What is legacy HID iCLASS (Picopass)?
Legacy HID iCLASS is the original 13.56 MHz contactless credential HID Global introduced to move sites off 125 kHz proximity. The underlying silicon is commonly known as Picopass, and the credential stores an access number protected by a proprietary encryption scheme rather than broadcasting it in the clear the way a proximity card does. For years it was one of the most widely deployed smart credentials in access control.
The scale is documented: the 2012 academic paper on iCLASS noted that "with more than 300 million cards sold, HID iClass is one of the most popular contactless smart cards on the market." That install base is exactly why legacy iCLASS still turns up in buildings today — and why understanding its security status matters before ordering more cards or planning an upgrade.
What are iCLASS 2K and 16K?
iCLASS 2K and 16K refer to the memory size of the legacy Picopass chip, not to different security levels. The 2K version (2 kilobits, organised as 256 bytes across two application areas) is the classic access-control credential — enough room for a facility code and card number plus one extra application. The 16K version (16 kilobits) provides more memory for multiple applications on one card, such as access plus a cashless or transit purse.
Crucially, iCLASS 2K and iCLASS 16K share the same proprietary cipher and the same 64-bit key structure. The extra memory on a 16K card does not make it more clone-resistant. Both belong to the legacy iCLASS generation that was reverse-engineered in 2012, so the memory version is a capacity choice, not a security choice.
What frequency and cryptography does legacy iCLASS use?
Legacy HID iCLASS operates at 13.56 MHz over the ISO/IEC 14443A air interface, the same high-frequency band as modern contactless smart cards. Where it differs from the current generation is the cryptography: legacy iCLASS used a proprietary HID cipher with 64-bit keys and single-DES-style key diversification, rather than the standards-based AES used by iCLASS SE and Seos.
That proprietary, closed design is the root of the problem. As the researchers who broke it concluded, "security by obscurity often covers up negligent designs," adding that "it would have been more secure and efficient to use 3DES." A 64-bit proprietary cipher that was never publicly reviewed is far weaker than the AES-128 that replaced it — which is the entire reason HID built the SE and Seos platforms.
Was legacy iCLASS cracked?
Yes. Legacy iCLASS was comprehensively reverse-engineered and its keys published. Milosch Meriac's 2010 "Heart of Darkness" talk (27C3) first exposed how the reader stored its keys, and in 2012 Garcia, de Koning Gans and colleagues published "Dismantling iCLASS and iCLASS Elite," fully reverse-engineering the cipher. They reported that legacy iCLASS Standard cards "worldwide share the same master key," and that the Elite variant's master key could be recovered "from only 15 authentication attempts" in about 5 seconds on an ordinary laptop.
The consequence is straightforward: with the cipher and keys in the public record, legacy iCLASS 2K and 16K cards can be cloned, and the technology can no longer be relied on for clone resistance. HID responded by establishing a Product Security Reporting Center and by driving customers toward the AES-based iCLASS SE and Seos platforms, which have no equivalent published break.
Legacy iCLASS vs iCLASS SE vs Seos
The word "iCLASS" covers three security eras. This table compares the legacy Picopass generation against the current SE and Seos platforms so a site can see exactly where its credentials stand.
| Credential | Cryptography | Key model | Clone-resistant? |
|---|---|---|---|
| Legacy iCLASS (Picopass 2K/16K) | Proprietary cipher, 64-bit | Shared master key (Standard) | No — broken and published (2012) |
| iCLASS SE | AES-128 mutual auth (SIO) | Diversified / custom keys | Yes — no published break |
| Seos | AES-128, device-independent (SIO) | Diversified keys, mobile-ready | Yes — no published break |
Can I buy a compatible or cloned legacy iCLASS card?
No. Even though the legacy iCLASS cipher is public, Security ID Systems does not supply cloned, copied, or aftermarket iCLASS credentials — that is a firm policy, not a stock issue. If your building genuinely still needs legacy iCLASS cards during a transition, the correct and legitimate source is HID or the integrator that manages your system.
The better answer for almost every site is to upgrade. Because the legacy cipher has been publicly broken, adding more legacy iCLASS cards does not restore security; moving readers and credentials to iCLASS SE or Seos does, using AES-128 that has not been broken. multiCLASS SE and HID Signo readers run legacy iCLASS, iCLASS SE, and 125 kHz proximity together during the cutover, so no one is locked out mid-transition. The open proximity formats many sites still run in the meantime are ones we do encode as fully compatible credentials.
Compatible formats we do supply
We do not supply cloned or aftermarket iCLASS credentials — but the 125 kHz proximity formats most sites still run during an HID upgrade are ones we encode as fully compatible credentials that read identically on your existing readers.
Sources & references
- Garcia, de Koning Gans et al., "Dismantling iCLASS and iCLASS Elite" (ESORICS 2012) — cipher reverse-engineered, 300M cards, shared master key
- Meriac, "Heart of Darkness — HID iCLASS Security" (27C3, 2010)
- HID Seos / SIO credential datasheet (AES-128 replacement platform)
- HID proximity-to-13.56 MHz migration background (integrator)
- HID Global — technology background
HID Global; offices, campuses, government, apartments and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.