Choosing a contactless card standard is a decision that shapes the security of an access control system throughout its entire operating life. In practice it usually comes down to one question: stay with the proven Mifare Classic, or move straight to DESFire with AES encryption. The difference does not concern day-to-day convenience, because a card presented to a reader works the same either way, but rather the credential's resistance to copying and to someone impersonating an authorised user. Below we explain how the individual standards in the Mifare family differ, how ICT readers behave towards them and when it is worth choosing a higher level of protection.
Mifare Classic - a popular standard with exposed security
Mifare Classic operates in the 13.56 MHz band and for years was the default choice in access control thanks to low card prices and wide availability. The problem is that its proprietary Crypto1 encryption algorithm was cracked well over a decade ago. Today, cloning a Mifare Classic card requires neither specialist knowledge nor expensive equipment, because a widely available reader-programmer and free software are enough to read the card's contents and produce a working clone.
In practice this means a credential based on Mifare Classic should be treated as easy to forge. For a low-risk facility, where the card mainly serves an organisational purpose, this may be acceptable. However, wherever access control protects real value, such as a server room, a warehouse, a production zone or personal data, relying on Classic is a risk that is hard to justify.
Mifare Plus and DESFire - what AES encryption delivers
Manufacturers answered the weaknesses of Classic with newer standards based on proven, publicly reviewed AES encryption. Mifare Plus lets you keep compatibility with existing infrastructure and gradually raise the security level, up to full AES mode. It is a sensible intermediate stage for facilities that want to move away from Crypto1 without a revolution across the whole system.
The highest level in this family is provided by DESFire, currently in the EV2 and EV3 versions. These cards use AES encryption with diversified keys, which means every card uses a unique key derived from a master key and the card number. Even if a single credential were compromised, it does not open the way to the remaining cards in the system. DESFire also supports mutual authentication between card and reader and encrypted transmission, which effectively closes the cloning and eavesdropping scenarios that Classic makes trivial.
Compatibility of ICT readers with both standards
Multi-standard reader support matters for planning. Readers from the ICT platform handle different card technologies within a single device, which allows a consistent identification policy regardless of which credential is currently in use. As a result, the same reader can read both older cards during the transition period and new DESFire credentials after migration.
This flexibility has practical value, because the investor is not forced to replace all cards and all readers at once. The process can be spread over time, while the hardware layer stays the same regardless of the chosen management software. You will find readers and credentials in the Access control and intrusion category, and the platform controllers and readers in the Protege GX line.
Migrating from Mifare Classic to DESFire without replacing the whole infrastructure
Moving from Classic to DESFire does not have to mean a single, costly replacement. A typical migration scenario involves a few steps:
- Configuring the readers so that during the transition period they accept both the old and the new standard at once.
- Gradually issuing new DESFire cards during staff turnover and the replacement of damaged credentials.
- Setting a cut-off date after which the readers stop accepting Classic cards.
- Deactivating the old standard in the system configuration and withdrawing the last Classic cards.
This model lets you spread the cost over several months and avoid downtime, while genuinely raising the security level as soon as the last Classic card is withdrawn.
Card cost versus real security level
DESFire cards are more expensive than Mifare Classic, yet the difference in the unit price of a credential is small compared with the value of the protected assets and the cost of a potential incident. With larger orders the card cost spreads across years of use, and choosing the higher standard at the outset is cheaper than a later migration forced by a discovered vulnerability. When calculating a budget, it is worth looking not at the price of a single card but at the total cost of system ownership and at how much a breach of access control would really cost.
Recommendation by facility type
It is worth tying the choice of standard to the facility's risk profile:
- Higher-risk facilities, such as server rooms, banks, laboratories, industrial plants and critical infrastructure: DESFire EV2 or EV3 as a no-compromise standard.
- Offices and commercial buildings with medium risk: DESFire for sensitive zones, with Mifare Plus acceptable as an intermediate stage.
- Low-risk facilities where the card serves an organisational purpose: Mifare Plus as a reasonable minimum, moving away from Classic.
In no new deployment today is there a good justification for designing a system around Mifare Classic. Since the hardware supports AES anyway, it is worth using its capabilities from the start.
Not sure which card standard to choose for your facility and how to plan a possible migration? Get in touch - we will help match readers and credentials to your risk profile and installation scale.