HID iCLASS custom-key program

HID iCLASS Elite Cards Explained: Custom Keys & Security

HID iCLASS Elite is HID Global's custom-key program for iCLASS credentials, replacing the shared factory master key with a site-specific key managed by HID. On the original 13.56 MHz iCLASS platform, researchers recovered the Elite master key in 2012; on the current iCLASS SE and Seos platforms, the Elite key model runs on unbroken AES-128 cryptography.

Last updated 2026-07-29

What is HID iCLASS Elite?

HID iCLASS Elite — historically marketed as the "Elite Key" or "High Security" program — is HID Global's custom-key management service for iCLASS credentials. In a standard iCLASS deployment, cards are secured with a master key that HID uses across many sites. Under iCLASS Elite, HID instead manages a custom, site-specific key so that a card encoded for one organisation will not authenticate at another organisation's readers.

The important point is that iCLASS Elite is a key-management program, not a different chip. It has existed on both the original iCLASS generation and the current iCLASS SE and Seos platforms. Which generation your Elite cards run on determines everything about their real-world security, because the two platforms use completely different cryptography.

How is iCLASS Elite different from standard iCLASS?

The difference between standard iCLASS and iCLASS Elite is the key, not the hardware. Standard iCLASS cards are diversified from a master key that is shared across HID's standard population; iCLASS Elite cards are diversified from a custom key managed for a single site. That custom key is what stops an Elite card from being read or re-encoded outside its own system.

Researchers described the standard-key weakness bluntly: on the original platform, "all iClass Standard cards worldwide share the same master key," stored in the memory of every standard iCLASS reader. iCLASS Elite was HID's answer to that shared-key exposure — a per-site key instead of a global one. On the legacy platform, though, a custom key sat on top of a cipher that was itself broken, which limited how much protection it actually added.

Was iCLASS Elite broken by researchers?

Yes — on the original iCLASS platform, iCLASS Elite was broken. In their 2012 paper "Dismantling iCLASS and iCLASS Elite," Garcia, de Koning Gans and colleagues reverse-engineered the proprietary iCLASS cipher and reported an attack that "directly recovers the master key from only 15 authentication attempts" and "can be fully executed within 5 seconds on an ordinary laptop." Meriac's earlier 27C3 (2010) work had already exposed the reader-side key handling.

This is documented history, not speculation: legacy iCLASS and legacy iCLASS Elite are no longer considered clone-resistant. It is worth being precise, though — the break applies to the original 13.56 MHz iCLASS generation. The Elite custom-key model as applied on the later iCLASS SE and Seos platforms rests on standards-based AES-128, which has no equivalent published break.

Is iCLASS Elite still used, and is it secure today?

iCLASS Elite is still offered, but its security now depends entirely on the platform underneath it. On the current iCLASS SE and Seos platforms, an Elite (custom-key) deployment layers a site-specific key on top of AES-128 mutual authentication and the Secure Identity Object (SIO) data model — a genuinely strong configuration with no published break. On the original iCLASS platform, an Elite custom key sits on the cipher that was dismantled in 2012, so it should be treated as legacy.

For an organisation, the decision comes down to which generation the readers and cards are. A modern iCLASS SE deployment using custom (Elite) keys is a defensible high-security choice. A legacy iCLASS Elite deployment is a candidate for upgrade to iCLASS SE or Seos, because no key-management program can repair a cipher that has been publicly broken.

iCLASS Standard vs Elite vs SE / Seos

Three things get called "iCLASS," and they carry very different security. This table compares standard iCLASS, legacy iCLASS Elite, and the current SE / Seos platform on key model and clone resistance.

CredentialKey modelCryptographyClone-resistant today?
Standard iCLASS (legacy)Global shared master keyProprietary cipher, 64-bitNo — cipher broken (2012)
iCLASS Elite (legacy)Custom site-specific keyProprietary cipher, 64-bitNo — master key recovered in ~15 attempts
iCLASS SE / SeosCustom / diversified keys (SIO)AES-128 mutual authenticationYes — no published break

Can I buy a compatible iCLASS Elite card?

No. iCLASS Elite credentials are tied to a custom key that HID manages for your specific site, so there is no legitimate way to produce a "compatible" Elite card from a third party, and Security ID Systems does not supply cloned or aftermarket iCLASS credentials of any kind. Additional Elite cards must be ordered through HID or the integrator that holds your site's key.

If your Elite deployment is on the original iCLASS platform, the more useful step than sourcing more legacy cards is upgrading: move readers and credentials to iCLASS SE or Seos, whose AES-128 security has not been broken. During that transition many sites still run 125 kHz proximity on some doors, and those open formats we do encode as fully compatible credentials.

Compatible formats we do supply

We do not supply iCLASS Elite credentials — but the 125 kHz proximity formats most sites still run during an HID upgrade are ones we encode as fully compatible credentials that read identically on your existing readers.

Sources & references

HID Global; higher-security iCLASS sites, enterprise and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

HID iCLASS Elite — common questions

What does iCLASS Elite mean?

iCLASS Elite (the "Elite Key" or "High Security" program) is HID Global's custom-key service for iCLASS credentials. Instead of the master key HID shares across standard iCLASS sites, an Elite deployment uses a site-specific key managed by HID, so a card encoded for one organisation will not work on another organisation's readers.

Is iCLASS Elite more secure than standard iCLASS?

It was designed to be, by replacing the shared global master key with a per-site custom key. On the original iCLASS platform, however, both standard and Elite sit on a cipher that researchers broke in 2012, so the improvement is limited. On the current iCLASS SE and Seos platforms, Elite custom keys run on unbroken AES-128.

Did researchers really break iCLASS Elite?

Yes. The 2012 ESORICS paper "Dismantling iCLASS and iCLASS Elite" reported recovering the legacy iCLASS Elite master key in roughly 15 authentication attempts, executable in about 5 seconds on an ordinary laptop. The break applies to the original 13.56 MHz iCLASS generation, not to the later iCLASS SE and Seos platforms.

Can I get a copy of my iCLASS Elite card?

Not from a third party. iCLASS Elite cards are bound to a custom key HID manages for your site, and Security ID Systems does not supply cloned or aftermarket iCLASS credentials. Additional Elite cards must be sourced through HID or the integrator that holds your site key.

Should I upgrade from iCLASS Elite to Seos?

If your Elite cards run on the original iCLASS platform, upgrading to iCLASS SE or Seos is the recommended path, because those use AES-128 with no published break, while legacy iCLASS Elite was dismantled in 2012. multiCLASS SE and HID Signo readers can run old and new credentials together during the transition.