What is the HID iCLASS SE / SR / Seos family?
The HID iCLASS SE, iCLASS SR, and Seos family is HID Global's set of modern 13.56 MHz credentials that replaced the original iCLASS generation. They are not three unrelated products — they are tiers of one architecture, all built on the Secure Identity Object (SIO) data model and protected by AES-128 cryptography rather than the proprietary cipher used by legacy iCLASS.
Read them as a ladder. iCLASS SE is the platform and the workhorse card. iCLASS SR is the dual-technology card that bridges a legacy-to-SE migration. Seos sits at the top as the device-independent, highest-assurance credential that runs identically on a card, a fob, or a smartphone. Choosing between them is mostly a question of how far along a migration a site is and whether phone-based access is needed.
How do iCLASS SE, iCLASS SR and Seos differ?
The three members of the HID iCLASS SE / SR / Seos family share a data model but play different roles. This map compares each by its job, its cryptography, the form factors it runs on, and whether any third party can supply a compatible card.
| Family member | Primary role | Cryptography | Runs on | Third-party card? |
|---|---|---|---|---|
| iCLASS SE | Current platform card | AES-128, SIO, diversified keys | Card, fob | No — integrator only |
| iCLASS SR | Legacy-to-SE migration bridge | Legacy iCLASS + AES-128 SIO | Card | No — via HID |
| Seos | Highest-assurance, mobile-ready | AES-128, device-independent | Card, fob, phone | No — HID channel |
What ties the family together — the SIO data model?
The common thread across the HID iCLASS SE / SR / Seos family is the Secure Identity Object (SIO): an encrypted, digitally-signed data container that holds the credential and is bound to a site's keys. Because identity lives in the SIO rather than in a fixed chip serial, the same protected object can be issued to a card, a fob, or a phone without weakening it.
HID's Seos credential datasheet describes this model as securing data with "a wrapper that provides key diversification, authentication signatures, and AES-128 based encryption," using a "mutual authentication protocol with generation of diversified session key" and defaulting to a random 4-byte identifier so a card cannot be tracked by a fixed number. That SIO layer is what every member of the family has in common, and it is why none of them is copyable like a proximity card.
How do I tell which HID credential my site uses?
Most sites cannot tell an iCLASS SE card from a legacy iCLASS or Seos card by looking — the plastic is usually identical. The reliable answer comes from the credential-management records or the integrator who programmed the system, because the difference is in the keys and data model, not the printing. If the site was deployed or upgraded after the mid-2010s and uses HID Signo or multiCLASS SE readers, it is likely on iCLASS SE or Seos.
This matters for ordering: legacy iCLASS, iCLASS SE, iCLASS SR, and Seos are not interchangeable at the credential level, and none of the modern members can be duplicated by a third party. Confirming which credential a site runs — through HID or your integrator — before ordering avoids buying cards that will not enroll.
Which readers run the whole family?
HID Signo and multiCLASS SE readers are the hardware that ties the HID iCLASS SE / SR / Seos family together at the door. Both read iCLASS SE, iCLASS SR, and Seos, and multi-technology versions also read legacy iCLASS and 125 kHz proximity at the same reader. That is what makes a phased migration possible: a site can install Signo or multiCLASS SE readers, keep every existing credential working, then move users up the family tier by tier.
The typical end-state is Seos, because it moves security from any fixed number to an AES-128 credential that also works as a phone-based mobile credential. The readers do not need to change again once they are Signo or multiCLASS SE, only the credentials do.
Where legacy 125 kHz proximity still fits during migration
Across the HID iCLASS SE / SR / Seos family, one thing does not change: none of these modern credentials can be sourced from a third-party card maker, so additional iCLASS SE, SR, or Seos cards come from HID or your integrator. What Security ID Systems can supply is the open 125 kHz proximity formats that most sites still run somewhere during an HID migration — on gates, parking, or older doors that have not been cut over yet.
Those open proximity formats we encode as fully compatible credentials that read identically on your existing readers. They are the practical companion to an HID upgrade, covering the doors that are still on proximity while the secure 13.56 MHz rollout finishes.
Compatible formats we do supply
None of the HID iCLASS SE / SR / Seos family can be sourced from a third party — but the 125 kHz proximity formats most sites still run during a migration are ones we encode as fully compatible credentials.
Sources & references
- HID Seos / SIO credential datasheet (SIO wrapper, AES-128, diversified session key, random UID)
- Garcia, de Koning Gans et al., "Dismantling iCLASS and iCLASS Elite" (ESORICS 2012)
- NIST SP 800-73-4, PIV secure-messaging reference
- HID proximity vs 13.56 MHz smart-card background (integrator)
- HID Global — technology background
HID Global and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.