Legacy 13.56 MHz credential

HID iCLASS Legacy (Picopass 2K/16K) Explained: Security & Upgrade

Legacy HID iCLASS is HID Global's first-generation 13.56 MHz contactless credential, built on Picopass silicon in 2K and 16K memory versions and protected by a proprietary cipher with 64-bit keys. Academic researchers reverse-engineered that cipher and published it in 2012, so legacy iCLASS is no longer clone-resistant; the secure fix is upgrading to iCLASS SE or Seos.

Last updated 2026-07-29

What is legacy HID iCLASS (Picopass)?

Legacy HID iCLASS is the original 13.56 MHz contactless credential HID Global introduced to move sites off 125 kHz proximity. The underlying silicon is commonly known as Picopass, and the credential stores an access number protected by a proprietary encryption scheme rather than broadcasting it in the clear the way a proximity card does. For years it was one of the most widely deployed smart credentials in access control.

The scale is documented: the 2012 academic paper on iCLASS noted that "with more than 300 million cards sold, HID iClass is one of the most popular contactless smart cards on the market." That install base is exactly why legacy iCLASS still turns up in buildings today — and why understanding its security status matters before ordering more cards or planning an upgrade.

What are iCLASS 2K and 16K?

iCLASS 2K and 16K refer to the memory size of the legacy Picopass chip, not to different security levels. The 2K version (2 kilobits, organised as 256 bytes across two application areas) is the classic access-control credential — enough room for a facility code and card number plus one extra application. The 16K version (16 kilobits) provides more memory for multiple applications on one card, such as access plus a cashless or transit purse.

Crucially, iCLASS 2K and iCLASS 16K share the same proprietary cipher and the same 64-bit key structure. The extra memory on a 16K card does not make it more clone-resistant. Both belong to the legacy iCLASS generation that was reverse-engineered in 2012, so the memory version is a capacity choice, not a security choice.

What frequency and cryptography does legacy iCLASS use?

Legacy HID iCLASS operates at 13.56 MHz over the ISO/IEC 14443A air interface, the same high-frequency band as modern contactless smart cards. Where it differs from the current generation is the cryptography: legacy iCLASS used a proprietary HID cipher with 64-bit keys and single-DES-style key diversification, rather than the standards-based AES used by iCLASS SE and Seos.

That proprietary, closed design is the root of the problem. As the researchers who broke it concluded, "security by obscurity often covers up negligent designs," adding that "it would have been more secure and efficient to use 3DES." A 64-bit proprietary cipher that was never publicly reviewed is far weaker than the AES-128 that replaced it — which is the entire reason HID built the SE and Seos platforms.

Was legacy iCLASS cracked?

Yes. Legacy iCLASS was comprehensively reverse-engineered and its keys published. Milosch Meriac's 2010 "Heart of Darkness" talk (27C3) first exposed how the reader stored its keys, and in 2012 Garcia, de Koning Gans and colleagues published "Dismantling iCLASS and iCLASS Elite," fully reverse-engineering the cipher. They reported that legacy iCLASS Standard cards "worldwide share the same master key," and that the Elite variant's master key could be recovered "from only 15 authentication attempts" in about 5 seconds on an ordinary laptop.

The consequence is straightforward: with the cipher and keys in the public record, legacy iCLASS 2K and 16K cards can be cloned, and the technology can no longer be relied on for clone resistance. HID responded by establishing a Product Security Reporting Center and by driving customers toward the AES-based iCLASS SE and Seos platforms, which have no equivalent published break.

Legacy iCLASS vs iCLASS SE vs Seos

The word "iCLASS" covers three security eras. This table compares the legacy Picopass generation against the current SE and Seos platforms so a site can see exactly where its credentials stand.

CredentialCryptographyKey modelClone-resistant?
Legacy iCLASS (Picopass 2K/16K)Proprietary cipher, 64-bitShared master key (Standard)No — broken and published (2012)
iCLASS SEAES-128 mutual auth (SIO)Diversified / custom keysYes — no published break
SeosAES-128, device-independent (SIO)Diversified keys, mobile-readyYes — no published break

Can I buy a compatible or cloned legacy iCLASS card?

No. Even though the legacy iCLASS cipher is public, Security ID Systems does not supply cloned, copied, or aftermarket iCLASS credentials — that is a firm policy, not a stock issue. If your building genuinely still needs legacy iCLASS cards during a transition, the correct and legitimate source is HID or the integrator that manages your system.

The better answer for almost every site is to upgrade. Because the legacy cipher has been publicly broken, adding more legacy iCLASS cards does not restore security; moving readers and credentials to iCLASS SE or Seos does, using AES-128 that has not been broken. multiCLASS SE and HID Signo readers run legacy iCLASS, iCLASS SE, and 125 kHz proximity together during the cutover, so no one is locked out mid-transition. The open proximity formats many sites still run in the meantime are ones we do encode as fully compatible credentials.

Compatible formats we do supply

We do not supply cloned or aftermarket iCLASS credentials — but the 125 kHz proximity formats most sites still run during an HID upgrade are ones we encode as fully compatible credentials that read identically on your existing readers.

Sources & references

HID Global; offices, campuses, government, apartments and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

HID iCLASS legacy (Picopass) — common questions

What is HID iCLASS Picopass?

Picopass is the silicon behind legacy HID iCLASS, a 13.56 MHz contactless credential HID introduced to move sites off 125 kHz proximity. It stores an access number protected by a proprietary cipher. Legacy iCLASS on Picopass was reverse-engineered and published in 2012 and is no longer considered clone-resistant.

What is the difference between iCLASS 2K and 16K?

The difference is memory size, not security. iCLASS 2K holds a facility code, card number, and one extra application; iCLASS 16K has more room for multiple applications on one card. Both share the same proprietary cipher and 64-bit key structure, so a 16K card is not more clone-resistant than a 2K card.

Can legacy iCLASS cards be cloned?

Yes. Researchers reverse-engineered the proprietary iCLASS cipher and published it in 2012, including recovery of the iCLASS Elite master key in roughly 15 authentication attempts. With the cipher and keys public, legacy iCLASS 2K and 16K cards can be cloned, which is why HID moved customers to the AES-based SE and Seos platforms.

Does Security ID Systems sell copied iCLASS cards?

No. Security ID Systems does not supply cloned, copied, or aftermarket iCLASS credentials. If a site genuinely still needs legacy iCLASS cards during a transition, the legitimate source is HID or your integrator. The recommended path is upgrading to iCLASS SE or Seos, whose AES-128 security has not been broken.

How do I upgrade from legacy iCLASS?

Install multiCLASS SE or HID Signo readers, which read legacy iCLASS, iCLASS SE, and 125 kHz proximity at the same door, then re-issue users onto iCLASS SE or Seos credentials in phases. That keeps every reader working during the cutover while moving security from the broken legacy cipher to unbroken AES-128.