What is the Brivo prox card layer?
The Brivo prox layer is the 125 kHz low-frequency proximity credential that Brivo places on a dual-technology card next to its AES-secured 13.56 MHz Unified Credential. On the dual-technology card, the proximity side is typically a 37-bit (H10304-class) format, and it presents a readable number that older 125 kHz readers can accept.
This prox layer is not where a Brivo card's security lives. Its purpose is compatibility: it lets a building that still runs 125 kHz readers keep unlocking doors while the site rolls out encrypted Unified Credentials and upgrades its readers. The encrypted 13.56 MHz half is what makes the card secure.
Why does Brivo pair a prox layer with an encrypted smart card?
Brivo pairs a 125 kHz proximity layer with the AES-secured 13.56 MHz smart card so a site can migrate without a flag-day cutover. Brivo's dual-technology cards are described as being for "a gradual migration," and its Smart Readers "support legacy prox cards alongside higher-security encrypted cards and mobile credentials at the same door."
The result is one card that works everywhere during the transition: on old 125 kHz readers via the prox layer, and on new Brivo readers via the encrypted Unified Credential. As readers are upgraded, the same cardholders are already carrying the secure credential, so no second re-badging is needed when the proximity layer is finally switched off.
Can a Brivo prox card be cloned?
The 125 kHz proximity layer of a Brivo card can be copied, like any unencrypted low-frequency proximity credential — it presents a readable number rather than performing a cryptographic challenge. That is a property of 125 kHz proximity in general, not a Brivo-specific weakness.
The AES-secured 13.56 MHz Unified Credential on the same card cannot be cloned that way, because it releases its identity only after an AES exchange and the smart card generation is certified to Common Criteria EAL5+. This split is exactly why a site should treat the prox layer as temporary: keep it while legacy readers exist, then remove it so only the encrypted credential remains.
How does a Brivo dual-technology migration work?
A Brivo migration runs the proximity and encrypted layers in parallel, then retires the weaker one. The stages below show how the dual-technology card carries a site through the transition.
| Stage | What the card presents | What the reader accepts |
|---|---|---|
| Start (legacy) | 125 kHz prox number only | Old 125 kHz readers |
| Dual-technology rollout | 125 kHz prox + AES-secured 13.56 MHz | Both old readers and new Brivo Smart Readers |
| Reader upgrade | 125 kHz prox + AES-secured 13.56 MHz | Brivo Smart Readers on OSDP secure channel |
| Hardened end state | AES-secured 13.56 MHz (or mobile) only | Encrypted credential only; prox retired |
How do I phase out the 125 kHz layer on Brivo?
Once every cardholder carries the AES-secured Unified Credential and readers have been upgraded to Brivo Smart Readers, a site can stop relying on the 125 kHz proximity layer. Moving reader wiring to OSDP with secure channel also closes the gap that legacy Wiegand leaves, since OSDP secure channel encrypts and authenticates the reader-to-controller link.
The end state is a Brivo deployment that accepts only encrypted credentials — the Unified Credential card or fob, or a Bluetooth mobile credential — with the copyable proximity layer removed. Until that point, the 125 kHz half of the dual-technology card is the part a third party can legitimately supply.
Can I buy a compatible Brivo prox card?
Yes — the 125 kHz proximity layer of a Brivo card is an open low-frequency format, so a compatible prox card can be encoded to match your site's format and read by your existing 125 kHz readers. This is different from the AES-secured Unified Credential, which is keyed within Brivo's system and can only come from Brivo or your integrator.
If your Brivo site still runs 125 kHz proximity anywhere, that layer is what we supply as compatible cards — the Brivo 37-bit prox format and the general HID, Indala, and AWID prox formats a mixed site carries. The encrypted Unified Credential itself should be sourced through Brivo.
Compatible prox formats we supply
The 125 kHz layer a Brivo site runs during migration, and adjacent open prox formats, can be encoded as fully compatible credentials that read on your existing readers.
Sources & references
Brivo and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.