High-security 13.56 MHz credential

HID Seos Cards Explained: Security, Specs & Credential Options

HID Seos is a high-security 13.56 MHz smart-card credential built on a secure element and protected by AES-128 mutual authentication with per-device diversified keys. Because the credential is cryptographically bound and has no published break, a Seos card cannot be cloned or reproduced by a third party — it is issued only through HID and its channel.

Last updated 2026-07-29

What is an HID Seos credential?

HID Seos is HID Global's flagship high-security credential. It is a 13.56 MHz contactless credential that stores identity data inside a Secure Identity Object (SIO) — an encrypted, digitally-signed data container — on a secure element, and it is designed to run identically on a plastic card, a key fob, or a smartphone. Unlike older technologies that are tied to one card chip, Seos is a device-independent credential standard.

Its defining feature is cryptography: every transaction between a Seos credential and a Seos-enabled reader is protected by AES-128 mutual authentication, so the card and reader each prove their identity before any data moves. That is a fundamentally different security model from the 125 kHz proximity cards Seos is meant to replace.

What frequency and technology does HID Seos use?

HID Seos operates at 13.56 MHz over the ISO/IEC 14443 air interface — the same high-frequency band used by other modern contactless smart cards. The credential data lives in an AES-secured secure element, and the Seos datasheet describes the security model as "key diversification, authentication signatures, and AES-128 based encryption," with "mutual authentication" and a "diversified session key," plus a random 4-byte UID so the card cannot be tracked by a fixed serial number.

Because keys are diversified per credential, recovering the data from one card does not expose any other card in the system — there is no shared secret broadcast in the clear.

Can an HID Seos card be cloned or copied?

No. A Seos credential cannot be cloned by copying its serial number the way a 125 kHz proximity card can, and there is no publicly documented cryptographic break of Seos. The AES-128 mutual authentication means a cloned card would also have to reproduce a secret key it never has access to.

This is a meaningful contrast with HID's own earlier 13.56 MHz technology. The proprietary cipher and key-diversification scheme used by legacy iCLASS were reverse-engineered and published by academic researchers in 2012, who reported recovering the iCLASS Elite master key in roughly 15 authentication attempts. Seos was designed as the standards-based AES replacement for exactly that generation, and no equivalent break has been published against it.

How does Seos compare to HID Prox and iCLASS?

HID's credential technologies span three security eras. Understanding which one a site runs on is the single most important step before ordering any card.

TechnologyBandSecurityThird-party compatible card?
HID Prox (125 kHz)125 kHz LFFixed number, no encryptionYes — openly supplied
iCLASS legacy13.56 MHz HFProprietary cipher, keys published (2012)Limited / legacy only
iCLASS SE / SR13.56 MHz HFSIO data model, site keysNo — integrator only
Seos13.56 MHz HFAES-128 mutual auth, diversified keysNo — HID channel only

Why does HID position Seos as the upgrade path?

HID has guided customers away from 125 kHz proximity for years — it introduced migration readers that read both 125 kHz and 13.56 MHz specifically so sites could move gradually without swapping every card and reader on the same day. The recommended end-state is Seos, because it moves security from a copyable serial number to an AES-128 credential that also works as a phone-based mobile credential.

A typical migration runs: 125 kHz Prox → iCLASS → iCLASS SE (SIO) → Seos, with multiCLASS SE readers running the old and new technologies side by side during the cutover so no one is locked out mid-transition.

Can I buy a compatible HID Seos card from a third party?

No — and that is by design. Because a Seos credential is cryptographically bound with keys held by HID and your credential-management system, there is no legitimate way for an independent manufacturer to produce a "compatible" Seos card, and Security ID Systems does not offer one. If your access-control system uses Seos, the correct source for additional credentials is HID or the integrator that manages your site's keys.

Where we can help is the other end of the same migration: many sites running Seos still have doors, gates, or legacy readers on 125 kHz proximity during the transition. Those open formats we supply as fully compatible, encoded credentials.

Compatible formats we do supply

If your site still runs 125 kHz proximity anywhere during an HID migration, these open formats are ones we encode as fully compatible credentials that read identically on your existing readers.

Sources & references

HID Global and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

HID Seos — common questions

Can an HID Seos card be cloned?

No. HID Seos uses AES-128 mutual authentication with per-credential diversified keys and has no publicly documented cryptographic break. A cloned card would need a secret key it can never read, so a Seos credential cannot be copied the way a 125 kHz proximity card can.

What is the difference between HID Seos and iCLASS?

Legacy iCLASS uses a proprietary cipher that researchers reverse-engineered and published in 2012, including recovery of the iCLASS Elite master key. Seos is the standards-based AES-128 replacement for that generation — a different, current security model that has not been broken.

Does HID Seos work with mobile phones?

Yes. Seos is a device-independent credential, so the same credential standard runs on plastic cards, key fobs, and smartphones as an HID Mobile Access credential, using the phone's NFC or Bluetooth radio.

Can I get a compatible or aftermarket HID Seos card?

No. Because Seos credentials are cryptographically bound with keys held by HID and your credential-management system, no third party can produce a compatible Seos card. Additional Seos credentials should be sourced through HID or your integrator.

What readers support HID Seos?

HID Signo and multiCLASS SE readers support Seos, and multi-technology readers can also read 125 kHz proximity and iCLASS during a migration, which lets a site move to Seos gradually rather than all at once.