What is LEGIC, and what are prime and advant?
LEGIC is a 13.56 MHz smart-card technology and key-management ecosystem from LEGIC Identsystems. It exists in two generations. LEGIC prime is the older generation, which secured cards with a proprietary LEGIC encryption scheme. LEGIC advant is the current generation, built on standards-based silicon supporting ISO/IEC 14443-A and ISO/IEC 15693 with an on-card file system, and secured with open, published cryptography rather than a proprietary cipher.
The distinction matters because the two generations have very different security properties. A LEGIC advant card uses AES and 3DES with mutual authentication; a LEGIC prime card relies on a closed scheme that predates that model. For anyone auditing a LEGIC estate, the first question is always which generation the cards actually are.
Is LEGIC prime still secure?
LEGIC prime is the legacy generation, and LEGIC itself guides customers off it toward LEGIC advant. Prime uses a proprietary encryption scheme rather than open-standard AES, and modern security practice — echoed across the access-control industry — favours published, peer-reviewed cryptography over closed designs. LEGIC prime is not in the same security class as advant, and a site still running prime should be planning a migration.
It is worth being precise about what is and is not known. Commonly cited launch years for prime and advant circulate online but are not confirmed from a primary source, so this guide does not state them. What is well documented is LEGIC's direction: advant is the AES-based generation LEGIC promotes, and its tooling is explicitly designed to move an installation from prime to advant in a controlled way.
How secure is LEGIC advant?
LEGIC advant is secured by open-standard cryptography on certified silicon. LEGIC's own Common Criteria statement describes an advant transponder chip that supports 3DES and AES, with "mutual authentication with 112 bit 3DES," "data encryption with 112 bit 3DES or 128/256 bit AES," and "message integrity with secure MAC." The silicon is certified to Common Criteria EAL4+, with the certificate granted by Germany's Federal Office for Information Security (BSI).
Advant also uses key diversification — different keys per card — so compromising one card does not expose the system. Combined with the Master-Token key hierarchy and a hardware Security Module (SAM) in each reader, that gives LEGIC advant a security model comparable to other current AES-secured 13.56 MHz smart cards, backed by an independent Common Criteria certification.
How does prime-to-advant migration work?
LEGIC migration is governed by Master-Token System-Control (MTSC). LEGIC ties each Master-Token to a technology generation through what it calls the Master-Token Zone, so "a Master-Token always corresponds to the security standard of the associated transponder technology." LEGIC Security Modules (SAMs) can read both advant and prime at the same time, which lets an operator run a mixed estate during a transition.
The controlled cutover works like this: with SAMs reading both generations, an operator reissues users onto LEGIC advant cards, and once everyone has moved, the older technology "can be selectively deactivated." That selective-deactivation mechanism is how a LEGIC site retires prime without a single overnight swap — the readers keep accepting both until the advant rollout is complete.
LEGIC prime vs advant at a glance
The table compares the two LEGIC generations across the properties that decide a migration.
| Property | LEGIC prime | LEGIC advant |
|---|---|---|
| Cryptography | Proprietary LEGIC scheme | AES 128/256 + 3DES |
| Standards | Legacy | ISO/IEC 14443-A / 15693 |
| Silicon certification | Not stated | Common Criteria EAL4+ (BSI) |
| LEGIC's position | Legacy — migrate off | Current generation |
| Key management | Master-Token (legacy zone) | Master-Token System-Control + SAM |
Can I source a compatible LEGIC card?
A working LEGIC card — prime or advant — is provisioned under your installation's Master-Token and encoded by a LEGIC Security Module, so an independent supplier cannot produce a keyed, ready-to-use LEGIC credential. Security ID Systems does not offer one; additional LEGIC cards come from LEGIC or the integrator that holds your Master-Token authority.
Where we can help is the surrounding open-format layer: serial-number cards for simple readers, and hotel or legacy cards for adjacent doors on a mixed site. Those are the formats below.
Open formats we supply
We don't produce a keyed LEGIC credential, but these open and hotel-card formats are ones we stock and encode for enrollment stock and adjacent readers alongside a LEGIC site.
Sources & references
LEGIC Identsystems and all other brand and product names are trademarks of their respective owners. Security ID Systems is an independent manufacturer and supplier of compatible access-control credentials and is not affiliated with, authorized by, sponsored by, or endorsed by these companies. Brand and format names are used only to identify the systems our products are compatible with.