What is a Cardax / Gallagher HF smart card?
A Cardax / Gallagher HF card is the 13.56 MHz smart-card version of a Gallagher access credential. "HF" means high frequency, distinguishing it from the older 125 kHz "LF" Cardax IV proximity card. Gallagher builds this credential on an AES-secured 13.56 MHz smart card and describes it as offering "secure 128-bit AES encryption" with "an additional layer of security" over the card data.
Crucially, the Cardax / Gallagher HF card encodes the same logical identity as the legacy Cardax IV card — the same region code, facility code, card number, and issue level. That is what lets a site move a cardholder from a 125 kHz proximity card to a 13.56 MHz smart card without renumbering the whole system.
How does the Gallagher HF card relate to the 125 kHz Cardax IV?
The Gallagher HF smart card and the 125 kHz Cardax IV card are two carriers for one identity scheme. On the 125 kHz Cardax IV card, the identity is stored as a proximity number that the reader picks up in the clear (though obfuscated by Gallagher's cipher). On the 13.56 MHz Gallagher HF card, that same identity lives inside an AES-encrypted, site-keyed application and is only released after mutual authentication.
Because the underlying number is identical, a Gallagher site can bridge the two: a cardholder keeps their card number while the security model underneath is upgraded from a readable proximity value to a 128-bit AES exchange. This is the practical reason a Gallagher HF migration is described as an upgrade rather than a re-numbering project.
How do I tell which Gallagher credential my site runs?
Identifying whether you hold a 125 kHz Cardax IV card or a 13.56 MHz Gallagher HF card determines what can and cannot be supplied. The two carriers behave differently and pair with different Gallagher T-Series reader variants.
| Clue | 125 kHz Cardax IV (LF) | 13.56 MHz Gallagher HF |
|---|---|---|
| Frequency band | 125 kHz proximity | 13.56 MHz smart card |
| Reader variant | Multi Tech (or legacy prox) T-Series | Single-tech or Multi Tech T-Series |
| Security model | Cipher-obfuscated number, no live crypto | 128-bit AES, site-keyed application |
| Clone-resistant? | No — an open proximity format | Yes, if a non-default site key is used |
| Third-party card available? | Yes — supplied as a prox format | No — Gallagher / integrator only |
Is a Gallagher HF card cloneable — the 2020 default-key advisory
A Gallagher HF smart card is only as clone-resistant as its key management. On 22 December 2020, Gallagher published a statement responding to a disclosed vulnerability in the default Gallagher smart-card keys, warning that cards left on those default keys "could be cloned or emulated." The same statement drew a sharp line: "Customers who have followed Gallagher's long-standing hardening guide, which recommends the use of site-specific keys, are not affected by this disclosure."
So the honest answer is conditional. A Gallagher HF card on a non-default, site-specific key is clone-resistant because a copy would need a secret AES key it cannot read. A Gallagher HF card still on the factory default keys is not. The difference is a configuration state at your site, which is why the credential is provisioned and keyed through Gallagher and its integrators.
Which T-Series reader bridges the LF-to-HF migration?
Gallagher's T-Series readers come in a single-technology variant, which reads the 13.56 MHz AES-secured smart card, and a Multi Tech variant, which additionally reads 125 kHz proximity such as Cardax IV. A site running the Multi Tech reader can accept both the legacy 125 kHz card and the new Gallagher HF smart card at the same door.
That dual-read capability is what makes a phased cutover possible: readers are set to accept both carriers, cardholders are re-issued Gallagher HF smart cards over time, and only once everyone has moved does the site retire 125 kHz acceptance. During that window, the 125 kHz Cardax IV layer is exactly the part a third party can legitimately supply as a compatible card.
Can I get a compatible Cardax / Gallagher HF card?
No third party can supply a working site-keyed Gallagher HF smart card, because the credential is bound to an AES site key held by the customer and Gallagher. Security ID Systems does not offer a compatible AES-secured Gallagher card — those come from Gallagher or your integrator, who also manage your keys.
The Cardax IV 125 kHz proximity layer is different. It is an open low-frequency format, and while a site still runs it on any door during migration, we can encode fully compatible 125 kHz credentials, along with the general HID, Indala, and AWID prox formats a mixed Gallagher site commonly carries.
The 125 kHz layer we can supply during migration
While a Gallagher site still bridges 125 kHz Cardax IV alongside its 13.56 MHz smart cards, these open proximity formats are ones we encode as fully compatible credentials.
Sources & references
- Gallagher SMB — credentials, site-specific encoding and cloning-prevention layers
- Gallagher — Credential Solutions datasheet (AES-secured smart card, 128-bit AES)
- Gallagher Security — statement on disclosed default-key vulnerability (22 Dec 2020)
- Gallagher — T-Series readers and terminals (single-tech and Multi Tech)
- Independent research — Gallagher card format and key diversification (megabug)
Gallagher and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.