly discussed as though they were interchangeable. A 26-bit Wiegand format, HID Corporate 1000, 125 kHz proximity, HID iCLASS, HID Seos, and MIFARE DESFire do not all describe the same part of a credential system.

Some terms describe how credential data is structured. Others describe the technology used to store, protect, and communicate that data. Reader-to-controller communication is another security layer entirely. Understanding those layers is essential when evaluating or upgrading a physical access control system.

Access Control Credential Security: Format vs. Technology

A useful way to think about credential security is to separate the system into three layers:

  1. Credential format: How identifying data such as a facility/company code and card number is organized.
  2. Credential technology: How that identity is stored and exchanged between the credential and reader, including whether cryptographic authentication is used.
  3. Reader-to-controller communication: How the reader sends access-control data to the controller.

A system can improve one layer without automatically improving the others. For example, putting a restricted numbering format on a modern smart credential addresses a different problem from encrypting reader-to-controller communications.

What Is 26-Bit Wiegand?

The commonly encountered 26-bit format is a credential data format. It typically includes parity bits, an 8-bit facility code, and a 16-bit card number. That structure provides a relatively small numbering space compared with many newer formats.

The important security point is that 26-bit describes the credential data format, not the radio-frequency credential technology itself. A format alone does not provide cryptographic authentication between a card and reader.

HID identifies its H10301 26-bit format as an open format. In HID’s guidance, open formats can create duplication concerns because credential values are not restricted to a single end-user organization in the way managed formats can be.

What Is HID Corporate 1000?

HID Corporate 1000 is a managed credential-format program rather than a card technology. HID assigns an organization a unique format and tracks credential numbering to help prevent duplicate card numbers within the program.

This solves an important identity-management problem: organizations with large or distributed card populations can maintain controlled numbering rather than relying on a broadly available open format.

However, a restricted format should not be confused with cryptographic credential security. Corporate 1000 can be used as part of a stronger credential strategy, but the security of the card-to-reader exchange still depends on the credential technology and configuration.

125 kHz Proximity Credentials

Traditional 125 kHz proximity credentials have been used extensively in physical access control. They are convenient and have broad legacy compatibility, but modern migration programs increasingly move away from legacy low-frequency credentials toward smart credential technologies with stronger data protection and authentication capabilities.

A proximity card can carry a credential number in formats such as 26-bit or other formats supported by the access control system. Again, the format and the credential technology are separate concepts.

What Is HID iCLASS?

HID iCLASS introduced contactless smart-card capabilities beyond traditional low-frequency proximity. Over time, the iCLASS ecosystem evolved to include newer security architectures and Secure Identity Object (SIO)-enabled solutions.

When evaluating an existing iCLASS deployment, the exact credential, reader generation, key configuration, and operating mode matter. The word “iCLASS” by itself does not fully describe the security configuration of a particular installation.

What Is MIFARE Classic?

MIFARE is a broad family of contactless technologies, so the word “MIFARE” alone is not enough to describe a credential’s security. MIFARE Classic and MIFARE DESFire, for example, are different product families and should not be treated as equivalent.

Organizations reviewing a MIFARE deployment should identify the exact technology and application configuration instead of assuming that every credential carrying the MIFARE name provides the same security capabilities.

What Is MIFARE DESFire?

NXP’s MIFARE DESFire family is a microcontroller-based contactless smart-card platform designed for secure, multi-application uses. Modern DESFire products support cryptographic protection and application-level access controls.

MIFARE DESFire EV3 supports AES as well as other cryptographic options, secure messaging features, multiple applications and keys, and additional mechanisms designed to protect transactions. NXP states that DESFire EV3 hardware and software are Common Criteria EAL5+ certified.

As with any smart-card technology, actual deployment security depends on system design, key management, reader configuration, and how the credential application is implemented.

What Is HID Seos?

HID Seos is a modern credential technology designed around protected identity data and cryptographic authentication. HID describes Seos as using modern cryptography, mutual authentication between credential and reader, and secure messaging.

