
Technical Insight
Understanding MIFARE Card Formats: What’s Secure, What’s Not, and What You Should Be Using
Compare MIFARE variants, security modes and reader compatibility. Credential security depends on the whole deployment, not a universal ranking of card names.
Short answer
What to know
Compare MIFARE variants, security modes and reader compatibility. Credential security depends on the whole deployment, not a universal ranking of card names.
Resource guide
The full explanation
MIFARE card technology is one of the most widely used—and most misunderstood—components of modern access control systems. If you’ve ever tapped a badge to enter a building or used a transit pass, there’s a good chance it was powered by a MIFARE chip. But not all MIFARE cards are created equal, and some pose serious security risks.
This guide compares MIFARE families, from legacy Classic to DESFire EV3 and DUOX. The useful question is how the credential will work with your readers, keys and access-control platform.
What Is MIFARE Classic?
The Original—and the Most Vulnerable
MIFARE Classic cards operate at 13.56 MHz and offer limited data storage. They’ve been around for years and are commonly found in low-cost access solutions.
MIFARE Classic uses legacy CRYPTO1 security with known weaknesses. Avoid treating a specific cloning time as a guarantee; exposure depends on the credential and deployment.
Key points:
- Treat existing Classic credentials as a migration consideration, including temporary deployments.
- Highly vulnerable to cloning.
- Not recommended for schools, offices, or commercial facilities.
We previously published a video comparing MIFARE to other card technologies like HID Prox and iCLASS. If you’re looking for a broader overview of access credentials, that video offers additional context.
What Is MIFARE Plus?
A Transitional Security Upgrade
MIFARE Plus supports a migration from Classic-compatible operation to AES-128 authentication and secure messaging. Its configured security level matters; using compatibility mode is not the same as using the stronger mode.
Key points:
- Supports stronger protection when the appropriate security mode and keys are configured.
- Useful as a transitional card when updating infrastructure.
- Reader compatibility and configuration determine which protections are actually used.
Where Does MIFARE Ultralight Fit?
Designed for Disposable Use
The Ultralight family targets limited-use applications such as ticketing. Variants differ: EV1, Ultralight C and Ultralight AES do not have identical security features.
Key points:
- Cost-effective for short-term applications.
- Select the exact variant for the application rather than treating the whole family as either secure or insecure.
What About MIFARE Ultralight C?
Ultralight C uses 3DES authentication; Ultralight AES is a different variant with AES-128. Neither name alone establishes suitability for a particular building-access requirement.
MIFARE DESFire: EV1, EV2, and EV3
Enterprise-Grade Access Control
DESFire supports cryptographic authentication and multiple applications. NXP lists DESFire EV3 hardware and software as Common Criteria EAL5+ certified. Chip certification does not certify the completed access-control system or its regulatory compliance.
Ideal for:
- Universities
- Hospitals
- Corporate campuses
- Government facilities
Key points:
- Supports strong credential protection when securely configured.
- Supports advanced access control configurations.
- Requires compatible infrastructure and a larger investment.
What Is MIFARE DUOX?
A Credential Option With Additional Cryptographic Capabilities
MIFARE DUOX brings together symmetric and asymmetric encryption, making it suitable for high-value applications such as smart vehicle access and EV charging stations.
Key points:
- Supports symmetric and asymmetric cryptography for compatible applications.
- Evaluate against the application’s authentication and certificate-management needs.
- Confirm reader support, provisioning, administration and actual installed cost.
MIFARE Families: Compare the Deployment, Not a Universal Ranking
These are application notes, not a least-to-most-secure scale. Security mode, key management and reader/controller configuration can change the result:
- MIFARE Classic — legacy security; plan migration where stronger protection is needed.
- MIFARE Ultralight — a family of limited-use credentials with different security features.
- MIFARE Plus — migration support; check the configured security level.
- MIFARE Ultralight C — 3DES authentication; not interchangeable with Ultralight AES.
- MIFARE DESFire EV1/EV2 — evaluate supported cryptography and the installed application.
- MIFARE DESFire EV3 — additional capabilities with EAL5+ chip certification.
- MIFARE DUOX — symmetric/asymmetric capabilities that need compatible infrastructure.
Which MIFARE Card Should You Choose?
For an existing system, first identify the credential, readers, keys and controller interface. For a new one, specify the required protections and administration process before selecting a card family.
Not sure which direction to go? That’s exactly where we come in.
Get Expert Help from 210 Solutions
At 210 Solutions, we help schools, businesses, and facilities design and implement access control systems that are built for security, scalability, and simplicity. Whether you’re replacing outdated credentials or starting fresh, we can guide you through the best options for your needs.
For help applying this to your facility, explore our access control services.
Need help applying this?
Start with the problem, not the product.
Tell 210 Solutions what is happening in your building and what you need the system to accomplish.