AES-secured 13.56 MHz credential platform

HID iCLASS SE & SR Cards Explained: SIO, Security & Sourcing

HID iCLASS SE is HID Global's AES-secured 13.56 MHz credential platform, built on the Secure Identity Object (SIO) data model. iCLASS SR is the dual-technology card that carries both a legacy iCLASS credential and an SE/SIO credential to bridge a migration. SE credentials are cryptographically bound with site keys held by HID, so no third party can clone one.

Last updated 2026-07-29

What is an HID iCLASS SE credential?

HID iCLASS SE is HID Global's current 13.56 MHz access-control platform, and it is the generation that replaced the original iCLASS. Instead of tying identity data to one fixed card chip, iCLASS SE stores that data inside a Secure Identity Object (SIO) — a portable, encrypted, digitally-signed data container that can live on a card, a fob, or a phone. This is what makes iCLASS SE a platform rather than a single card type.

The practical difference from legacy iCLASS is cryptography and key management. iCLASS SE uses AES-128 with mutual authentication and per-credential diversified keys, so the card and reader each prove their identity before any data moves, and the identity object is protected independently of the chip it sits on. That security model is why an iCLASS SE credential is not sourced from a third-party card maker.

What is the SIO (Secure Identity Object) data model?

The Secure Identity Object (SIO) is the core of HID iCLASS SE. An SIO is an encrypted, cryptographically-signed container that holds the credential data and is bound to a site's keys, so it cannot simply be read off the card and re-written to a blank. HID's Seos credential datasheet — Seos shares the same SIO approach — describes the model as securing data with "a wrapper that provides key diversification, authentication signatures, and AES-128 based encryption."

Because the SIO is portable, the same identity object can be provisioned to different form factors without changing the underlying security. That decoupling of identity from silicon is the single feature that separates iCLASS SE from the legacy iCLASS generation, where the security lived in a proprietary cipher on the chip itself.

What is an iCLASS SR card, and why does it exist?

iCLASS SR is HID's dual-technology iCLASS card, built for one job: letting a site move from legacy iCLASS to the iCLASS SE / SIO model without re-badging everyone on a single day. An iCLASS SR card is designed to present both a legacy iCLASS credential and an SE/SIO credential, so it works on old readers and new readers during the transition window.

That makes iCLASS SR a migration tool rather than an end-state. Paired with multiCLASS SE readers — which read legacy iCLASS, iCLASS SE, and 125 kHz proximity at the same door — an SR card keeps every reader in the building working while an operator swaps hardware in phases. Once the readers are all upgraded, the end-state credential is a pure iCLASS SE (SIO) or Seos card.

How secure is iCLASS SE — can it be cloned?

An HID iCLASS SE credential cannot be cloned the way a 125 kHz proximity card can, because there is no fixed number to copy — the SIO is encrypted, signed, and bound to site keys, and the reader exchange uses AES-128 mutual authentication. There is no publicly documented cryptographic break of the SE / SIO model. A copied card would have to reproduce a secret key it never has access to.

This is a deliberate contrast with the earlier iCLASS generation. The proprietary cipher used by legacy iCLASS was reverse-engineered and published by academic researchers in 2012, who reported recovering the iCLASS Elite master key in roughly 15 authentication attempts. iCLASS SE was built to replace that broken cipher with standards-based AES, and no equivalent break has been published against it.

iCLASS SE vs legacy iCLASS vs Seos

HID's 13.56 MHz credentials span three security tiers. Knowing which one a site actually runs on is the first step before ordering any card, because the sourcing rules differ completely between them.

CredentialData modelCryptographyThird-party compatible card?
Legacy iCLASSOn-chip proprietary formatProprietary cipher, 64-bit keys — broken (2012)No cloned/aftermarket — source via HID
iCLASS SESecure Identity Object (SIO)AES-128 mutual auth, diversified keysNo — integrator only
iCLASS SRLegacy iCLASS + SIO (dual)Legacy layer + AES-128 SIO layerNo — migration card via HID
SeosSecure Identity Object (SIO)AES-128, device-independent, mobile-readyNo — HID channel only

Can I buy a compatible or aftermarket iCLASS SE card?

No — and that is by design. An HID iCLASS SE (SIO) credential is cryptographically bound with keys held by HID and your credential-management system, so there is no legitimate way for an independent manufacturer to produce a "compatible" iCLASS SE card, and Security ID Systems does not offer one. If your access-control system runs iCLASS SE or iCLASS SR, the correct source for additional credentials is HID or the integrator that manages your site's keys.

Where we can help is the other end of the same migration. Many sites moving to iCLASS SE still run 125 kHz proximity on gates, older doors, or legacy readers during the cutover. Those open proximity formats we do supply as fully encoded, compatible credentials that read identically on your existing hardware.

Compatible formats we do supply

If your site still runs 125 kHz proximity anywhere during an HID iCLASS SE migration, these open formats are ones we encode as fully compatible credentials that read identically on your existing readers.

Sources & references

HID Global; modern enterprise and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

HID iCLASS SE / SR — common questions

What is the difference between iCLASS SE and iCLASS SR?

iCLASS SE is HID's AES-secured 13.56 MHz platform built on the Secure Identity Object (SIO) data model. iCLASS SR is a dual-technology card that carries both a legacy iCLASS credential and an SE/SIO credential, so a site can migrate from legacy iCLASS to SE gradually without replacing every reader at once.

Can an HID iCLASS SE card be cloned?

No. iCLASS SE stores identity in an encrypted, signed Secure Identity Object bound to site keys and uses AES-128 mutual authentication, with no publicly documented cryptographic break. Unlike a 125 kHz proximity card, there is no fixed number to copy, so a third party cannot reproduce a working iCLASS SE credential.

Is iCLASS SE the same as Seos?

No, but they are related. Both use the Secure Identity Object (SIO) model and AES-128. iCLASS SE is the platform generation that replaced legacy iCLASS; Seos is HID's highest-assurance, device-independent credential that also runs on phones and wearables. Seos is the recommended end-state of an HID migration.

What readers work with iCLASS SE and SR?

iCLASS SE readers, multiCLASS SE readers, and HID Signo readers support iCLASS SE and iCLASS SR credentials. multiCLASS SE and Signo readers can also read 125 kHz proximity and legacy iCLASS at the same door, which lets a site move to iCLASS SE in phases rather than all at once.

Where do I buy replacement iCLASS SE cards?

Because iCLASS SE credentials are cryptographically bound with keys held by HID and your credential-management system, additional cards should be sourced through HID or the integrator that manages your site's keys. There is no legitimate third-party compatible iCLASS SE card, and Security ID Systems does not supply one.