Seos is also designed to be form-factor independent. The credential can be deployed on traditional cards and supported alternative form factors, while the broader architecture can support mobile credentials.

For organizations migrating from older credential technologies, combination credentials can help support phased transitions in which existing readers are gradually replaced.

What About Mobile Credentials?

A mobile credential moves the access identity onto a compatible smartphone or other supported device. Mobile access can simplify credential distribution and replacement, but it does not eliminate the need to evaluate authentication, key management, reader compatibility, device policies, and reader-to-controller security.

The fact that a credential is on a phone does not automatically make the entire access control path secure. The complete architecture still matters.

Credential Format Does Not Equal Credential Security

This distinction is one of the most important concepts in access control.

Term Primarily Describes What It Addresses
26-bit Wiegand / H10301 Credential data format Structure of facility code and card number
Corporate 1000 Managed credential format/program Controlled, organization-specific numbering
125 kHz Prox Credential technology Legacy low-frequency contactless identification
iCLASS Smart credential technology family Contactless smart-card applications; security depends on generation/configuration
MIFARE Classic Contactless credential technology family Legacy smart-card applications
MIFARE DESFire Secure smart-card platform Cryptographic authentication, protected applications and data
HID Seos Secure credential technology Modern cryptography, mutual authentication and protected identity data
OSDP Secure Channel Reader-to-controller communication Protection of communications on the reader bus

Why More Bits Do Not Automatically Mean Better Credential Security

A larger credential format provides more room for identifiers and can improve numbering flexibility, but bit length by itself should not be treated as a measure of cryptographic strength.

A larger card-number format can reduce numbering limitations while still being used with a legacy credential technology. Conversely, a modern cryptographic credential can carry access-control data whose format is only one small part of the overall security design.

What Is OSDP and Why Does It Matter?

Credential-to-reader security is only one part of the path. After a reader processes a credential, information still has to reach the access control controller.

Open Supervised Device Protocol (OSDP) is a reader-to-controller communications protocol used in modern physical access control. Secure Channel support can protect this communication path rather than relying on legacy unencrypted signaling between the reader and controller.

This means an access control upgrade should evaluate both sides of the reader: credential-to-reader and reader-to-controller.

A Better Way to Evaluate Credential Security

Instead of asking only “How many bits is the card?”, evaluate the entire credential architecture:

  • Is the credential format open, tracked, or restricted?
  • How large and manageable is the credential numbering space?
  • Does the credential authenticate securely to the reader?
  • Is credential data cryptographically protected?
  • How are encryption and authentication keys managed?
  • Are readers configured to accept legacy credential technologies that are no longer required?
  • How does the reader communicate with the access control controller?
  • Does the system support secure reader communications such as OSDP Secure Channel?
  • How will older credentials and readers be migrated?
  • Does the architecture support future card and mobile credential requirements?

Planning a Credential Migration

Large organizations rarely replace every credential and reader in a single day. A migration may involve multi-technology readers or combination credentials that support both an existing technology and a newer one during the transition.

A practical migration plan should inventory existing credentials, formats, readers, controllers, enrollment processes, integrations, and user populations before equipment is changed. The organization can then determine which legacy technologies must remain temporarily and establish a plan for eventually disabling them where appropriate.

How This Fits Into an Access Control System

Credential security is only one component of physical access control. Readers, controllers, locking hardware, door position monitoring, request-to-exit devices, software, networking, and power all contribute to the complete system.

For the fundamentals, see our guide to how an access control system works. You can also read our comparison of key cards, key fobs, and mobile credentials to understand the differences between physical credential form factors.

Final Thoughts

Access control credential security cannot be accurately judged by a single number or product name. A 26-bit format, Corporate 1000, Prox, iCLASS, Seos, MIFARE DESFire, mobile credentials, and OSDP address different parts of the access-control architecture.

The strongest approach is to evaluate the complete chain: credential format, credential technology, authentication and key management, reader configuration, and reader-to-controller communications. Understanding those layers makes it much easier to identify legacy dependencies and plan a responsible upgrade path.