13.56 MHz smart-card ecosystem

LEGIC prime vs advant Explained: Security & Migration

LEGIC is a 13.56 MHz smart-card ecosystem with two generations: LEGIC prime, the older generation using proprietary encryption, and LEGIC advant, the current generation using open-standard AES (128/256-bit) and 3DES on Common Criteria EAL4+ certified silicon. LEGIC guides customers off prime and onto advant, managed through its Master-Token System-Control.

Last updated 2026-07-29

What is LEGIC, and what are prime and advant?

LEGIC is a 13.56 MHz smart-card technology and key-management ecosystem from LEGIC Identsystems. It exists in two generations. LEGIC prime is the older generation, which secured cards with a proprietary LEGIC encryption scheme. LEGIC advant is the current generation, built on standards-based silicon supporting ISO/IEC 14443-A and ISO/IEC 15693 with an on-card file system, and secured with open, published cryptography rather than a proprietary cipher.

The distinction matters because the two generations have very different security properties. A LEGIC advant card uses AES and 3DES with mutual authentication; a LEGIC prime card relies on a closed scheme that predates that model. For anyone auditing a LEGIC estate, the first question is always which generation the cards actually are.

Is LEGIC prime still secure?

LEGIC prime is the legacy generation, and LEGIC itself guides customers off it toward LEGIC advant. Prime uses a proprietary encryption scheme rather than open-standard AES, and modern security practice — echoed across the access-control industry — favours published, peer-reviewed cryptography over closed designs. LEGIC prime is not in the same security class as advant, and a site still running prime should be planning a migration.

It is worth being precise about what is and is not known. Commonly cited launch years for prime and advant circulate online but are not confirmed from a primary source, so this guide does not state them. What is well documented is LEGIC's direction: advant is the AES-based generation LEGIC promotes, and its tooling is explicitly designed to move an installation from prime to advant in a controlled way.

How secure is LEGIC advant?

LEGIC advant is secured by open-standard cryptography on certified silicon. LEGIC's own Common Criteria statement describes an advant transponder chip that supports 3DES and AES, with "mutual authentication with 112 bit 3DES," "data encryption with 112 bit 3DES or 128/256 bit AES," and "message integrity with secure MAC." The silicon is certified to Common Criteria EAL4+, with the certificate granted by Germany's Federal Office for Information Security (BSI).

Advant also uses key diversification — different keys per card — so compromising one card does not expose the system. Combined with the Master-Token key hierarchy and a hardware Security Module (SAM) in each reader, that gives LEGIC advant a security model comparable to other current AES-secured 13.56 MHz smart cards, backed by an independent Common Criteria certification.

How does prime-to-advant migration work?

LEGIC migration is governed by Master-Token System-Control (MTSC). LEGIC ties each Master-Token to a technology generation through what it calls the Master-Token Zone, so "a Master-Token always corresponds to the security standard of the associated transponder technology." LEGIC Security Modules (SAMs) can read both advant and prime at the same time, which lets an operator run a mixed estate during a transition.

The controlled cutover works like this: with SAMs reading both generations, an operator reissues users onto LEGIC advant cards, and once everyone has moved, the older technology "can be selectively deactivated." That selective-deactivation mechanism is how a LEGIC site retires prime without a single overnight swap — the readers keep accepting both until the advant rollout is complete.

LEGIC prime vs advant at a glance

The table compares the two LEGIC generations across the properties that decide a migration.

LEGIC prime vs LEGIC advant
PropertyLEGIC primeLEGIC advant
CryptographyProprietary LEGIC schemeAES 128/256 + 3DES
StandardsLegacyISO/IEC 14443-A / 15693
Silicon certificationNot statedCommon Criteria EAL4+ (BSI)
LEGIC's positionLegacy — migrate offCurrent generation
Key managementMaster-Token (legacy zone)Master-Token System-Control + SAM

Can I source a compatible LEGIC card?

A working LEGIC card — prime or advant — is provisioned under your installation's Master-Token and encoded by a LEGIC Security Module, so an independent supplier cannot produce a keyed, ready-to-use LEGIC credential. Security ID Systems does not offer one; additional LEGIC cards come from LEGIC or the integrator that holds your Master-Token authority.

Where we can help is the surrounding open-format layer: serial-number cards for simple readers, and hotel or legacy cards for adjacent doors on a mixed site. Those are the formats below.

Open formats we supply

We don't produce a keyed LEGIC credential, but these open and hotel-card formats are ones we stock and encode for enrollment stock and adjacent readers alongside a LEGIC site.

Sources & references

LEGIC Identsystems and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.

LEGIC (prime / advant) — common questions

Is LEGIC prime still secure?

LEGIC prime is the legacy generation and uses a proprietary encryption scheme rather than open-standard AES. LEGIC guides customers off prime and onto LEGIC advant, which uses AES and 3DES on Common Criteria EAL4+ certified silicon. A site still running prime should be planning a migration to advant.

What is the difference between LEGIC prime and advant?

LEGIC prime is the older generation secured with a proprietary LEGIC scheme. LEGIC advant is the current generation using open-standard AES (128/256-bit) and 3DES with mutual authentication, on ISO-standard silicon certified to Common Criteria EAL4+ by the German BSI.

How do I migrate from LEGIC prime to advant without replacing everything?

LEGIC Security Modules read both prime and advant at once, so an operator reissues users onto advant cards while readers still accept prime. Once the advant rollout is complete, the older technology can be selectively deactivated through the Master-Token, avoiding an overnight swap.

What is the LEGIC Master-Token and what if I lose it?

The Master-Token is a unique, uncopyable physical medium that holds the authority over a LEGIC installation — the right to encode cards and configure readers. Losing it is a serious event because it is the root of authority, so LEGIC sites protect and back up Master-Token control with their integrator.

When were LEGIC prime and advant launched?

Commonly cited launch years for LEGIC prime and advant circulate online but are not confirmed from a primary LEGIC source, so this guide does not state them. What is documented is that advant is the current AES-based generation and prime is the legacy generation LEGIC advises migrating away from.